# What happened Attorney General Todd Blanche said this week that sophisticated cybercriminals attempted a mass password-recovery attack against hundreds of thousands of X users. X disrupted the campaign before any accounts were captured, and the U.S. Justice Department is collaborating with the company to identify those behind the effort.
# Why this matters for crypto users
# How password-recovery attacks work A password-recovery attack targets the account-reset process instead of trying to guess existing passwords. Common elements include:
- Triggering "forgot password" flows en masse for many accounts.
- Exploiting the email or SMS verification step to claim control.
- Using automation to scale attempts across large lists of usernames or contact points.
Authorities and X have not disclosed which exact technique was used in this incident, whether specific user groups were targeted, or the precise number of accounts hit.
# What X and authorities have said Attorney General Todd Blanche described the perpetrators as "sophisticated cybercriminals" and confirmed X blocked the attempt before accounts were compromised. No additional evidence about methods, identified suspects, or targeted cohorts has been publicly released.
# Practical steps to protect your X account The story lists concrete defensive actions users can take:
- Turn on Password Reset Protect in X via Settings > Security and account access > Security.
- Use two-factor authentication with an authenticator app or a hardware security key instead of SMS-based 2FA to reduce exposure to account-recovery attacks via SMS interception or SIM-swapping.
# What remains unclear Key details are still unknown: the specific technical method used, the exact count of accounts targeted, and whether attackers focused on crypto-related or other high-value accounts. The Justice Department and X continue their investigation.
# Bottom line The campaign was stopped before account takeovers occurred, but the event highlights how the account-recovery process can be abused at scale. For users involved in crypto or with sizable followings, securing account-recovery channels and using non-SMS two-factor methods reduces the risk that a hijacked account will be used to spread scams or malicious links.