Why are crypto industry leaders receiving unsolicited X password reset emails?

Multiple crypto industry figures and journalists reported a wave of unsolicited X password reset emails on Tuesday, signaling a potential coordinated targeting of high-profile accounts. While there is no evidence of a breach at X itself, the incident suggests bad actors are attempting to gain access to influential profiles to facilitate crypto-related scams.
Why are crypto industry leaders receiving unsolicited X password reset emails?

Crypto industry leaders and media professionals are currently being targeted by a wave of unsolicited password reset emails from X, the social media platform formerly known as Twitter. These notifications are legitimate system-generated emails triggered when a third party attempts to initiate a password change for a specific handle. While the emails themselves do not indicate that X’s internal systems have been compromised, they confirm that attackers are actively trying to gain entry into accounts belonging to prominent members of the blockchain community.

The surge in reset requests was reported on Tuesday by several crypto-native figures and staff members at CoinDesk. This type of activity often points to a credential stuffing attack, where hackers use databases of leaked emails and passwords from other platforms to see if they can gain access to X. Alternatively, it could be a tactic known as 'push bombing,' designed to annoy or confuse a user into accidentally approving a reset or clicking a malicious link in a follow-up phishing attempt.

For the US crypto market, this security alert serves as a stark reminder of the risks associated with 'Crypto Twitter,' which serves as a primary source for real-time market data and project updates. The SEC has previously highlighted the dangers of social media hijacks; in January 2024, the SEC’s own X account was compromised via a SIM-swap attack to falsely announce the approval of Bitcoin ETFs, causing immediate and significant volatility in the price of BTC.

Investors and industry participants should monitor their account security settings closely in the coming days. Security experts recommend moving away from SMS-based two-factor authentication (2FA) in favor of hardware keys or authenticator apps to prevent unauthorized access. As of now, X has not released an official statement regarding the origin of these reset requests, but the concentrated targeting of crypto accounts suggests that the motive is likely the promotion of fraudulent 'drainer' links or fake token airdrops.