U.S. Attorney General Todd Blanche: X Prevents Large-Scale Password Reset Attacks
U.S. Attorney General Todd Blanche stated that this week, "sophisticated cybercriminals" launched password recovery attacks against hundreds of thousands of X users. The platform has interrupted the attacks to prevent account takeovers, and the Justice Department is working with X to trace the perpetrators, stating that there is no safe harbor behind the screen.
The attack targeted the "forgot password" process: users received reset emails and six-digit verification codes from official domains without any action on their part, with some receiving eight emails within three minutes and others receiving over ten emails at the same time in the morning. Engineer Mridul Singhai explained internally that the attackers seemed to believe that X Money had rolled out to qualified users, making account takeovers more lucrative; the company stated that it had not found evidence of a system breach and apologized for the email bombardment. Public usernames can repeatedly trigger the reset form, which does not equate to a theft of the password database.
X Money opened to X Premium users in July, offering about 3% cashback on credit card transactions, instant payments, and free withdrawals, bringing social accounts closer to financial gateways. Chief Legal Officer James Burnham stated that the legal and security teams will hold accountable those responsible. The platform advises enabling two-factor authentication and activating protections that prevent username-only resets. The Attorney General did not disclose details of the methods used, whether any individual accounts have been compromised, or the location of the attackers.
A historical comparison is July 2020: attackers used social engineering to access internal management tools, replaced confirmation emails, and forcibly reset about 130 accounts, stealing approximately $118,000 in Bitcoin. This public statement emphasizes that the forms were triggered in bulk, rather than an internal backend breach. In July, the White House established a coordination group for AI developers and critical infrastructure vulnerability sharing, which has no direct evidence chain related to this case, but indicates that law enforcement prioritized cyber fraud and account hijacking during the same period.
Who is buying and who is selling: the incident is driven by account arbitrage following the launch of payment features, not advertising traffic. The attackers buy sessions that can pass the reset gate and sell token calls or wallet transfers after takeover; benefiting are users who have enabled two-factor authentication and reset protections, while the platform is under pressure for layering payment on top of the public username recovery process. The Justice Department's involvement turns a product safety incident into a narrative of cross-border pursuit, shifting pricing power from engineering logs to public prosecution.
Reuters did not receive an immediate written response from X when seeking confirmation. The official only confirmed that the attacks were interrupted and that accounts were not "captured" on a large scale, without providing an exact list of targeted users or interception success rates.
Source: Public Information
ABAB AI Insight
Todd Blanche is not a technical bureaucrat from a cybersecurity background; his public stance against "screen behind the scammers having nowhere to hide" elevates a wave of reset emails to a joint pursuit by the Justice Department and the platform, rewriting the old wound of Twitter's internal tools being compromised in 2020 into a display of current government law enforcement: the platform first reports no breaches, and the minister adds the weight of the state machinery.
The capital path is that X has turned social conversations into an entry point for X Money settlements. Money has shifted from subscriptions and advertising to cashback from card organizations, instant payments, and premium users depositing funds. Attackers migrate with the financial entry points, using publicly available usernames at near-zero cost to hit official recovery interfaces, which is an arbitrage on "accounts as wallets." Until the platform changes the design that allows username-triggered resets, the launch of payments increases the expected returns from each takeover.
The reference points are the 2020 resets of high-profile accounts via internal tools and the old script of various "forgot password" interfaces being filled with credentials and bombarded with emails. The industry position is that social platforms are in an expansion phase at the edge of financial licensing, with control still in the hands of product managers overseeing recovery processes, not yet shifted to bank-level identity verification.
The structural change is a combination of regulatory shifts and industry chain reconstruction: account security has transformed from a content review issue to a payment infrastructure issue. The mechanism is that recovery interfaces are open to the public, and verification codes go through email, meaning attackers only need to scale triggering and the second step on the inbox side; once payments are enabled, the expected loss from the same interface shifts from losing followers to losing balances, prompting the Justice Department to be willing to name and support.
ABAB News · Cognitive Laws
- Once payments are enabled, the reset interface becomes an ATM.
- Processes triggered by public usernames equate to hanging a lock on the outside of the door.
- The platform reporting no breaches does not mean there is no economic motivation for the attacks.