Capital costs, not price, drive Strategy's Bitcoin buys, says CEO
Strategy CEO Phong Le says Bitcoin purchases are based on capital costs, not price. He expects the rally to continue.
X users received unwanted password reset emails on Tuesday; X said there was no breach and advised enabling reset protection.
A wave of unsolicited password reset emails struck X accounts on Tuesday. One account holder received eight messages within three minutes. The company says it has not found any breach.
These messages are genuine, sent from X itself rather than spoofed senders. Rather than hacking users directly, attackers keep firing X’s own account recovery form at publicly known usernames.
BEWARE OF THIS!! ENABLE 2FA AND PASSWORD RESET PROTECT ON YOUR X ACCOUNT
— Sweep (@0xSweep) September 1, 2026
Many accounts are getting breached https://t.co/uy5pFsW9hB
The company's response came from Mridul Singhai, an X product engineer. He offered a possible motive, denied a breach, and apologized.
“Attackers appear to believe that, now that XMoney is widely available, they can gain unauthorized access to accounts. We are actively investigating the issue and, so far, have found no evidence of any breaches. We apologize for the multiple emails and appreciate your patience…,” Singhai wrote.
That statement stood as the company's sole public comment on the matter. Neither the main X account, nor X Support, nor X Money posted anything.
The timing is consistent with the suspected motive. X Money launched peer-to-peer payments for US Premium subscribers back in late June. Funds are kept at Cross River Bank, where deposits are federally insured for as much as $10 million.
An X login therefore doubles as a banking credential. That upends the risk calculations. With a hijacked profile, an attacker can tout a phony token. A compromised wallet, meanwhile, can be drained.
There is no confirmation of any data leak. Typically, campaigns of this kind rely on aged email lists that have been trading on criminal marketplaces for years.
The recovery form at X will accept just a username. Those usernames are public. So that alone opens the door.
X's help pages already offer a remedy: users who get a reset they “did not request” are told to enable Password reset protection. With that setting on, the recovery form first requires the email or phone number on file.
On Tuesday, Nikita Bier, who used to run product at X, put up the setting. By afternoon, his screenshot had been viewed more than 85,000 times.
“Just turn this on,” Bier said.
Two more protective layers are worth adding:
This is not the first time X has faced such an attack, though previously it came from within. Back in July 2020, intruders social-engineered their way past employees to an internal admin tool. They rerouted confirmation emails and triggered password resets for 130 accounts, making off with $118,000 in Bitcoin.
This time around, the attackers are operating externally, routing abuse through a public form. The objective is unchanged. The recommended steps for hardening X accounts have not changed either.
It remains to be seen whether X will put rate limits on the form or leave it to users to defend themselves.
Share to
Disclaimer: this article comes from third-party media and is provided for reference only. It does not constitute investment advice. Crypto and other financial products carry significant price volatility risk, so please make your own decisions carefully.
Strategy CEO Phong Le says Bitcoin purchases are based on capital costs, not price. He expects the rally to continue.
Stablecoins are reshaping cross-border payments by enabling faster, real-time settlement, forcing a redesign of legacy banking infrastructure.
The anonymous GTA 6 leaker made about $350,000 in fees from the CyberLeek meme coin, not from selling tokens.
Institutions face billions in costs to prepare crypto for quantum computers, with no central budget for migration.