X Money attacked right after launch: Fintech security lessons
Fujigo Software Solutions
Member of M&C Holdings (Japan)

The incident right after launch
X Money, the new payment service integrated into the X platform (formerly Twitter), faced a serious security attack right after launch. Numerous X users reported receiving unsolicited password reset emails — a classic sign of a mass account takeover attempt.
“Attackers appear to believe that, now that @XMoney is widely available, they can gain unauthorized access to accounts,” an X representative said in a statement. “We are actively investigating the issue and, so far, have found no evidence of any breaches.”
The company also apologized for the multiple emails and thanked users for their patience while they work to resolve the issue.
Why is X Money attractive to hackers?
X Money is a newly launched payment service integrated into X, including a bank card and other benefits. For X, the service makes it easier for creators to collect payments on the platform, facilitating X’s digital economy.
However, money changing hands has a tendency to attract bad actors. When a social platform expands into fintech, it doesn’t just face normal security threats — it must also protect users’ actual financial assets.
This is why attacks on X Money right after launch aren’t surprising. Hackers know that:
First, users aren’t yet familiar with the new service. They may not have set up additional security measures like two-factor authentication or transaction alerts.
Second, there’s direct financial value. A normal X account has value because of content and followers. An X Money account has real money and the ability to transfer funds.
Third, launch periods often have vulnerabilities. New services often have undiscovered bugs, and hackers always look to exploit them in the early stages.
Lessons for Vietnamese fintech companies
The X Money incident offers many important lessons for fintech companies developing in Vietnam:
First, security must be prioritized from day one. When building financial services, you can’t treat security as an afterthought feature. It must be the foundation of your system architecture.
Second, prepare for attacks at launch. Fintech companies should have detailed incident response plans, 24/7 security teams, and real-time monitoring systems from the very first day.
Third, user education is key. Many attacks succeed because users don’t recognize warning signs. Fintech companies need to invest in guiding users about account security.
Fourth, transparency in communication. X quickly acknowledged the incident and provided updates. This is the right way to maintain user trust, especially when money is involved.
Fifth, integrate multi-layer security. Two-factor authentication, biometrics, abnormal behavior monitoring, and transaction limits are necessary protection layers for any fintech service.
The future of X Money and social fintech
Although this security incident is an unfortunate start, it also shows the potential of social fintech. When social platforms with billions of users integrate financial services, they can revolutionize how we pay and transfer money.
However, success depends on the ability to build trust. Users will only use X Money if they believe their money is safe. Every security incident erodes that trust.
For Vietnam, where e-wallets like MoMo, ZaloPay, and Viettel Money have become popular, the lesson from X Money is even clearer. Security isn’t a cost — it’s an investment in user trust, and trust is the most valuable asset of any fintech company.
Source: X says attackers are targeting accounts after the launch of X Money — TechCrunch, September 1, 2026