The Specialty News
Business

X Opens Its 6% Yield Bank, and Hackers Instantly Target the Front Door

Elon Musk is offering an unbeatable interest rate and up to $10 million in FDIC coverage to turn the timeline into a bank, but the everything app is already facing an unprecedented wave of account takeover attempts.

By The Specialty News DeskEdited by 4 min read
X Opens Its 6% Yield Bank, and Hackers Instantly Target the Front Door
Photo: americanbanker.com

Within 24 hours of Elon Musk flipping the switch to turn X into a bank, an unprecedented wave of automated password-reset requests flooded user inboxes. A compromised social media account used to mean a spam post in your name. Today, it means a hacker could access your direct-deposited paycheck, peer-to-peer transaction history, and metal Visa debit card. The stakes of timeline security just went from stolen memes to stolen life savings.

The Timeline Bank

Elon Musk has spent more than two decades waiting for this moment. In 1999, he founded the original X.com with the explicit goal of replacing traditional bank accounts entirely. Now, the modern iteration of X is stepping into territory tightly controlled by Robinhood, Apple Pay, and the bank-backed Zelle consortium, daring to test if a social feed functions better as a financial dashboard.

To force that behavior change, X is dangling an extraordinary financial carrot. That aggressive rate vastly outpaces the 4.5% standard found in today's high-yield savings accounts, serving as the ultimate justification for X's $115 to $400 annual subscription tiers. For high-net-worth users, X implemented a cash sweep program offering aggregate FDIC pass-through coverage of up to $10 million.

X avoids becoming a chartered bank itself by piping the funds directly into Cross River Bank's regulated backend. It effectively treats a social media login like the keys to a physical bank vault. But holding the money securely at a partner bank only matters if X can lock its own front door.

The Security Paradox

The Security Paradox
Photo: incrypted.com

Global attackers instantly understood the shifting economics of a compromised account. On September 1, just hours after the feature went live for US users, a massive automated password-reset campaign struck the platform. Attackers scraped public X usernames and flooded the system, betting that users had not yet secured their new financial hubs with two-factor authentication.

Attackers appear to believe that, now that @XMoney is widely available, they can gain unauthorized access to accounts. We are actively investigating the issue and, so far, have found no evidence of any breaches.Mridul Singhai

X Product Engineer Mridul Singhai was dispatched to calm the public, confirming that internal systems held firm. Simultaneously, X General Counsel James Burnham issued a statement vowing to hunt down the perpetrators.

The tension is obvious. A platform historically infamous for bots and data scraping is now guarding actual banking credentials. The convenience of in-app finance is massive, but it risks being overshadowed by phishing nightmares if users fail to adapt their security habits. This early friction immediately caught the attention of regulators who were already watching Musk's pivot.

From Social Feed to Bank Vault

A visual summary of this story

The Brief

Stay curious

AI and technology: what changes and why it matters.
Your daily selection, in English or Spanish.

Free forever. Unsubscribe anytime.

Conversation

Start the conversation

No account needed. Comments are checked automatically — keep it civil.

More stories

Keep reading