Global Feed Post Login
Replying to Avatar bumi

The password reset email could be requested with an email and attackers use leaked emails from lists recorded in for example haveibeenpwned.

Sadly in the Alby case the password reset email could also be requested with the lightning address which is likely what happened to you. Some attacker got the lightning address from nostr for example to do this.

We have disabled this now.

f8
f8e499c2... 4d ago

today (29.12.25) i received an email from crypto.com – a service i never registered for. i‘m an alby user. i suspect this leak to be the culprit.

Reply to this note

Please Login to reply.

Discussion

No replies yet.