Thread

Zero-JS Hypermedia Browser

Relays: 5
Replies: 77
Generated: 21:09:32
Overnight we have received notices of some unusual requests to our infrastructure. Over a short period of time many password reset emails had been requested from various residential proxies around the world. Our rate limiting protects against spamming attacks but requests got through to request password reset emails. Many of the requests are likely for emails that had been included in some data breach or have been publicly exposed by their owner. Password request emails also have been requested for lightning addresses which falsely exposed the user's email address. This had been a feature deployed to help users keep easy access to their accounts. But as many users post their lightning address on profiles like nostr this should not be exposed and a fix has been deployed immediately. Generally there should be no way to display a user's email address. We have failed here. About 5500 password reset emails had been requested by the attacker. **We have not seen any abnormal related login activity and accounts are safe. People who got a password reset email can ignore the email.** As we have seen a general increase in attacks on user accounts trying to brute force logins with some emails from some data leaks we have fully disabled password logins and require all users to login with the one time token. This adds an another layer of security. Additionally we also offer the option to login with Google. If you have questions or feedback, please let us know: support.getalby.com
2025-10-21 08:07:47 from 1 relay(s) 27 replies ↓
Login to reply

Replies (77)

We've seen many attacks where it seemed attackers have used emails + passwords from different breaches. If you want get a picture of which breaches your email was included in: https://haveibeenpwned.com/ However, we also recognize that Alby emails could have been exposed through the reset password system as mentioned already in this announcement and we have made the necessary changes to ensure affected users are not at risk of losing their funds.
2025-10-21 08:48:50 from 1 relay(s) ↑ Parent 2 replies ↓ Reply
They don't break any server, by using your public alby address in nostr, they just requested a password reset. This is not scam email, it's real email from Alby. The hack consists of that they can get your email from your Alby address, but to do so they have to trigger password reset. Everything is pretty safe, don't worry. Just make sure use strong passwords and have in mind for any incoming emails with email address connected to Alby account
2025-10-21 09:11:33 from 1 relay(s) ↑ Parent 1 replies ↓ Reply
It's definitely unpleasant that it happened. But one must be careful on the internet. I personally, using tools to check for data leaks, have seen emails leaked from other much bigger companies and software. That's why personal culture regarding cybersecurity is an important thing. I'm also 99% sure that a large part of these emails have already been leaked somewhere else. That's why it's good to use email masking services.
2025-10-21 09:31:19 from 1 relay(s) ↑ Parent 1 replies ↓ Reply
yes, many requests we see originate from emails that also don't have accounts with Alby. There are many brute force attacks out there in the wild internet sadly. Using alias email addresses like the ones proton offers is encouraged.
2025-10-21 09:35:29 from 1 relay(s) ↑ Parent Reply
She has alby cloud pro hub , when she wants to top up her bitcoin , she need to buy bitcoin and through the third payment system like Mt. pelerin .. is it not right ? This is not transfer from lightning to lightning payment ..? Don’t you not know this ?
2025-10-21 10:55:12 from 1 relay(s) ↑ Parent 1 replies ↓ Reply
Hey nostr:nprofile1qqsyv47lazt9h6ycp2fsw270khje5egjgsrdkrupjg27u796g7f5k0spremhxue69uhkummnw3ez6ur4vgh8wetvd3hhyer9wghxuet59uq3xamnwvaz7tmsw4e8qmr9wpskwtn9wvhsdymxeg - please allow passkey login. My account shouldn’t be constrained solely by email. Email is not a suitable 2FA method. Username + password + TOTP or email token + TOTP are good, but Passkey is better because it requires a device you possess already and doesn’t rely on email that’s phishable. I’ve seen other sites go further and require TOTP after a Passkey too, fwiw. Point being, give uses the option for real 2FA decoupled from email.
2025-10-21 11:17:50 from 1 relay(s) ↑ Parent 2 replies ↓ Reply
Yep - good to see it's fixed. Thanks nostr:nprofile1qqsyv47lazt9h6ycp2fsw270khje5egjgsrdkrupjg27u796g7f5k0spzamhxue69uhhyetvv9ujuurjd9kkzmpwdejhgtcpz4mhxue69uhhyetvv9ujuerpd46hxtnfduhszymhwden5te0wp6hyurvv4cxzeewv4ej7hjm7rj for quick turnaround I want to point out I saw this posted on NOSTR yesterday which was pretty instant and the fact a thread of people calling out to Alby for information worked so well... And alby gets back to us with nostr... Its just so great to see!
2025-10-21 13:31:11 from 1 relay(s) ↑ Parent Reply
this password reset feels like the tip of an iceberg. leaking emails on reset? credential stuffing? this is basic stuff in auth, which brings my to my next point: this screams a homerolled auth system by someone with little experience or a lapse in judgment. id bet the former. wonder what else you’d fine if you looked around. good time to double check those cookie settings and maybe google “owasp top 10” nostr:nevent1qqswh5upmuma0h89vdnh7pnk6ap637xg0mtt0k32hwaxrxm98vuv28cpzemhxue69uhhyetvv9ujuurjd9kkzmpwdejhg0f4n4v
2025-10-21 14:28:00 from 1 relay(s) ↑ Parent Reply
nostr:nprofile1qqsrf5h4ya83jk8u6t9jgc76h6kalz3plp9vusjpm2ygqgalqhxgp9gpzemhxue69uhkzarvv9ejumn0wd68ytnvv9hxgqgkwaehxw309a3xjarrda5kuetj9eek7cmfv9kqs6xl8h coming in with the steel chair. 💪
2025-10-22 01:25:48 from 1 relay(s) ↑ Parent Reply
I actually noticed a request from my email to reset my password that happened yesterday and I just happened to try and reset it today and noticed it while i was searching my inbox.
2025-10-22 01:26:48 from 1 relay(s) ↑ Parent 1 replies ↓ Reply
Good to know that she used Mt.Pelerin. If she did KYC, she should receive it on the same day depending on the payment method she used. If she didn't do KYC, she needs to wait 7 days. That's Mt.Pelerin's policy to ensure they are not scammed.
2025-10-22 06:51:37 from 1 relay(s) ↑ Parent Reply
We noticed that a lot of users used their lightning address instead of email address to log into their Alby Account. To make it easy for them we recognized their lightning address instead of rejecting it and sent them the one-time login code via email. For better guidance we told them the email address, which was a mistake .
2025-10-22 07:07:21 from 1 relay(s) ↑ Parent Reply
I came home and I was surprisingly log out, when I tried and connect my keys were not recognised so I lost access to it , including my primal account. I uninstall the extension but I’m still getting emails and paying ?!
2025-10-22 13:18:58 from 1 relay(s) ↑ Parent Reply
=========================== #2 🔥 Community Highlights =========================== 1. The signal is so high here. We need more meetups/presentations like this. Great work! 🤝 nostr:nevent1qvzqqqqqqypzpdyfuac80dk47xvxj256jak6dc22fvh342ry7l48kn8dqu74uek5qqs2twk5mpesaedvgv80fr557wy74x9wnp6tqvpae643dez7aw599jgyzh40z 2. This time this tremendous character talking to Jeff Jarvis. Watchout who 👇 nostr:nevent1qvzqqqqqqypzqak8r2hr5jglrk0wc37t59lz98x6gyf6pwaku6hpwakhvslznjh6qqs04l5f36jn074cnd48c6ws08gususpnpmu9gt7wvagqghaw8z5p4scpaym4 3. A good news from Miljan. Let’s get ready for Primal 3.0 🤟 nostr:nevent1qvzqqqqqqypzp4sl80zm866yqrha4esknfwp0j4lxfrt29pkrh5nnnj2rgx6dm62qyvhwumn8ghj7urjv4kkjatd9ec8y6tdv9kzumn9wshszymhwden5te0wp6hyurvv4cxzeewv4ej7qpq89fj3q439n3ft30lphvtjuudwkc93sntt3qdfgsad5txruee8avqv59x8t 4. There is no reason to be not 😉 nostr:nevent1qvzqqqqqqypzp2q0cjncvd8wy64tety4rdx0676k4cvt40fnckhaea476mwgp673qqsd3y73s6njvyhps6lum9cddda0sactsh4mn4g7jauehwd22xmljcgcfl9uw 5. Well said by the Nostr memes master 👌 nostr:nevent1qvzqqqqqqypzp78xcep59u0q2fyqvv8z0cgpdh8rtlp6v98xqs60aa92y5pn9r9fqqsytg269hcvcnrrdn8az9nf2txv43z0l4j70yefkcstw3njmath9ngc2t8er 6. Let’s listen to a Nostr speech of Matt Odell 👇 nostr:nevent1qvzqqqqqqypzq5edsvxllcyuz0n4azc5tjp9wx8uz2cqq0mp6c0fqamjr3llly7tqqszeukd3cf7958fkdlgy5vu7z28yugle56evtgcl6n7w26ctrkjrxcjwghtw 7. It is so nice to see plebs like this 💪 nostr:nevent1qqspfapyj0s6prq6ktmk3n8n5f9u9zvhj2kjm3j7fyyygm8ywdkp26cpzemhxue69uhhyetvv9ujuurjd9kkzmpwdejhgq3q88xk4n2quqcpkfgwhlexc7ccrms2qwdhd86eu8hfzk8mtgjzwucsxpqqqqqqz6s7az7 8. This is 100% true 👇 nostr:nevent1qqsps7fn00hpsaj658ed2w2eyjc7tl4erguj8qwhvd468tgnfmxfh6spzemhxue69uhhyetvv9ujuurjd9kkzmpwdejhgq3q8q204nzhrcrrz8875ytkpf8vk0eg649dc98xuqwsz65znph7z5asxpqqqqqqzpakjfq 9. This is the power of Nostr 😍 nostr:nevent1qvzqqqqqqypzpkmztemrw4pu5ltmuegztq6dkvv2p3ahtv8z848mncuj986m5ma8qyt8wumn8ghj7etyv4hzumn0wd68ytnvv9hxgtcprfmhxue69uhkvctwveshyetn9ehx7um5wgcjucm0d5hszrnhwden5te0dehhxtnvdakz7qpqed2epf94sdfdzmz8lda7vt5fvhlpp67l4s0lslzlwcxgyqm9aqjsvj4ajw 10. We must fight for the privacy 🤝 nostr:nevent1qvzqqqqqqypzq5xeflpdskqvdq4swxj59793uvdzqzc9pzatjk3nhmcg2h0js8trqqsyfrevggh0qawdhwp68gtz2dnxhqnvjlttrec3kps9cc9hsv0azushwqtzy 11. Alby adds an another security layer to protect users from attackers 🔏 nostr:nevent1qvzqqqqqqypzq3jhml5fvklgnq9fxpete767txn9zfzqdkc0sxfptmnchfrexje7qqswh5upmuma0h89vdnh7pnk6ap637xg0mtt0k32hwaxrxm98vuv28cxmpjjn 12. Do you agree Nostriches? 🫵 nostr:nevent1qvzqqqqqqypzqx78pgq53vlnzmdr8l3u38eru0n3438lnxqz0mr39wg9e5j0dfq3qqsyykq40vvzdwhsr7xze8n7h2ngludrjg68a77f098qdy5ju3hp8qg44fedw 13. The macro discussion summary of Lyn Alden with her favorite macro analyst 🗒️ nostr:nevent1qvzqqqqqqypzp64suatdx2uqhn2xfu7cgjuqgqcrqadp864uxkv6wckf43atj860qyfhwumn8ghj7ur4wfcxcetsv9njuetn9uq3wamnwvaz7tmjv4kxz7fwwpexjmtpdshxuet59uq32amnwvaz7tmjv4kxz7fwv3sk6atn9e5k7tcqyr9gdf7parcxxa305c9pt0vauh9sd3tznlnasrwgaete7hrad3sazwndr9w 14. An impressive drone show in Lugana, Switzerland 😍 nostr:nevent1qvzqqqqqqypzqx7n9gux57lx76yt8hrufq80cgwdj34586kpfwjt57p543m6y0nfqqsgc559vhxytrevvywzmnsm8jjn9t3wgrxuefrdsanfcnvnlzkpzmq6h40uw 15. A new Nostr based voice and video calling app announced 📲 nostr:nevent1qvzqqqqqqypzqp85ucrkqnxrlzdpeu2gcnssry9t6y6nngjk55lxp9kuqs54zje6qythwumn8ghj7un9d3shjtnswf5k6ctv9ehx2ap0qqsgs25c8k8kcj4r8cu9r7axg6smtyrztz84jeyqmgyzdnajtetn6mszszmfk 16. These things can be happen to a tremendous person 🫂 nostr:nevent1qvzqqqqqqypzqpxfzhdwlm3cx9l6wdzyft8w8y9gy607tqgtyfq7tekaxs7lhmxfqqspkfhlpssysqz8pnwc0cjj2826c680v45v84t9nkgv6zzm8xghk5syvrr4e #community_nostr_recap
2025-10-27 06:59:39 from 1 relay(s) ↑ Parent Reply