Overnight we have received notices of some unusual requests to our infrastructure.
Over a short period of time many password reset emails had been requested from various residential proxies around the world. Our rate limiting protects against spamming attacks but requests got through to request password reset emails.
Many of the requests are likely for emails that had been included in some data breach or have been publicly exposed by their owner.
Password request emails also have been requested for lightning addresses which falsely exposed the user's email address. This had been a feature deployed to help users keep easy access to their accounts. But as many users post their lightning address on profiles like nostr this should not be exposed and a fix has been deployed immediately. Generally there should be no way to display a user's email address. We have failed here. About 5500 password reset emails had been requested by the attacker.
**We have not seen any abnormal related login activity and accounts are safe. People who got a password reset email can ignore the email.**
As we have seen a general increase in attacks on user accounts trying to brute force logins with some emails from some data leaks we have fully disabled password logins and require all users to login with the one time token. This adds an another layer of security.
Additionally we also offer the option to login with Google.
If you have questions or feedback, please let us know: support.getalby.com
Login to reply
Replies (30)
Please note: only Alby Accounts use email-based login. Alby Hub, the Alby Browser Extension, and Alby Go are not affected.
Reset password email will come from alby since it was requested from their website.
Thank you for the transparency.
Just a note, my alby login email address has only ever been used wirh alby so it couldn't have come from another data leak.
Same situation here
Nostr keys are saved locally and encrypted in the Alby Extension and are not affected in any way. Please contact Alby support and we can see if there's any way you are able to recover your lost primal account.
My friend send transfer 1000$ to her Alby hub and she expect received soon . Been 2 days .
Good you informed this
Please ask her to reach out via support.getalby.com so that we can check what exactly happened.
aren't this economic valid requests because they are technically possible and filters dont work?!🎉🤔😎
I think she will received it’s just this is the first time so she will wait til 3 days . You guys mentioned this on your website . It will take 2-3 working days if I am not mistaken .
Right ?
Lightning payments are instant. Fiat payments related to one of the integrated exchange providers depend on there terms of service.
She has alby cloud pro hub , when she wants to top up her bitcoin , she need to buy bitcoin and through the third payment system like Mt. pelerin .. is it not right ? This is not transfer from lightning to lightning payment ..?
Don’t you not know this ?
Same
Same here
Thank you for the update!
I changed my email and disabled password logins as well when I got the password reset request email!
Would prefer using TOTP with an Authenticator instead of email though but I couldn’t find that in the settings.
You used the word too too, I will block you now.
They said password requests were also made against lightning address which is public information.
That shouldn’t be possible going forward 🙏
Yep - good to see it's fixed. Thanks @Alby for quick turnaround
I want to point out I saw this posted on NOSTR yesterday which was pretty instant and the fact a thread of people calling out to Alby for information worked so well... And alby gets back to us with nostr... Its just so great to see!
In this case are you guys going to change account email if your reset was triggered by lightning address?
when time sync MFA?
I changed mine cause I don’t just have one email address.
The transparency is a good start, but you haven't covered the case where a) an unique email address was used that only Alby had and b) wasn't used as lightning address visible anywhere publicly
accounts? where we are going we wont need accounts. #NDN
Email alias for the win
I didn't have a public lightning address. My account email address was only known by Alby
Same here, I realized it was a data breach as the email address I used for Alby was made only for that.
Let's not jump to conclusions without an official statement.
The email address can leak via other channels as well from an Internet connected device...
This concisely explains it, thank you .
I actually noticed a request from my email to reset my password that happened yesterday and I just happened to try and reset it today and noticed it while i was searching my inbox.
That was a failure. Good that you already used a dedicated address.
Let us know if we can improve other things: 
👤 Alby Accounts - 💡 Request a Feature | Alby