Update on the @Alby attack:
β οΈ ITβS WORSE THAN I THOUGHT! β οΈ
What I believe is happening is someone is using the public Lightning addresses from Nostr profiles to doxx everyoneβs registered email address on Alby.
By simply entering a valid Alby address, the login page LEAKS the corresponding email address.
This means that the purpose of the attack is not so much to breach your Alby account, itβs to collect emails of Alby users for future phishing attacks.



