Overnight we have received notices of some unusual requests to our infrastructure.
Over a short period of time many password reset emails had been requested from various residential proxies around the world. Our rate limiting protects against spamming attacks but requests got through to request password reset emails.
Many of the requests are likely for emails that had been included in some data breach or have been publicly exposed by their owner.
Password request emails also have been requested for lightning addresses which falsely exposed the user's email address. This had been a feature deployed to help users keep easy access to their accounts. But as many users post their lightning address on profiles like nostr this should not be exposed and a fix has been deployed immediately. Generally there should be no way to display a user's email address. We have failed here. About 5500 password reset emails had been requested by the attacker.
**We have not seen any abnormal related login activity and accounts are safe. People who got a password reset email can ignore the email.**
As we have seen a general increase in attacks on user accounts trying to brute force logins with some emails from some data leaks we have fully disabled password logins and require all users to login with the one time token. This adds an another layer of security.
Additionally we also offer the option to login with Google.
If you have questions or feedback, please let us know: support.getalby.com
Thread
Login to reply
Replies (31)
My friend send transfer 1000$ to her Alby hub and she expect received soon . Been 2 days .
Please ask her to reach out via support.getalby.com so that we can check what exactly happened.
I think she will received itβs just this is the first time so she will wait til 3 days . You guys mentioned this on your website . It will take 2-3 working days if I am not mistaken .
Right ?
Lightning payments are instant. Fiat payments related to one of the integrated exchange providers depend on there terms of service.
She has alby cloud pro hub , when she wants to top up her bitcoin , she need to buy bitcoin and through the third payment system like Mt. pelerin .. is it not right ? This is not transfer from lightning to lightning payment ..?
Donβt you not know this ?
Good to know that she used Mt.Pelerin. If she did KYC, she should receive it on the same day depending on the payment method she used.
If she didn't do KYC, she needs to wait 7 days. That's Mt.Pelerin's policy to ensure they are not scammed.
I've read something about failure but all I can see is responsible and honest approach.
View quoted note β
Hey @Alby - please allow passkey login. My account shouldnβt be constrained solely by email. Email is not a suitable 2FA method. Username + password + TOTP or email token + TOTP are good, but Passkey is better because it requires a device you possess already and doesnβt rely on email thatβs phishable. Iβve seen other sites go further and require TOTP after a Passkey too, fwiw. Point being, give uses the option for real 2FA decoupled from email.
I'd love passkeys in Alby! Passed it on
Thanks for your feedback Gene and sorry for the mistake.
Could you add your ideas to our feedback board then we can prioritize it: 
π€ Alby Accounts - π‘ Request a Feature | Alby
Thank you for the update!
I changed my email and disabled password logins as well when I got the password reset request email!
Would prefer using TOTP with an Authenticator instead of email though but I couldnβt find that in the settings.
Thanks for acting and sorry again.
Could you upvote or add other features to our feedback board? 
π€ Alby Accounts - π‘ Request a Feature | Alby
βHide My Emailβ is probably one of my favorite iOS features.
Websites really need to stop using email as an authentication method. There are better options that preserve privacy.
when time sync MFA?
For info, the email resets received on our side were set up specifically for internal testing and never shared anywhere
Good luck with the investigation and thanks for the transparency! Hope we can all learn something.
Thanks for your understanding and sorry for the mistake. We are getting better.
If the service wasn't already shitty enough. Charging way too much money and the service is crap. Can't even talk to a person without paying. Now they leaked my personal data. Great. Thanks for nothing
If you really want you can get in touch with Alby anytime using the chat widget on support.getalby.com and I bet you'll receive a reply within 12 hours from a human, not a bot.
accounts? where we are going we wont need accounts. #NDN
2FA would be nice β‘οΈ
Thanks for your feedback. If you could upvote and leave add other ideas here:
That would be great.
Offer 2FA for account login | π€ Alby Accounts - π‘ Request a Feature | Alby
.. as an additional security mechanism for my Alby account.
Done β‘οΈ
@ZEUS coming in with the steel chair. πͺ
I actually noticed a request from my email to reset my password that happened yesterday and I just happened to try and reset it today and noticed it while i was searching my inbox.
Let us know, if we can help anytime: support.getalby.com
please allow passkey
Thanks for the feedback.
I have already canceled my subscription a few weeks ago β¦
Any advice on how to manage this.


@bevo