• Home
  • News
    • Bitcoin
    • Ethereum
    • Altcoins
    • NFTs
    • Blockchain
    • DeFi
    • AI
    • Policies
  • Market
    • Trends
    • Analysis
  • Interviews
  • Discover
    • For Beginners
    • Tips
  • All Posts
Hot News

Astar Lowers Base Staking Rewards to Mitigate Inflationary Pressure

2025-04-18

Imminent Bitcoin Price Volatility as Speculators Transfer 170K BTC — CryptoQuant

2025-04-18

Spar Supermarket in Switzerland Begins Accepting Bitcoin Payments

2025-04-18
Facebook X (Twitter) Instagram
X (Twitter) Telegram
BlockoalaBlockoala
  • Home
  • News
    • Bitcoin
    • Ethereum
    • Altcoins
    • NFTs
    • Blockchain
    • DeFi
    • AI
    • Policies
  • Market
    • Trends
    • Analysis
  • Interviews
  • Discover
    • For Beginners
    • Tips
  • All Posts
Subscribe
BlockoalaBlockoala
Home » Authy 2FA app inadvertently disclosed potentially exploitable phone numbers for text phishing purposes
Blockchain

Authy 2FA app inadvertently disclosed potentially exploitable phone numbers for text phishing purposes

2024-07-03No Comments2 Mins Read
Facebook Twitter Pinterest LinkedIn Tumblr Email
Share
Facebook Twitter LinkedIn Pinterest Email

Hackers managed to breach the Authy Android app database and were able to extract information linked to accounts, such as phone numbers, as per a security alert published on July 1 by Twilio, the developer of the app. The security notice clarified that the accounts themselves remained secure, indicating that the attackers did not access authentication credentials. However, the exposed phone numbers could potentially be utilized in future phishing and smishing attempts. To address this potential risk, Twilio advised Authy users to remain vigilant and exercise caution regarding the messages they receive.

Twilio’s security alert concerning the Authy data breach can be seen in the provided image from Twilio.

Authy is a popular choice among centralized exchange users for implementing two-factor authentication (2FA). This process involves generating a code on the user’s device, which the exchange might request before processing withdrawals, transfers, or other critical transactions. Authy serves as the default 2FA application for exchanges like Gemini and Crypto.com, while platforms such as Coinbase, Binance, and numerous others offer it as an alternative.

The breach occurred through an “unauthenticated endpoint,” according to the security alert. Steps have been taken to secure this endpoint, preventing any further unauthenticated requests within the app. Users are advised to update to the latest version of the application, which includes enhanced security features.

Twilio assured users that their authenticator codes remained secure and inaccessible to the attackers, thus safeguarding their exchange accounts. The company stated that there was no indication of the threat actors breaching Twilio’s systems or acquiring other sensitive data.

Reports suggest that the cybercriminal group ShinyHunters executed the hack, leaking a document containing approximately 33 million phone numbers registered with Authy. In a separate incident in 2021, the same group was linked to an AT&T data breach, which exposed data from over 51 million customers.

Authenticator apps were designed to combat SIM swap attacks, a form of social engineering where the attacker convinces a phone provider to transfer the user’s number to them. This access allows the attacker to intercept the user’s 2FA codes without physical possession of their device.

Despite the prevalence of such attacks, with some users continuing to receive 2FA codes via text messages rather than through an app, instances like the recent losses suffered by OKX users due to SIM swap attacks highlight the ongoing risks in the digital security landscape.

Share. Facebook Twitter Pinterest LinkedIn Tumblr Email

Related Posts

Astar Lowers Base Staking Rewards to Mitigate Inflationary Pressure

2025-04-18

Imminent Bitcoin Price Volatility as Speculators Transfer 170K BTC — CryptoQuant

2025-04-18

Spar Supermarket in Switzerland Begins Accepting Bitcoin Payments

2025-04-18

Sygnum Predicts Potential Altcoin Surge in Q2 2025 Due to Enhanced Regulations

2025-04-18
Add A Comment

Leave A Reply Cancel Reply

Editors Picks

Astar Lowers Base Staking Rewards to Mitigate Inflationary Pressure

2025-04-18

Imminent Bitcoin Price Volatility as Speculators Transfer 170K BTC — CryptoQuant

2025-04-18

Spar Supermarket in Switzerland Begins Accepting Bitcoin Payments

2025-04-18

Sygnum Predicts Potential Altcoin Surge in Q2 2025 Due to Enhanced Regulations

2025-04-18
Latest Posts

Astar Lowers Base Staking Rewards to Mitigate Inflationary Pressure

2025-04-18

Imminent Bitcoin Price Volatility as Speculators Transfer 170K BTC — CryptoQuant

2025-04-18

Spar Supermarket in Switzerland Begins Accepting Bitcoin Payments

2025-04-18
Blockoala
X (Twitter) Telegram
  • Home
  • News
  • Market
  • Interviews
  • Discover
  • All Posts
Copyright © 2025 Blockoala. All rights reserved.

Type above and press Enter to search. Press Esc to cancel.