📈 Get daily crypto insights that make you smarter about your money

Authy Data Breach Exposes 33 Million Phone Numbers in Major 2FA Security Failure

The cryptocurrency community faces a significant security wake-up call after Twilio confirmed that its popular two-factor authentication app, Authy, suffered a data breach exposing the phone numbers of approximately 33 million users. The breach, publicly disclosed on July 1, 2024, and widely reported on July 5, was claimed by the notorious hacking group ShinyHunters, who posted the stolen data on BreachForums. With Bitcoin trading at $56,662 and Ethereum at $2,981, the timing of this breach adds another layer of anxiety to an already volatile market rattled by Mt. Gox repayment distributions.

The Exploit Mechanics

Twilio revealed that the attackers exploited an unauthenticated endpoint in the Authy infrastructure. In simple terms, this means there was a vulnerability in the API that allowed anyone to query user data without providing credentials. ShinyHunters leveraged this oversight to systematically harvest phone numbers and account IDs associated with Authy accounts. Twilio stated that the compromised data included phone numbers and Authy account IDs, but stressed that no passwords, two-factor authentication seeds, or other sensitive account details were accessed. The company has since secured the endpoint and no longer allows unauthenticated requests.

Affected Systems

Authy is one of the most widely used authenticator applications in the cryptocurrency ecosystem. Binance, Gemini, and Crypto.com have all at various points recommended or endorsed Authy as a preferred 2FA solution for their platforms. The breach therefore directly impacts a substantial portion of the crypto-using population. With over 33 million phone numbers exposed, the scope is enormous. The exposed data does not directly grant access to crypto wallets or exchange accounts, but it provides attackers with a powerful tool for targeted social engineering campaigns. Phone numbers tied to known crypto users are particularly valuable to attackers because they can be used for SIM-swap attacks, smishing campaigns, and targeted phishing attempts that impersonate crypto exchanges or wallet providers.

The Mitigation Strategy

Twilio has released emergency updates for the Authy app across both major platforms. Users on Android should update to version 25.1.0 or later, while iOS users need version 26.1.0 or later. These updates include patches for the exploited vulnerability and additional security hardening. Beyond simply updating the app, security researchers recommend several additional steps. Tim Jenkins, Head of Cyber Defense Research at SentryBay, emphasized that while the breach may seem limited, the exposed phone numbers enable highly convincing phishing attacks. He noted that threat actors can now impersonate Authy and Twilio directly to users, making phishing attempts far more credible and dangerous.

Lessons Learned

This breach underscores a fundamental truth in cybersecurity: the security of your assets is only as strong as the weakest link in your authentication chain. Authy, as a centralized 2FA provider, became a single point of failure for millions of users. The incident highlights the risks inherent in relying on cloud-connected authentication services that store user metadata on external servers. For cryptocurrency users specifically, this is a stark reminder that even security tools themselves can become attack vectors. The breach also demonstrates that unauthenticated API endpoints remain a persistent and dangerous class of vulnerability in modern web services.

User Action Required

All Authy users should immediately update the app to the latest version. Beyond that, crypto holders should consider migrating to alternative 2FA solutions that do not rely on cloud-connected phone number databases. Hardware security keys, such as YubiKey, offer a significantly more secure alternative by requiring physical possession of the device for authentication. Users should also be hyper-vigilant about any unsolicited calls or text messages claiming to be from Authy, Twilio, or any cryptocurrency exchange. As the crypto market navigates the turbulence of Mt. Gox repayments and broader selling pressure, security vigilance has never been more important.

Disclaimer: This article is for informational purposes only and does not constitute financial or security advice. Always conduct your own research before making security decisions regarding your cryptocurrency holdings.

🌱 FOR BUSINESSES BitcoinsNews.com
Reach 100K+ Crypto Readers
Sponsored content, press releases, banner ads, and newsletter placements. Put your brand in front of Bitcoin's most engaged audience.

26 thoughts on “Authy Data Breach Exposes 33 Million Phone Numbers in Major 2FA Security Failure”

  1. privacyorbust

    33 million phone numbers from a 2fa app is beyond ironic. the thing supposed to protect you becomes the attack vector

    1. 2fa_exhausted

      shinyhunters posting on breachforums with 33M records and twilio could only say ‘no seeds were compromised’. phone numbers alone enable SIM swaps. thats the real damage

    2. 33 million phone numbers from a 2fa app is beyond ironic. the thing supposed to protect you becomes the attack vector

      1. 2fa_refugee 33M phone numbers from a 2FA app is dark comedy. SIM swap crews were probably celebrating when that dump hit breachforums

      2. shinyhunters_track

        shinyhunters claiming it on breachforums means everyone with authy should rotate numbers fast

      3. 2fa_refugee the irony is lethal. 33M phone numbers from the app designed to protect your accounts. sim swap crews got a christmas list

  2. ShinyHunters exploiting an unauthenticated endpoint in 2024 is embarrassing for Twilio. This is security 101 stuff.

    1. twilio also had that employee phishing attack in 2022. at what point do we stop trusting them with auth infrastructure

    2. unauthenticated endpoint in 2024. this isnt some startup, its twilio. they have the budget and the talent to do better

      1. an unauthenticated endpoint in their auth infrastructure in 2024. twilio charges enterprise prices for authy and cant do basic API security

        1. hardware_key_advocate

          switched to yubikey after this. sms 2fa is broken, phone-based apps are broken. hardware keys are the only thing that actually work

          1. hardware_key_advocate yubikey is great until you lose it and have no backup. most people are not running dual key setups for their exchange accounts

          2. Beata K. losing a yubikey is scary but losing your phone number to a sim swap is worse. at least you can backup a hardware key

        2. twilio_critic

          unauthenticated endpoint in auth infrastructure in 2024? twilio charges enterprise prices and cant do basic api security

          1. twilio_critic unauthenticated endpoint in 2024 from a company charging enterprise prices for auth. theres no excuse for that level of negligence in security infrastructure

  3. rust_not_async

    unauthenticated endpoint on a 2FA app is beyond ironic. Twilio sold security software and couldnt secure their own API. 33M phone numbers in the wild enables SIM swap chains for years

  4. authy_breach_rat

    33m phone numbers exposed via unauthenticated endpoint on july 1 with btc at 56662 raises sim swap fears

  5. twilios post-mortem said no seeds were compromised but phone numbers alone are enough for targeted sim swaps. they downplayed it because the real damage is downstream

    1. tobias_k exactly. 33M numbers mapped to authy accounts tells you exactly who uses 2FA. thats a target list for sim swappers

  6. seed_phraser_

    switched everyone in my family to hardware keys after this. my mom has a yubikey on her keychain now. authy is dead to me

  7. ShinyHunters posting on BreachForums like its 2015. same group, same playbook, still finding unauthenticated endpoints. youd think 2FA providers would audit their own attack surface

  8. 33M phone numbers from a 2FA provider and twilio spun it as no big deal because seeds werent leaked. phone numbers enable the entire sim swap chain

    1. sim_swap_survivor

      Dimitrios L. phone numbers being the leak is the worst part. you cant just change your number across 50 accounts in one afternoon

  9. switched to hardware keys after this breach. phone-based 2FA is fundamentally broken when the phone number itself is the leak

    1. switched to yubikey after this. SMS 2FA is broken, phone-based apps are broken. hardware keys are the only thing left that actually work

  10. ShinyHunters finding an unauthenticated endpoint on a 2FA provider is the most embarrassing thing in infosec this decade. twilio charges premium prices

Leave a Comment

Your email address will not be published. Required fields are marked *

BTC$64,784.00-0.2%ETH$1,916.49+0.1%SOL$76.27+2.0%BNB$602.84+1.4%XRP$1.04+0.2%ADA$0.1988-0.5%DOGE$0.0701-0.1%DOT$0.8099-1.0%AVAX$6.48-0.7%LINK$8.33+0.9%UNI$3.96-0.7%ATOM$1.38+0.5%LTC$46.13+1.4%ARB$0.0777-1.3%NEAR$1.62+2.2%FIL$0.7102+1.0%SUI$0.6920+1.3%BTC$64,784.00-0.2%ETH$1,916.49+0.1%SOL$76.27+2.0%BNB$602.84+1.4%XRP$1.04+0.2%ADA$0.1988-0.5%DOGE$0.0701-0.1%DOT$0.8099-1.0%AVAX$6.48-0.7%LINK$8.33+0.9%UNI$3.96-0.7%ATOM$1.38+0.5%LTC$46.13+1.4%ARB$0.0777-1.3%NEAR$1.62+2.2%FIL$0.7102+1.0%SUI$0.6920+1.3%
Scroll to Top