Close Menu

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    What's Hot

    Ripple’s CTO  flags phishing emails targeting Robinhood users

    April 27, 2026

    XRP Healthcare launches XRPHAI token trading on MEXC

    April 27, 2026

    Luxor expands MicroBT partnership with $100 million mining rig deal

    April 27, 2026
    Facebook X (Twitter) Instagram
    Facebook X (Twitter) Instagram LinkedIn
    Ai Crypto TimesAi Crypto Times
    • Altcoins
      • Coinbase
      • Litecoin
      • Bitcoin
    • Ethereum
    • Crypto
    • Blockchain
    • Lithosphere News Releases
    Ai Crypto TimesAi Crypto Times
    Home » Ripple’s CTO  flags phishing emails targeting Robinhood users
    Crypto

    Ripple’s CTO  flags phishing emails targeting Robinhood users

    James WilsonBy James WilsonApril 27, 2026No Comments3 Mins Read
    Facebook Twitter Pinterest LinkedIn Tumblr Email
    Share
    Facebook Twitter LinkedIn Pinterest Email



    Ripple’s former CTO David Schwartz has warned that a targeted phishing campaign has begun exploiting Robinhood users through seemingly legitimate emails ahead of the firm’s earnings report.

    Summary

    • David Schwartz has warned that phishing emails targeting Robinhood users are passing authentication checks and mimicking official alerts.
    • Attackers have exploited email system gaps to embed malicious links inside legitimate-looking messages sent from Robinhood’s infrastructure.

    According to Schwartz, the attack involves emails that appear to originate from Robinhood’s own system, with authentication checks such as SPF, DKIM, and DMARC passing successfully, making the messages appear genuine to recipients. 

    “WARNING: Any emails you get that appear to be from Robinhood (and may actually be from their email system) are phishing attempts,” he wrote in a post on X.

    Details shared by Schwartz show that the emails include a login alert listing time, device, and a case ID, alongside a prompt urging users to “Review Activity Now.” The message layout and branding mirror official communication, yet the embedded button reportedly initiates a phishing sequence designed to capture user credentials.

    Explaining the unusual delivery method, Schwartz said he believes the emails were “somehow injected into Robinhood’s actual email infrastructure,” later describing the exploit as “quite sneaky.” 

    The ability to pass standard authentication checks increases the likelihood of users trusting the communication, according to his observation.

    Exploit tied to email system manipulation

    Insight referenced by Schwartz from Abdel Sabbah outlines a possible attack vector involving Gmail’s “dot trick,” which allows multiple variations of the same email address. Sabbah said attackers created a Robinhood account using such variations and assigned a device name embedded with malicious HTML code.

    Robinhood’s system, according to Sabbah, does not sanitize this field, allowing the HTML payload to render inside official emails sent from [email protected]. The result is a fully authenticated message that appears legitimate but contains hidden malicious elements.

    Phishing scams continue to target crypto users

    Phishing attacks have continued to pose a persistent risk to cryptocurrency users, with multiple campaigns reported across wallet platforms in recent days.

    As previously reported by crypto.news, MetaMask users were targeted by a phishing campaign that promoted a fake two-factor authentication process, according to blockchain security firm SlowMist. The spoofed emails used MetaMask branding and included a countdown timer designed to pressure users into immediate action.

    SlowMist said victims who clicked the “Enable 2FA Now” prompt were redirected to a malicious website that requested their seed phrase, giving attackers full access to wallet funds. The firm noted that such campaigns often rely on small inconsistencies, including misspelled domains and unusual sender addresses, to bypass initial scrutiny.



    Source link

    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
    James Wilson

    Related Posts

    XRP Healthcare launches XRPHAI token trading on MEXC

    April 27, 2026

    Luxor expands MicroBT partnership with $100 million mining rig deal

    April 27, 2026

    Justin Sun sets 2026 timeline for TRON quantum-resistant upgrade

    April 27, 2026

    Comments are closed.

    Our Picks
    Stay In Touch
    • Facebook
    • Twitter
    • Pinterest
    • Instagram
    • YouTube
    • Vimeo
    Don't Miss

    Ripple’s CTO  flags phishing emails targeting Robinhood users

    Crypto April 27, 2026

    Ripple’s former CTO David Schwartz has warned that a targeted phishing campaign has begun exploiting…

    XRP Healthcare launches XRPHAI token trading on MEXC

    April 27, 2026

    Luxor expands MicroBT partnership with $100 million mining rig deal

    April 27, 2026

    Justin Sun sets 2026 timeline for TRON quantum-resistant upgrade

    April 27, 2026

    Subscribe to Updates

    Get the latest creative news from SmartMag about art & design.

    X (Twitter) Instagram YouTube LinkedIn
    Our Picks

    ETH crashes to four-year low against BTC

    March 17, 2026

    Kevin Warsh discloses crypto and AI investments ahead of Senate Fed hearing

    April 15, 2026

    How to delete Netflix history

    April 14, 2026
    Recent Posts

    Ripple’s CTO  flags phishing emails targeting Robinhood users

    April 27, 2026

    XRP Healthcare launches XRPHAI token trading on MEXC

    April 27, 2026

    Luxor expands MicroBT partnership with $100 million mining rig deal

    April 27, 2026

    Type above and press Enter to search. Press Esc to cancel.