Crypto Exchanges
By Dan Saada
1 / 15
How the Attack Worked. Security researcher Abdel Sabbah tore apart the breach mechanics.
2 / 15
What Robinhood Isn't Saying. Protos reached out to Robinhood for comment. No response came back before publication.
3 / 15
What Users Can Actually Do. Standard advice still applies, even if it feels inadequate. Don't click links in unexpected emails.
4 / 15
Robinhood customers got hammered by phishing emails over the weekend. Not the usual junk. These looked real.
5 / 15
The messages came from noreply@robinhood.com, carried all the right authentication stamps, and slipped past spam filters like they belonged there.
6 / 15
Security researcher Abdel Sabbah tore apart the breach mechanics. Attackers used what's called Gmail's "dot trick." Gmail ignores periods in email addresses—john.doe@gmail.
7 / 15
The phishing messages wanted login credentials. They wanted two-factor authentication codes. They wanted access to funds, basically. And the scary part?
8 / 15
Ripple's David Schwartz jumped on the warnings pretty fast. He'd seen something similar before—back in April 2025, attackers pulled off a comparable stunt using Google's own…
9 / 15
Traditional advice tells you to verify the sender's domain. Check for authentication failures. Look for typos or weird formatting. None of that helped here.
10 / 15
Protos reached out to Robinhood for comment. No response came back before publication. The company's stock opened unchanged on Nasdaq Monday morning.
11 / 15
The silence from Robinhood raises questions. What's the company doing to fix the notification pipeline? How many users got hit? How much money walked out the door?
12 / 15
And that's kind of the problem. Being careful doesn't cut it when the attacks are this sophisticated.
13 / 15
Related: US Military Runs Bitcoin Node as Pentagon Eyes Crypto for Defense Operations
14 / 15
Email authentication protocols like DKIM were supposed to solve this. They verify that messages actually come from who they claim to come from.
15 / 15
The Gmail dot trick isn't new. Security researchers have warned about it for years. But Robinhood's failure to normalize email addresses before sending notifications created an…
The Currency Analytics
Want the full story?