ThreatPaper
Weak Evidence

The Dropbox attackers were hunting for cryptocurrency seed phrases

Assessment

The evidence is one account. Jameson Lopp, co-founder of Casa, reports the intruder opened exactly one file in his Dropbox, named IMPORTANT.rtf, found it locally encrypted, and left. That behaviour, selective and brief, fits a search for stored keys, and cryptocurrency outlets led coverage. But neither Dropbox nor Lenovo has characterised the targeting, no second victim has described comparable selectivity on the record, and how the 5,000 addresses were chosen is unknown. Plausible, singly sourced, and unconfirmed.

Where this claim appeared

Decrypt · 2026-09-01

https://decrypt.co/377099/dropbox-security-breach

What “Weak Evidence” means

Evidence exists but is thin, circumstantial, or explicitly qualified as weak by the source that published it. Shared hosting infrastructure between threat clusters is the recurring example.

3 of 5 · rating scale

Assessed in

Dropbox via Lenovo ID: How a Third Party's Email Check Became a Password Bypass for 5,000 Accounts

Think this assessment is wrong? Report an error.