The Dropbox attackers were hunting for cryptocurrency seed phrases
Assessment
The evidence is one account. Jameson Lopp, co-founder of Casa, reports the intruder opened exactly one file in his Dropbox, named IMPORTANT.rtf, found it locally encrypted, and left. That behaviour, selective and brief, fits a search for stored keys, and cryptocurrency outlets led coverage. But neither Dropbox nor Lenovo has characterised the targeting, no second victim has described comparable selectivity on the record, and how the 5,000 addresses were chosen is unknown. Plausible, singly sourced, and unconfirmed.
Where this claim appeared
Decrypt · 2026-09-01
https://decrypt.co/377099/dropbox-security-breachWhat “Weak Evidence” means
Evidence exists but is thin, circumstantial, or explicitly qualified as weak by the source that published it. Shared hosting infrastructure between threat clusters is the recurring example.
3 of 5 · rating scale
Assessed in
Dropbox via Lenovo ID: How a Third Party's Email Check Became a Password Bypass for 5,000 AccountsThink this assessment is wrong? Report an error.