Loading HuntDB...

Requestor Email Disclosure via Email Notification

Low
C
Coinbase
Submitted None

Team Summary

Official summary from Coinbase

When a Coinbase user requests money from another coinbase user, the user that receives the request sees an email that says, in part: John Smith ([email protected]) sent you a request to pay 1 BTC using Coinbase. Where John Smith is the sending account's display name (meaning you can make it whatever you want), and [email protected] is the sending account's verified email address. This is done intentionally, as without an identifier like an email address in the request, it would be impossible to tell the difference between the actual John Smith and someone claiming to be John Smith. If Coinbase users wish to receive money while disclosing less information about themselves, Coinbase allows users to create single use BTC addresses that can receive payments (https://support.coinbase.com/customer/portal/articles/1816349-how-do-i-get-a-bitcoin-address-).

Reported by japz

Report Details

Additional information and metadata

State

Closed

Substate

Informative

Submitted

Weakness

Information Disclosure