Awaken crypto tax platform suffered a data breach; attacker stole user emails and is mass-creating accounts using the leaked list.
Security & Exploits ·
A data breach at AwakenTax, a cryptocurrency tax platform, exposed user email addresses that were subsequently misused by an attacker. On August 27, 2026, the platform's founder disclosed that the compromise occurred on April 1st, with the attacker subsequently leveraging the stolen emails to mass-create accounts and send platform invitations to affected users.
The attacker's strategy involves a two-stage approach. The immediate wave of invitations originate from the platform itself and pose minimal direct risk, but serve as reconnaissance for a follow-up phishing campaign. The attacker plans to impersonate AwakenTax by sending emails from spoofed domains they control, targeting users who have already received the platform invitations. AwakenTax is implementing additional rate-limiting controls to constrain the volume of fraudulent account creation.
The company has advised users to remain cautious and disregard unexpected invitations from the platform, while remaining alert for phishing attempts via external email addresses. The extent of the breach—such as how many user emails were exposed or whether any additional data beyond email addresses was compromised—has not been disclosed. The effectiveness of the additional rate-limiting measures in preventing further unauthorized account creation remains to be seen.