Critical safety advice

Hello everyone,

It’s the second time in two months that they steal my sendgrid API keys and send emails from my account. The thing seems strange to me since I have two-factor authentication and the key is set as private inside Bubble..

Did it happen to someone else? Do you have any advice on this?

I assume you have changed the API key each time. I don’t think they break your 2FA for Sendgrid. Secure your Bubble account, maybe with Google Login and add 2FA. Is your app editor public? Does anyone have access to your editor?

Yes I had to change it.. Of course.. my editor is private, I have login with google and 2fa on bubble.. That’s why I’m really surprised that it can happen.. twilio obviously said it’s not their fault for this loss.. but I don’t have anything else in mind..

Have you tried NQU Secure | Not Quite Unicorns to check where it’s leaking?