# Tata's B2B platform returned OTPs in API responses

DevFeed: [Tata's B2B platform returned OTPs in API responses](<https://devfeed.tech/articles/tata-s-b2b-platform-returned-otps-in-api-responses-32624.md>)

Original publisher: [Read original article](<https://eaton-works.com/2026/08/24/tata-nexarc-hack/>)

Author: Eaton

Published: 2026-08-24T14:25:14Z

Content type: article

Language: en

Sources: [Eaton Works Feed](<https://devfeed.tech/sources/eaton-works-feed.md>)

Topics: [vulnerability](<https://devfeed.tech/topics/vulnerability.md>), [account takeover](<https://devfeed.tech/topics/account-takeover.md>), [API](<https://devfeed.tech/topics/api.md>), [Encryption](<https://devfeed.tech/topics/encryption.md>), [Binance](<https://devfeed.tech/topics/binance.md>)

Tags: [account-takeover](<https://devfeed.tech/tags/account-takeover.md>), [api](<https://devfeed.tech/tags/api.md>), [b2b](<https://devfeed.tech/tags/b2b.md>), [encryption](<https://devfeed.tech/tags/encryption.md>), [platform](<https://devfeed.tech/tags/platform.md>), [vulnerability](<https://devfeed.tech/tags/vulnerability.md>)

## AI overview

A security write-up describes a vulnerability in Tata nexarc that returned OTPs in API responses. Because the responses could be decrypted client-side, an attacker with a target's phone number could obtain the OTP and take over the account, including accounts with administrative privileges.

## Source excerpt

Tata's nexarc platform had a vulnerability where OTPs could be decrypted from API responses, making it easy to take over any account.