Dropbox Watchdog

Search issues

Search the Dropbox Watchdog archive

All issues

Daedalus Blue v. Dropbox: ex-IBM patents aimed at Magic Pocket and Dropbox's API

2024 onward

MediumStatus: OngoingProduct: Dropbox APIYear: 2024

Patent-assertion entity Daedalus Blue, holder of former IBM patents, sued Dropbox in August 2024, accusing the Dropbox API, the Magic Pocket storage system, and the Nautilus search engine of infringement; Dropbox's eligibility challenge was granted only in part, leaving the case alive.

What happened

Daedalus Blue, LLC — a patent-assertion entity that acquired a portfolio of former IBM patents — sued Dropbox in the U.S. District Court for the District of Delaware (Daedalus Blue, LLC v. Dropbox, Inc., No. 1:24-cv-00998), filing on 30 August 2024. The complaint asserted at least U.S. Patent Nos. 7,542,957; 8,176,269; and 8,131,726, and accused several Dropbox systems of infringement, including the Dropbox API, the Magic Pocket storage infrastructure, and the Nautilus search engine. Daedalus Blue alleged that the patents had previously been licensed to many companies — including Amazon, Oracle, and Dropbox itself — but that the relevant license had expired.

Dropbox moved to dismiss, arguing that all asserted claims were directed to patent-ineligible subject matter under 35 U.S.C. Section 101. The court recommended granting the motion in part and denying it in part, meaning some claims survived the eligibility challenge while others did not — so the litigation continued rather than being dismissed outright.

As of the court's 2025 recommendation on Dropbox's motion to dismiss, the allegations remain unproven and there is no finding of infringement or liability against Dropbox; the matter remains pending.

Impact

Daedalus Blue directly targets Dropbox's internal infrastructure — Magic Pocket, the storage system Dropbox built to move off Amazon's cloud, and its Nautilus search engine — placing core engineering at the center of a live patent fight. The partial survival of the claims past the Section 101 stage means Dropbox faces continued litigation exposure rather than an early exit, and the case is one of the company's active post-2024 legal matters.

Dropbox's Response / Official Position

Dropbox moved to dismiss the complaint on patent-eligibility grounds under Section 101; the motion was granted in part and denied in part, leaving some claims to proceed. Dropbox is defending the remaining claims and discloses material patent litigation in its SEC filings.

Sources

Related guides

Spot an error, or have a source to add?
Report an error / suggest update

Related issues

9 sources
HighApproximately 5,000 accounts; files accessed in fewer than a third (about 1,500 by 9to5Mac's arithmetic)

The 2026 Lenovo ID sign-in flaw: ~5,000 Dropbox accounts entered without a Dropbox password

A flaw in how Lenovo verified account-holder email addresses let an attacker register a Lenovo ID on a victim's email, and Dropbox's Lenovo ID sign-in link then trusted that identity without ever asking for a Dropbox password — reaching roughly 5,000 accounts.

Security Incidents & Data BreachesCurrent / Ongoing Issues (2024–2026)
Read documentation

In an 8-K filed May 26, 2026, Dropbox disclosed that co-founder Drew Houston would step back as CEO after 19 years, with the Board appointing Ashraf Alkarmi — its General Manager, Core — as Co-Chief Executive Officer effective that date, ahead of Alkarmi becoming sole CEO and Houston moving to executive chairman 'following a transition period.' The handoff arrives as AI upends the software era Dropbox grew up in and the company's revenue sits near flat.

Product Changes & User BacklashCurrent / Ongoing Issues (2024–2026)
Read documentation

Dropbox's Q1 and Q2 2026 results both kept total reported revenue growth under 1% year-over-year, the company refinanced debt and repurchased hundreds of millions of dollars in stock over the same six months, and the period closed with a co-CEO handoff, a new product chief, and a routine, tax-related insider stock disposition reported by the Motley Fool.

Pricing & Business PracticesCurrent / Ongoing Issues (2024–2026)
Read documentation

ConsentFix, an OAuth-consent phishing technique first documented by Push Security in December 2025 and reported on independently through mid-2026, delivers its Microsoft 365 lures through trusted file-hosting platforms — reporting names both Dropbox and DocSend (a Dropbox company) as hosts for the password-protected files attackers use to get past mail filters.

Security Incidents & Data BreachesCurrent / Ongoing Issues (2024–2026)
Read documentation