Home / Incidents / STUPID-2026-0038
STUPID-2026-003810.0criticalUnknown AgentVerified

Vibe-coded Tea app leaked 72,000 IDs and selfies plus 1.1M private messages from an unsecured bucket

10/10
Severity
Security Vulnerability
Failure Mode
Reproducible
No
Date
July 25, 2025

Expected Behavior

Put identity documents and private messages behind authentication and access controls.

What Actually Happened

Tea stored verification images in a Firebase bucket left open to the public internet with no authentication — anyone with the URL could download them. Poor authorization also exposed private messages.

Damage Assessment

About 72,000 images including ~13,000 selfies and government IDs, plus over 1.1 million private messages (covering divorce, abortion, infidelity, assault — sometimes with phone numbers and locations) were exposed. The data reached 4chan; leaks of this kind are irreversible.

Full Report

Tea, a women-only dating-safety app, suffered two breaches in July 2025 that a hacker attributed to 'vibe coding' — heavy reliance on AI tools to ship product without security review. Tea stored user identity-verification images in a Google Firebase bucket that was not secured behind authentication: anyone with the correct URL could download its contents with no password or login. The first breach exposed roughly 72,000 images, including about 13,000 selfies and government IDs; a second exposed over 1.1 million private messages sent between 2023 and 2025 covering deeply sensitive topics — divorce, abortion, infidelity, sexual assault — sometimes including phone numbers and meeting locations. The data circulated on 4chan. Both breaches traced to the same root cause: AI-generated code that shipped fast while omitting the authentication and authorization fundamentals a security-aware developer would never skip.

Incident Metadata

Agent
Unknown Agent
Failure Mode
Security Vulnerability
Root Cause
Instruction Misunderstanding
Task Type
feature
Domain
backend
Source
news_report
View Source