Vibe-coded Tea app leaked 72,000 IDs and selfies plus 1.1M private messages from an unsecured bucket
10/10
Severity
Security Vulnerability
Failure Mode
Reproducible
No
Date
July 25, 2025
Expected Behavior
Put identity documents and private messages behind authentication and access controls.
What Actually Happened
Tea stored verification images in a Firebase bucket left open to the public internet with no authentication — anyone with the URL could download them. Poor authorization also exposed private messages.
Damage Assessment
About 72,000 images including ~13,000 selfies and government IDs, plus over 1.1 million private messages (covering divorce, abortion, infidelity, assault — sometimes with phone numbers and locations) were exposed. The data reached 4chan; leaks of this kind are irreversible.
Full Report
Tea, a women-only dating-safety app, suffered two breaches in July 2025 that a hacker attributed to 'vibe coding' — heavy reliance on AI tools to ship product without security review. Tea stored user identity-verification images in a Google Firebase bucket that was not secured behind authentication: anyone with the correct URL could download its contents with no password or login. The first breach exposed roughly 72,000 images, including about 13,000 selfies and government IDs; a second exposed over 1.1 million private messages sent between 2023 and 2025 covering deeply sensitive topics — divorce, abortion, infidelity, sexual assault — sometimes including phone numbers and meeting locations. The data circulated on 4chan. Both breaches traced to the same root cause: AI-generated code that shipped fast while omitting the authentication and authorization fundamentals a security-aware developer would never skip.
Incident Metadata
- Agent
- Unknown Agent
- Failure Mode
- Security Vulnerability
- Root Cause
- Instruction Misunderstanding
- Task Type
- feature
- Domain
- backend
- Source
- news_report