One Checkbox Left Open: 300 Million Private AI Chats Spilled Onto the Open Internet
A guy called “Harry” opened a browser, typed a URL, and read 25 million strangers’ deepest secrets. No password. No hacking. Just a database somebody forgot to lock.
300,000,000 messages. 25,000,000 users. 1 misconfigured Google Firebase backend. Fixed in “hours” — after sitting wide open.
The app is called Chat & Ask AI, made by a company named Codeway. And the leak reportedly bled into their other apps too. Full writeup at Malwarebytes and Fox News.

Right, so here’s what’s actually happening. Nobody “broke in.” There was no genius exploit. Someone at a real company shipped an app, wired it to a Google database, and left the front door propped open with a brick. Millions of people typed their most private thoughts into a friendly little chat bubble — and every one of those messages was sitting in a folder anyone could open. Kids these days call it “the cloud.” I call it “someone else’s computer that you forgot to put a lock on.”
🧩 Dumb Mode Dictionary
| Term | What it actually means |
|---|---|
| Firebase | A ready-made Google backend (the “storage room” behind an app). Fast to set up, easy to leave unlocked. |
| Misconfiguration | Nobody flipped the “require login to read this” switch. The data was public by accident. |
| Backend | The part of an app you never see — where all your data actually lives. |
| Unauthenticated access | You didn’t need a password. Type the address, see everything. |
| Responsible disclosure | Finding the hole and quietly telling the company before telling the world. The polite version of hacking. |
| Metadata | The “data about your data” — timestamps, settings, which AI you used. Boring-sounding, scary-useful. |
📰 What actually leaked (and why it's worse than a password dump)
A password leak is bad but fixable — you change the password. This was people’s actual thoughts. According to the reporting, the open database held:
- Full chat histories — every conversation, word for word
- Custom chatbot names people made
- Which AI models they used, their settings and preferences
- Timestamps and internal metadata
And the content? Reporters saw people asking things like “how do I painlessly kill myself,” requests to write suicide notes, “how to make meth,” and how to break into other apps. You can’t reset your rock-bottom 3 AM confessions. Once that’s out, it’s out.
🔍 How one guy found it in January 2026
An independent security researcher who goes by Harry poked at the app’s backend and realized the database had no lock on it. Basic technical knowledge, no fancy tools — just the ability to notice the door was open and walk through.
He pulled roughly 300 million messages from 25M+ users, then did the honorable thing: reported it to Codeway on January 20, 2026 instead of selling it. The company reportedly patched it across all their apps within hours.
Which raises the obvious question — if it took hours to fix, how long was it open before Harry showed up? Nobody knows. That’s the part that keeps sysadmins up at night. (Background: Business & Human Rights Centre.)
⚙️ Right, so here's why this keeps happening
Firebase is genuinely good tech. That’s the problem. It’s so easy to spin up that people ship apps in a weekend without ever reading the security rules. The default mindset is “make it work,” and “make it safe” gets a to-do comment that never gets done.
- Firebase has a “test mode” that leaves data open. It’s meant for the first 30 days of building. People forget to turn it off. For years.
- This isn’t rare. Whole databases of exposed Firebase apps get found monthly. Chat & Ask AI is just the biggest and most personal one.
- Google literally warns you in the console. The warning gets clicked past like a cookie banner.
New tools, same old sin: the boring security step nobody wants to do. See Google’s own security rules docs — the fix was a 5-line config the whole time.
📊 The receipts
| Thing | Number |
|---|---|
| Messages exposed | ~300,000,000 |
| Users affected | ~25,000,000 |
| Password/hacking required | Zero |
| Company’s other apps hit | Yes (whole ecosystem) |
| Time to fix once reported | “Within hours” |
| Time it was open before that | ¯\(ツ)/¯ |
🗣️ What the timeline's saying
- The privacy crowd: “Stop typing your secrets into free AI apps you found in the app store.” (r/privacy has this fight daily.)
- The devs: “There but for the grace of God go I.” Every backend engineer has left a test config on once.
- The cynics: The app kept running. Most of the 25M users will never hear about this. That’s the real ending.
Cool. Some Company Leaked Your 3 AM Confessions. Now What the Hell Do We Do? ( ͡ಠ ʖ̯ ͡ಠ)

Here’s the thing — a leak this dumb creates work. Not for hackers. For the people smart enough to spot that thousands of apps have this exact same unlocked-door problem right now. You don’t need to be a genius. You need to be the person who checks the door before everyone else notices it’s open.
🕳️ The Open-Door Auditor
Firebase misconfigs are findable with free tools that scan for databases left in “test mode.” Companies with a leaky app will pay to hear about it before a “Harry” goes public and torches their reputation. You’re not breaking in — you’re the polite knock that says “hey, your safe is open.”
Example: A 24-year-old comp-sci student in Nigeria runs Firebase Scanner against apps from mid-size startups, writes a clean one-page “your data is public” report, and emails the founder offering a $150 fix-consult. Two replies out of thirty. That’s $300 for a weekend of scanning.
Timeline: First paid report in 2-3 weeks (most companies ignore you — expect it). Dries up as bug-bounty platforms get flooded with AI-assisted scanners doing the same thing. 6-month window, tops.
🧹 The Digital Ghostbuster
Millions just learned their old chats are floating around forever. There’s a growing panic-market for “help me disappear from apps I forgot I used.” Not deleting accounts — most people don’t even remember which apps have their data. Be the person who maps it and nukes it for them.
Example: A 27-year-old in the Philippines builds a simple checklist service: you send her your email, she uses free lookup tools like HaveIBeenPwned to find every breach and forgotten app tied to it, then walks you through deletion requests over a $20 call. Boomer parents and small-biz owners eat this up.
Timeline: First clients within days via local Facebook groups. Plateaus once free “delete me” tools like JustDeleteMe get more popular and word spreads. Solid 3-4 month run, repeatable per breach cycle.
📡 The Breach-Radar Newsletter Nobody Built Right
Every week another app leaks. The news is scattered across ten sites, all written for engineers. Regular people have no “is MY app on the list?” alert. Be the plain-English breach alert for one specific crowd — parents, therapists, small businesses — not the whole world.
Example: A 22-year-old in Brazil runs a free Substack that only covers leaks in mental-health and AI-chat apps, written so a scared parent understands it. Free list grows fast; she charges therapists $8/mo for a “which apps are safe to recommend to clients” version.
Timeline: Audience builds over 4-6 weeks off shares. Paid tier trickles in month 2. Burnout risk is real — it’s a weekly grind. Niche-and-narrow or it dies.
🔐 The Panic-Room Setup Guy
This leak scared a lot of people who use AI chat but don’t want a company reading it. There’s real demand for “set me up so my AI stays private.” Self-hosted local AI that runs on your own machine — no company database to leak — is now beginner-doable, but nobody wants to figure it out alone.
Example: A 25-year-old in India offers a $40 remote setup: installs Ollama + a friendly chat front-end on a client’s laptop so their AI runs 100% offline, no cloud, nothing to leak. Sells it to lawyers and journalists who handle sensitive stuff.
Timeline: First gigs in 1-2 weeks via LinkedIn DMs to privacy-conscious pros. Stays alive longer than the others — local AI keeps getting easier, and paranoid professionals keep multiplying.
🎣 The 'Before They Patch It' Config Reviewer
Here’s the grey-hat-flavored (but fully legal) play: thousands of tiny indie apps and no-code startups are shipping right now with the exact same unlocked Firebase. They can’t afford a security team. Offer a flat-fee “I’ll check your backend isn’t wide open” review before their app blows up and blows up on them.
Example: A 23-year-old in Poland lurks Indie Hackers and r/SideProject, spots founders launching AI apps, DMs “want me to make sure your database isn’t public? $75, 24-hour turnaround.” Reads their Firebase rules, sends a fix. Founders with real users pay instantly out of pure fear.
Timeline: First client in under a week (fear is a fast closer). Scales as long as no-code app launches keep booming. Slows when automated security scanners get baked into the build tools themselves — maybe a year out.
🛠️ Follow-Up Actions
| Want to… | Do this |
|---|---|
| Check if you’re already leaked | Run your email through HaveIBeenPwned |
| Run AI with zero cloud leaks | Install Ollama and go fully offline |
| Learn how the door was left open | Read Firebase security rules |
| Scan an app for this exact bug | Try FireBaseScanner (on apps you own/have permission for) |
| Delete forgotten accounts | Use JustDeleteMe |
Quick Hits
| You Want | You Do |
|---|---|
| Run it locally with Ollama — no company, no database | |
| Check HaveIBeenPwned right now | |
| Offer $75 backend checks to Indie Hackers founders | |
| Skim Google’s own docs on the switch nobody flipped | |
| Work through JustDeleteMe |
The hack of the year wasn’t a hack. It was a checkbox. Somewhere, right now, another one’s still unchecked.
!