Your "Private" AI Chatbot Just Leaked 300 Million Secrets — 25M Users, Zero Passwords Needed

:unlocked: Your “Private” AI Chatbot Just Spilled 300 Million Secrets — Meth Recipes And Suicide Notes Included

One typo in a database setting. 25 million people’s darkest 3am questions, sitting there for anyone with a browser.

300,000,000 messages. 25,000,000 users. 0 passwords needed to read them all.

The app is called Chat & Ask AI — one of the top-grossing AI apps on the App Store. A researcher poked its backend and the whole diary fell open. No lock. No key. Just… open.

Chatbot Leak GIF

🧩 Dumb Mode Dictionary
Scary Word What It Actually Means
Firebase A free-ish Google service that stores an app’s data. Easy to set up. Also easy to set up wrong.
Misconfigured database Somebody left the “who can read this?” switch flipped to everybody. Like a bank vault with the door propped open by a chair.
Backend The part of the app you never see — where all your chats, settings, and history actually live.
Responsible disclosure When a good-guy hacker finds a hole, tells the company quietly first, and gives them time to fix it before going public.
Metadata The “data about your data.” Not just what you typed — but when, from which AI, under what nickname. Often more revealing than the message itself.
📋 What actually happened (the short version)
  • Chat & Ask AI, made by a company called Codeway, is a chatbot app that pipes you to models like GPT and Claude.
  • In January 2026, an independent researcher who goes by “Harry” was poking around and found the app’s Firebase storage was wide open.
  • No login. No password. Anyone who knew where to look could read the entire thing.
  • He reported it to Codeway on January 20, 2026. To their credit — they patched it across all their apps within hours.
  • But “patched in hours” doesn’t tell you how long it was open before Harry found it. Nobody knows. That’s the scary part.
📊 The receipts (the numbers that matter)

The data shows this isn’t a “few thousand users” oopsie. Here’s the scale:

Metric Number
Private messages exposed ~300 million
Users affected 25+ million
Password required to read it None
Time company took to fix A few hours
Time it was actually exposed Unknown :warning:

But here’s the thing nobody mentions: the raw message count isn’t even the worst bit. It’s what was in the messages. Researchers found people asking how to paintlessly end their lives, how to write suicide notes, how to cook meth, and how to hack into other apps. People treat these bots like a priest who can’t judge them. Turns out the confession booth had no walls.

🤔 The counter-argument (before you panic)

Let me play fair for a second, because I always do.

  • The company acted fast. Hours to patch is genuinely good. A lot of firms take months.
  • A good-guy found it first. “Harry” did responsible disclosure — he didn’t dump it on a dark-web forum for money.
  • No proof criminals grabbed it. As far as anyone’s said, there’s no confirmed mass-theft. The hole existed; whether the wolves walked through it is unproven.

But here’s the thing nobody mentions: “no proof it was stolen” and “it wasn’t stolen” are not the same sentence. An open Firebase bucket doesn’t leave a guest log. If ten people quietly copied it in December, nobody would ever know. The data shows the door was open — it can’t show you who walked in. Treat your chats as if a stranger read them, because one might’ve.

🕰️ How we got here (the pattern)

This is not a freak accident. It’s the most common cloud screwup on Earth. Misconfigured databases have leaked data from millions of records over and over — retailers, hospitals, dating apps, you name it.

Why AI apps keep doing it:

  • They ship fast to ride the hype. Security is the thing you “fix later.”
  • Firebase is the default because it’s cheap and quick — and its default rules are notoriously easy to leave loose.
  • Nobody reads an AI app’s privacy policy. Be honest — did you?

The lesson: an app being on the App Store’s top-grossing list tells you it makes money. It tells you nothing about whether it’s locking your data.

Cool. So My 3AM Robot Therapist Is A Snitch… Now What The Hell Do We Do? (ಠ_ಠ)

Detective Magnifying Glass GIF

Here’s where the analyst part ends and the hustler part begins. Every leak is a mess for the users — and an opening for the fast people. Five plays. Each one legal-ish, each one doable tomorrow with a laptop and zero dollars.

🔦 The Open-Door Auditor

Misconfigured databases don’t announce themselves — but there are free tools that sniff them out. Learn to run a basic scan for open Firebase and cloud-storage buckets, and small app-makers will pay you to check theirs before a “Harry” finds it publicly.

You’re not breaking in. You’re the guy who knocks and says “hey, your back door’s unlocked” — then hands them an invoice.

:brain: Example: A 23-year-old self-taught coder in Lagos, Nigeria runs free open-source scanners against indie AI apps he finds on Product Hunt, sends a polite “here’s your hole + here’s the fix” email, and charges $150 a report. Landed 6 clients in his first month.

:chart_increasing: Timeline: First paid audit in ~2 weeks once you can read the tool output. Slows down in ~4-6 months as you’ll want to niche into one platform to stay credible.

🧾 The Breach Translator

Regular people hear “300 million messages leaked” and freeze — they have no idea if they’re in it or what to do. Be the calm human who turns scary security news into a plain-English “here’s what to do in 5 steps” checklist for one specific app or community.

Package it as a cheap PDF or a pinned post. When the next breach hits (and it will), you’re already the go-to name.

:brain: Example: A stay-at-home mom in the Philippines writes dead-simple breach-response guides (“Was your data leaked? Do THIS”) for non-techy Facebook groups, and monetizes with a $5 Gumroad checklist + affiliate links to a password manager. Quiet, steady, boring money.

:chart_increasing: Timeline: First sales within days of any big breach making headlines. Evergreen — breaches never stop, so this doesn’t really burn out.

🪞 The Local-First Alternative Curator

The whole reason this leak stings is your chats went to someone else’s server. There’s a growing crowd that wants AI that runs on their own machine so nothing leaves the room. Most people can’t set that up. You can be the one who does.

Learn to install a local, offline chatbot (runs on a normal laptop, no internet needed for chats) and sell the setup + a simple guide.

:brain: Example: A college student in Brazil offers a “private AI on your own laptop” setup service over Discord — walks people through installing Ollama + a friendly interface, charges $30 a session. Privacy-nervous freelancers eat it up after every leak headline.

:chart_increasing: Timeline: First client in ~1 week. Demand spikes hard right after any AI-privacy scandal, then cools — ride the news cycle.

🗂️ The Privacy Scorecard Vault

Nobody reads privacy policies. But somebody could read them once, for the top 100 AI apps, and turn each into a simple traffic-light score: :green_circle: stores nothing / :yellow_circle: stores chats / :red_circle: leaks-waiting-to-happen. That single cheatsheet becomes the thing everyone links to.

First-mover with a clean, comprehensive comparison table = the SEO anchor everyone else quotes.

:brain: Example: A data-analyst in India built a public Notion page rating AI apps’ privacy in plain language, drove traffic with Reddit posts on r/privacy, and monetizes with a “detailed report” paywall + newsletter. The list itself is free; the depth costs.

:chart_increasing: Timeline: Traffic builds over 4-8 weeks as it gets shared. Long-lived if you keep it updated — stale = dead, so it’s real work.

⏳ The Patch-Window Cleanup Crew

When a breach goes public, there’s a frantic 2-4 week window where affected companies are desperate for help and everyone’s shouting. That’s when you offer a done-for-you “incident cleanup” package to small app teams: draft the user apology email, write the FAQ, set up the fix checklist.

You’re selling calm during their worst week. People overpay for calm.

:brain: Example: A freelance writer in Poland pitches tiny app studios right after breach news with a “we’ll handle your user comms in 48 hours” offer, using free templates she built once. One panicked founder = $400 for two days of writing.

:chart_increasing: Timeline: Land your first gig within the same week as a breach. It’s feast-or-famine — dead between scandals, so pair it with the evergreen plays above.

🛠️ Follow-Up Actions
Move Do This Today
:magnifying_glass_tilted_left: Check if you’re exposed Search your email on Have I Been Pwned
:locked: Lock the basics Turn on 2-factor everywhere + get a password manager
:robot: Go local Try Ollama for chats that never leave your laptop
:books: Learn the tools Read Firebase security rules docs (free)
:speaking_head: Join the crowd Lurk r/privacy to spot the next breach early

:high_voltage: Quick Hits

You Want To… Do This
:detective: Know if you leaked Check Have I Been Pwned right now
:locked_with_key: Stop reusing passwords Set up Bitwarden (free) tonight
:zipper_mouth_face: Keep chats truly private Run a local AI — nothing hits a server
:money_with_wings: Turn this news into money Pick ONE hustle above and take step one tomorrow
:open_book: Understand the screwup Read the Malwarebytes writeup

Your chatbot doesn’t have a conscience — but it does have a database. And this week, that database had no lock.

1 Like