The dating app that doxxed 72,000 women...

Duration

3:52

Captions

1

Language

EN

Published

Jul 30, 2025

Description

Get up to 67% off VPS at Hostinger. Use code FIRESHIP for an extra discount at https://hostinger.com/fireship In today's video, we'll find out how the tea app was compromised and look at all the hilarious stuff developers have been building with the hacked data. #teaapp #tech #coding #programming 💬 Chat with Me on Discord https://discord.gg/fireship 🔗 Resources https://techcrunch.com/2025/07/26/dating-safety-app-tea-breached-exposing-72000-user-images/ 🔥 Get More Content - Upgrade to PRO Upgrade at https://fireship.io/pro Use code YT25 for 25% off PRO access 🎨 My Editor Settings - Atom One Dark - vscode-icons - Fira Code Font 🔖 Topics Covered - How the Tea app got hacked - Who is Sean Cook? - How to not set up Firebase - Online Safety Act - Did vibe coding cause the Tea app hack?

Captions (1)

00:00

Last week, one of the most revolutionary

00:01

dating apps for women, T, shot to the

00:04

top of the App Store download charts and

00:06

then immediately imploded after one of

00:08

the most embarrassing data breaches of

00:10

all time. Te is an app that can only be

00:12

used by women to dox and gossip about

00:14

men that they've gone out with on dating

00:16

sites to warn other women about bad

00:18

behavior before they go on a date. That

00:20

means if you're one of the top 5% of

00:22

desirable males who get 80% of the women

00:24

on apps like Tinder, they're probably

00:26

talking about you on tea. Unfortunately,

00:28

on July 25th, T confirmed unauthorized

00:31

access to a legacy Firebase storage

00:33

bucket that was left completely and

00:35

egregiously insecure. Around 72,000

00:38

images were compromised, 13,000 selfies,

00:40

and ID photos. Then, just days later,

00:43

another database was hacked that

00:44

allegedly contains over 1.1 million

00:47

shared posts, comments, and direct

00:49

messages. In today's video, we'll find

00:50

out how this app was compromised and

00:52

look at all the hilarious stuff

00:53

developers have been building with the

00:55

hack data. It is July 30th, 2025, and

00:58

you're watching the Code Report. The

00:59

world is changing quickly. Just days

01:01

ago, age verification for adult websites

01:04

went into effect in the UK, and similar

01:06

laws are also now in place in a handful

01:08

of US states. We live in a dystopian

01:10

world where Gooners now need to get

01:12

permission from the government just for

01:13

the privilege to goon online. Protecting

01:16

kids from degenerate content is a good

01:17

thing, but it's only a matter of time

01:19

before one of these age verification

01:21

data sets gets hacked. A tea app, which

01:23

requires women to verify that they're

01:25

women by taking a selfie with their ID,

01:27

is a perfect example. It was cooked up

01:29

by Shawn Cook, a male developer with

01:31

over 6 months of coding under his belt,

01:33

according to LinkedIn. But now, his app

01:35

is cooked after this massive data breach

01:37

was dumped on 4chan. And it's kind of

01:39

sad that an app meant to help women stay

01:41

safe ended up harming them instead.

01:43

4chan anons played the Uno reverse card

01:45

when thousands of selfies of users on

01:47

the T app were dumped and subsequently

01:49

spread across the internet. And people

01:51

are continuing to roast these tea users

01:53

as we speak. The users of this app and

01:54

the victims of the breach are being

01:56

referred to as roasties. Vibe coders saw

01:58

an opportunity to build all sorts of

02:00

ridiculous apps based on this data. Like

02:02

one guy used Python to do a detailed

02:04

data exploration while another used

02:07

JavaScript to take the location data

02:09

from the hacked images and plot it on

02:10

Google Maps while another person made a

02:12

website to rank them based on their

02:14

looks. After the breach went viral, the

02:16

T team released a statement which was

02:18

basically a non-apology with a bunch of

02:20

corpo speak that explained how a legacy

02:22

data storage system was penetrated

02:24

non-consensually. What's especially

02:26

egregious about this breach though is

02:28

that the data was kept in a Firebase

02:30

storage bucket. It completely

02:31

unencrypted and unsecured just waiting

02:33

to be found by someone on the internet.

02:35

And you actually have to go out of your

02:37

way to screw up Firebase this bad

02:38

because you get tons of warnings when

02:40

you have a bucket or database with rules

02:42

set to public along with email reminders

02:44

that tell you anyone can access this

02:46

data. In addition, in the UI, they tell

02:48

users that they will delete your selfie

02:50

after the verification process is done,

02:52

but it appears that wasn't the case.

02:54

They were either lying or just highly

02:55

incompetent as some have speculated that

02:57

the app itself is just vibecoded slop,

02:59

but I think that's highly unlikely

03:01

because not even AI would screw up

03:02

Firebase this bad. But between your AI

03:05

coding agent bills, your AI girlfriend

03:07

bills, and your cloud hosting bills,

03:09

it's never been more expensive to be a

03:10

10x developer, which is why you should

03:12

check out Hostinger, the sponsor of

03:14

today's video. Their virtual private

03:16

servers will give you the power and

03:17

flexibility to run whatever you want

03:19

without locking you into someone else's

03:21

platform. And for less than 10 bucks per

03:23

month, you get a respectable two CPUs

03:26

and 8 GB of RAM. You can see how they

03:28

have a bunch of operating systems to

03:30

choose from. Or you could go with a

03:31

pre-installed template like this one

03:33

from Koolifi, which lets you easily

03:35

deploy any framework like Nex.js or

03:37

Astro. If you want freedom from our

03:39

serverless overlords and a great

03:41

developer experience, check out

03:43

Hostinger at the link below for an even

03:45

bigger discount. This has been the code

03:47

report. Thanks for watching and I will

03:48

see you in the next one.

Video Information

YouTube ID: miTpJmMt7uo
Added: Jul 31, 2025
Last Updated: 7 months ago