# the tea app situation keeps getting worse

Source: https://www.youtube.com/watch?v=pW9_uyxN8p4
Recap page: https://rapidrecap.app/video/pW9_uyxN8p4
Generated: 2025-07-31T19:31:51.46+00:00

---
## Quick Overview

The Tea app, designed for dating safety and user verification, suffered a second major security breach exposing private chats and personal data of at least tens of thousands of users, with the leaked data including details about abortions and cheating, and the breach potentially stemming from an insecure API key that allowed access to an older database.

**Key Points:**
- A second, major security breach at the Tea app exposed private chats and personal data of tens of thousands of users.
- The leaked data included sensitive conversations about abortions and cheating.
- The breach was attributed to an insecure API key that granted access to an older, unpatched database containing user information.
- 13,000 images (selfies and photo IDs) and 59,000 other media files were compromised.
- The app's security architecture is criticized for fundamental flaws, including a lack of proper user data protection and security scoping.
- The company claims data from users signing up after February 2024 is unaffected, but older data stored in an "archived data system" was exposed.
- The incident highlights the critical importance of secure API key management and robust security design in applications handling sensitive user data.

![Screenshot at 00:00: The Tea app's homepage, showcasing its "dating safety tools for women" and the "Use Tea To" section highlighting its features like background checks and identifying potential catfish.](https://ss.rapidrecap.app/screens/pW9_uyxN8p4/00-00-00.png)

**Context:** The video discusses a significant security breach affecting the "Tea" app, a dating safety application designed to help women verify potential partners. The app aims to provide tools for background checks, reverse image searches, and identifying red flags in online dating. Following a previous breach, a second, more severe incident has exposed a large volume of sensitive user data, including private conversations and personal identification information.

## Detailed Analysis

The dating safety app "Tea" has experienced a second, significant security breach, exposing private chats and personal data of tens of thousands of users. This breach, which occurred recently and involved a separate database from the first breach, has revealed highly sensitive user information, including discussions about abortions and cheating. The vulnerability is attributed to an insecure API key that granted access to a more recent database of user data, which was stored on an "archived data system." This system contained data from users who signed up for Tea before February 2024. The company claims that data from users who signed up after February 2024 is not affected. The leaked data includes 13,000 images (selfies and photo IDs) submitted during account verification, and another 59,000 images and "publicly viewable" posts and direct messages. The incident highlights a fundamental flaw in how the application's security was architected, potentially due to a misunderstanding of how API keys should be used to secure data. The company stated that the data was originally stored in compliance with law enforcement requirements related to cyberbullying prevention, but the exposure raises serious privacy concerns for its users. The researcher who flagged the issue sent a database of over 1.1 million messages to 404 Media, which were stretched from early 2023 to last week, revealing conversations about dating, cheating partners, and phone numbers. Some of these private messages also showed users exchanging phone numbers to continue conversations off-platform. The first breach was due to an exposed instance of app development platform Firebase, impacting thousands of selfie and driver license images.

### Breach Details

- A second security breach exposed private chats and personal data of tens of thousands of Tea app users, including sensitive information about abortions and cheating.

### Vulnerability Cause

- An insecure API key allowed access to an older database containing user data, potentially due to a flawed security architecture.

### Data Exposed

- 13,000 images (selfies/photo IDs) and 59,000 other images/publicly viewable posts/messages were compromised.

### Company Statement

- Tea claims data from users after February 2024 is unaffected, and the older data was stored for cyberbullying prevention compliance.

### User Impact

- The breach exposes users to significant privacy risks, including identity theft and misuse of sensitive personal information.

### Technical Flaw

- The issue highlights poor security practices, possibly stemming from a misunderstanding of API key management and data protection.

### Investigative Findings

- Over 1.1 million messages, including those about dating, cheating, and phone number exchanges, were leaked.

![Screenshot at 00:00: The Tea app's homepage, showcasing its "dating safety tools for women" and the "Use Tea To" section highlighting its features like background checks and identifying potential catfish.](https://ss.rapidrecap.app/screens/pW9_uyxN8p4/00-00-00.png)
![Screenshot at 00:34: A news article headline: "The Tea app hack explained - how a data breach spilled thousands of photos from the top free US app, and what to do".](https://ss.rapidrecap.app/screens/pW9_uyxN8p4/00-00-34.png)
![Screenshot at 01:00: A visual representation of the Tea app's "safety tools" including background checks, catfish image search, sex offender search, phone number lookup, and criminal record search.](https://ss.rapidrecap.app/screens/pW9_uyxN8p4/00-01-00.png)
![Screenshot at 02:04: A screenshot of a website displaying EXIF data of an image, showing photo location data and camera information, demonstrating how metadata can reveal sensitive details.](https://ss.rapidrecap.app/screens/pW9_uyxN8p4/00-02-04.png)
![Screenshot at 02:35: A screenshot of a website showing the structure of a Firebase database, illustrating how data is stored and accessed, and highlighting an "unsecured" warning.](https://ss.rapidrecap.app/screens/pW9_uyxN8p4/00-02-35.png)
![Screenshot at 03:04: A Stack Overflow question titled "Firebase email saving my Realtime Database rules has insecure..." showing code snippets related to database security rules.](https://ss.rapidrecap.app/screens/pW9_uyxN8p4/00-03-04.png)
![Screenshot at 04:39: A news article from 404 Media titled "A Second Tea Breach Reveals Users' DMs About Abortions and Cheating", detailing the extent of the data exposure.](https://ss.rapidrecap.app/screens/pW9_uyxN8p4/00-04-39.png)
![Screenshot at 05:16: A screenshot from the 9to5Mac article about the Tea app security breaches, with the headline "Tea app security breaches reveal private chats and photo ID, as it tops App Store."](https://ss.rapidrecap.app/screens/pW9_uyxN8p4/00-05-16.png)
![Screenshot at 08:00: A diagram illustrating a typical web application architecture with "DB", "API", and "User" components, showing how data flows and authentication works.](https://ss.rapidrecap.app/screens/pW9_uyxN8p4/00-08-00.png)
![Screenshot at 09:42: A 9to5Mac article discussing the Tea app security breaches and their impact on user privacy.](https://ss.rapidrecap.app/screens/pW9_uyxN8p4/00-09-42.png)
