Tea app, second breach
Three days after the first breach, over a million private messages were exposed through an API endpoint with no access control.
Unnamed · 2026-01
An app exposed 4.75 million records, including 1.5 million API tokens and 35,000 email addresses.
The sources report 4.75 million exposed records.
They included 1.5 million API tokens and 35,000 email addresses.
The causes reported are missing database access controls and an open admin route.
The founder said he did not write a single line of code.
Missing access control
An open admin route shows up as O6 and tables that answer the browser key show up as O8. Whether each row rule is right is still Not verified.
Three days after the first breach, over a million private messages were exposed through an API endpoint with no access control.
Run all sixteen groups on your published address and see the evidence behind every result.
ShipReady is not a penetration test or a security certification. No automated check can prove an application is secure.
Last updated September 20, 2026