Skip to content

Firebase · 2025-07

Tea app, second breach

Three days after the first breach, over a million private messages were exposed through an API endpoint with no access control.

Last updated 2025-07
Not verified

What the sources report

The sources report a second exposure three days after the first.

Over a million private messages were exposed.

The endpoint that served them performed no access control.

Root cause class

Missing access control

Covered by

What ShipReady can say

An endpoint that answers without checking who is asking is only visible from inside the app. This stays Not verified until auth flows and tenant isolation are reviewed.

Sources

Related incidents

  • Observed

    Moltbook records exposure

    An app exposed 4.75 million records, including 1.5 million API tokens and 35,000 email addresses.

Check your app

Run all sixteen groups on your published address and see the evidence behind every result.

Running it confirms you own this app or are authorized to test it. ShipReady reads its public pages and JavaScript bundles.

ShipReady is not a penetration test or a security certification. No automated check can prove an application is secure.

Last updated September 20, 2026