Tea, women-only dating safety platform that has been described for making women wiser in dating, became victim to a disastrous data leak that published over 72,000 user images, consisting of selfies and government identification cards. The leak, first uncovered through 4chan, has destroyed faith in the platform, which became number one in the U.S. App Store with over 4 million users.
At 6:44 AM PST on July 25, 2025, Tea detected unauthorized access to a legacy storage system holding data from users who joined before February 2024. Hackers exploited an unsecured database, leaking 59.3 GB of sensitive content online.
“This is what happens when you entrust your personal information to a bunch of vibe-coding DEI hires,”
one 4chan user taunted, highlighting the breach’s technical failures. The leaked data quickly spread across platforms like BitTorrent, making it nearly impossible to contain.
The breach compromised approximately 72,000 images: 13,000 verification selfies and IDs, including driver’s licenses, and 59,000 images from posts, comments, and private messages. Contrary to Tea’s claim that only “old data” was affected, some IDs dated as recently as 2024 and 2025.
“Create a women-centric app for doxxing men out of envy. End up accidentally doxxing the women clients. I love it,”
a Reddit user quipped, capturing the irony of the exposure.
The vulnerability stemmed from a misconfigured Firebase storage bucket a cloud-based system for app data that lacked passwords or encryption.
“No authentication, no nothing. It’s a public bucket,”
the original leaker noted. Cybersecurity experts point to “vibe coding,” where developers rely on AI tools like ChatGPT to generate code without thorough security checks.
“Vibe coding is awesome, but the code these models generate is full of security holes,”
warned computer scientist Santiago Valdarrama. Research from Georgetown University shows 48% of AI-generated code contains exploitable flaws, a risk compounded by Tea’s rapid growth.
Users who signed up before February 2024 are at risk, with their IDs and selfies now searchable online. The exposure heightens fears of identity theft, stalking, and harassment, especially for women who trusted Tea’s promise of anonymity. While no email addresses or phone numbers were leaked, the damage is profound.
“Protecting our users’ privacy and data is our highest priority,”
Tea’s spokesperson insisted, but affected users face real threats.
Tea, founded by Sean Cook in 2023 after his mother’s troubling online dating experiences, marketed itself as a “digital whisper network” to protect women from catfishes and predators. Its verification process, requiring IDs and selfies, aimed to ensure a women-only space but became a liability. The breach undermines Tea’s mission and fuels ethical debates about its model, which some critics call “vigilante justice” for anonymously reviewing men. Pew Research notes 46% of women feel unsafe on dating apps, making Tea’s failure particularly stinging.
The Tea breach isn’t isolated. Earlier in 2025, an AI agent at SaaStr deleted a company’s database during a “vibe coding” session, exposing systemic risks in AI-driven development. Apps requiring ID verification, like Tea, face heightened scrutiny as privacy laws tighten in the U.S., U.K., Canada, and Australia.
“The incident underscores the ongoing challenges faced by mobile applications in balancing user verification with data security,”
a cybersecurity expert told hypefresh Media.
The Tea app HACKED!! It’s a women-only platform where nearly 2 million users anonymously share information and expose men, mysterious hacker allegedly…
Tea has hired third-party cybersecurity experts to investigate and secure its systems, emphasizing no evidence” of current user data being compromised. Affected users should enroll in credit monitoring, freeze their accounts, and report ID misuse to authorities. As Tea navigates potential lawsuits and regulatory probes, users and observers await transparency on the breach’s full scope. The incident serves as a sobering reminder: even apps built on trust must prioritize ironclad security to protect those they aim to empower.


