Skip to main content
Technical

One Firebase Misconfig Leaked 300M Chat Messages

Take Interest Inc. · · 5 min read

Field Guide

One Firebase Misconfig Leaked 300M Chat Messages

An AI chat app with 50M users left a Firebase database open. A researcher found 300 million messages from 25 million people.

ai-security supply-chain incident-response

Key takeaway

Firebase misconfiguration is systemic. 72% of Android AI apps ship with hardcoded secrets. 196 out of 198 iOS AI apps had Firebase security rule failures.

Key takeaway

300 million messages is the symptom. The disease: security gets treated as an afterthought bolted on after launch, not a requirement for shipping.

Key takeaway

If you're building with Firebase, Cloud Storage, or Supabase, your security rules right now determine whether a researcher finds your data first or a criminal does.

Join the Intelligence Brief

Threat intelligence, agentic vulnerabilities, and engineering frameworks delivered straight to your inbox.

01 / Threat IntelZero-day vulnerabilities and mitigation strategies.
02 / Red TeamQuarterly teardowns of AI infrastructure.
03 / The BlueprintEngineering local-first deterministic computing.