/
Navigation
Chronicles
Browse all articles
Explore
Semantic exploration
Research
Entity momentum
Nexus
Correlations & relationships
Story Arc
Topic evolution
Drift Map
Semantic trajectory animation
Posts
Analysis & commentary
Pulse API
Tech news intelligence API
Browse
Entities
Companies, people, products, technologies
Domains
Browse by publication source
Handles
Browse by social media handle
Detection
Concept Search
Semantic similarity search
High Impact Stories
Top coverage by position
Sentiment Analysis
Positive/negative coverage
Anomaly Detection
Unusual coverage patterns
Analysis
Rivalry Report
Compare two entities head-to-head
Semantic Pivots
Narrative discontinuities
Crisis Response
Event recovery patterns
Connected
Search: /
Command: ⌘K
Embeddings: large
TEXXR

Chronicles

The story behind the story

← → days · ↑ ↓ browse · Enter similar · o open

Researcher finds a flaw in Grindr's password reset process that allowed anyone with knowledge of a user's email address to claim the account; issue is now fixed

TechCrunch Zack Whittaker

Context & Ripple Effects

This is the third time in roughly four years that outside researchers have surfaced a Grindr weakness on their own: after the 2016 colluding-trilateration attacks that pinpointed users of gay dating apps and the 2019 finding that public APIs exposed any user's location given a username, the password reset process becomes the entry point — this time letting anyone who knows a target's email claim the account outright.

The stakes are higher than a typical takeover bug because Grindr's user base faces real-world exposure if an account changes hands, and the company is simultaneously betting its future on trust-dependent expansion: an AI-native reorganization under CEO George Arison, a global 'gayborhood' hub offering services like HIV treatment and hotel bookings, and a premium Edge tier priced around $80–$220 per week.

First-order effects

  • Users whose email addresses were known were exposed to full account takeover through the reset flow until Grindr shipped the fix, putting profiles, messages, and identity data in strangers' hands.

Second-order effects

  • A pattern of researcher-found flaws — location in 2016, APIs in 2019, account recovery now — forces Grindr to treat security remediation as a standing cost rather than an incident, and gives skeptics of its AI-native push and staff opposition fresh ammunition about engineering priorities.

Third-order effects

  • If the cycle holds, apps serving at-risk communities will be judged on independently verified account integrity before they can monetize trust through high-priced subscriptions like Edge or expand into sensitive services such as health offerings.

The trend: Dating platforms serving vulnerable communities face recurring independent security scrutiny that makes account integrity a precondition for premium monetization and service expansion.

Discussion

  • @realoldpaul Paul Gold on x
    lol hard to believe this wasn't intentional https://www.troyhunt.com/...
  • @zackwhittaker Zack Whittaker on x
    New: A major security vulnerability in dating app Grindr allowed anyone with a user's email address to reset their password, hijack their account, and access their private data. https://techcrunch.com/...
  • @kyrah @kyrah on x
    “Grindr has fixed a security vulnerability that allowed anyone to hijack and take control of any user's account using only their email address.” I wonder how such basic flaws ever make it into prod? https://techcrunch.com/...
  • @kyrah @kyrah on x
    It's literally copy-paste. “This is one of the most basic account takeover techniques I've seen.” More details on the Grindr vuln by @troyhunt: https://www.troyhunt.com/...
  • @shonwashed Shon on x
    apologies to everyone who received my unsolicited nudes during this security breach https://twitter.com/...
  • @zackwhittaker Zack Whittaker on x
    Here's how it worked: A user resets their password, and the password reset token is sent as a clickable link to the user's email. But the token was also leaked to the browser, making it very easy for an attacker to create their own password reset link. ➡️ https://techcrunch.com/.…
  • @evacide Eva on x
    So this is bad. https://twitter.com/...
  • @seanwrightsec Sean Wright on x
    This vulnerability was definitely a critical issue. Concerning a company the size of Grindr could have such a flaw. https://twitter.com/...
  • @scott_helme Scott Helme on x
    Whist we try not to ‘over-egg the pudding’ in these matters, this was a trivial attack to hack into and fully takeover *any* Grindr account you wanted, it's pretty bad: https://www.troyhunt.com/... @troyhunt @wasbou
  • @zackwhittaker Zack Whittaker on x
    The bug is now fixed, thanks to @wasbou reporting the issue. @troyhunt and @scott_helme also verified the bug. “This is one of the most basic account takeover techniques I've seen.” Any who knew where to look could've hijacked a Grindr account in seconds. https://www.troyhunt.com…
  • @troyhunt Troy Hunt on x
    So here's the @Grindr story and how a simple vulnerability found by @wasbou made it trivial to takeover @Scott_Helme's account by copying and pasting a token out of the password reset response page: https://www.troyhunt.com/...