Researcher finds a flaw in Grindr's password reset process that allowed anyone with knowledge of a user's email address to claim the account; issue is now fixed
TechCrunchZack Whittaker
Context & Ripple Effects
This is the third time in roughly four years that outside researchers have surfaced a Grindr weakness on their own: after the 2016 colluding-trilateration attacks that pinpointed users of gay dating apps and the 2019 finding that public APIs exposed any user's location given a username, the password reset process becomes the entry point — this time letting anyone who knows a target's email claim the account outright.
The stakes are higher than a typical takeover bug because Grindr's user base faces real-world exposure if an account changes hands, and the company is simultaneously betting its future on trust-dependent expansion: an AI-native reorganization under CEO George Arison, a global 'gayborhood' hub offering services like HIV treatment and hotel bookings, and a premium Edge tier priced around $80–$220 per week.
First-order effects
Users whose email addresses were known were exposed to full account takeover through the reset flow until Grindr shipped the fix, putting profiles, messages, and identity data in strangers' hands.
Second-order effects
A pattern of researcher-found flaws — location in 2016, APIs in 2019, account recovery now — forces Grindr to treat security remediation as a standing cost rather than an incident, and gives skeptics of its AI-native push and staff opposition fresh ammunition about engineering priorities.
Third-order effects
If the cycle holds, apps serving at-risk communities will be judged on independently verified account integrity before they can monetize trust through high-priced subscriptions like Edge or expand into sensitive services such as health offerings.
The trend: Dating platforms serving vulnerable communities face recurring independent security scrutiny that makes account integrity a precondition for premium monetization and service expansion.
New: A major security vulnerability in dating app Grindr allowed anyone with a user's email address to reset their password, hijack their account, and access their private data. https://techcrunch.com/...
“Grindr has fixed a security vulnerability that allowed anyone to hijack and take control of any user's account using only their email address.” I wonder how such basic flaws ever make it into prod? https://techcrunch.com/...
It's literally copy-paste. “This is one of the most basic account takeover techniques I've seen.” More details on the Grindr vuln by @troyhunt: https://www.troyhunt.com/...
Here's how it worked: A user resets their password, and the password reset token is sent as a clickable link to the user's email. But the token was also leaked to the browser, making it very easy for an attacker to create their own password reset link. ➡️ https://techcrunch.com/.…
Whist we try not to ‘over-egg the pudding’ in these matters, this was a trivial attack to hack into and fully takeover *any* Grindr account you wanted, it's pretty bad: https://www.troyhunt.com/... @troyhunt @wasbou
The bug is now fixed, thanks to @wasbou reporting the issue. @troyhunt and @scott_helme also verified the bug. “This is one of the most basic account takeover techniques I've seen.” Any who knew where to look could've hijacked a Grindr account in seconds. https://www.troyhunt.com…
So here's the @Grindr story and how a simple vulnerability found by @wasbou made it trivial to takeover @Scott_Helme's account by copying and pasting a token out of the password reset response page: https://www.troyhunt.com/...