Researchers demonstrate ability to pinpoint users of Grindr, other gay dating apps with “colluding” trilateration attack
A few days ago, I warned my wife that the experiment I was about to engage in was entirely non-sexual, lest she glance over my shoulder at my iPhone. Tweets: @caseynewton Tweets: Casey Newton / @caseynewton : It's a great way to let a guy know you're really interested in him http://twitter.com/...
Context & Ripple Effects
In May 2016, researchers showed that three accounts acting in concert could trilaterate a Grindr user's position from the distance data the app displays — no exploit against Grindr's servers required, just the app's own proximity feature turned into a targeting tool. For an app serving users who can face real-world danger from being outed, location leakage is not a generic privacy bug but a safety failure.
The 2016 demo was the opening data point in a pattern that kept repeating: by 2019 researchers could derive any user's location from four dating apps' public APIs knowing only a username (API-based location extraction), a 2020 study documented these same apps feeding intimate data to brokers (data-broker sharing across Grindr, Tinder, OkCupid), and in 2024 a six-app vulnerability let malicious users fix positions to within two meters before the apps patched it.
First-order effects
- Grindr users are exposed right now: anyone running the colluding-accounts method can convert displayed distances into a physical location, with no technical barrier beyond creating multiple profiles.
Second-order effects
- Every proximity-based dating app inherits the problem, since the attack exploits a shared design assumption — that coarse distance readouts are safe to expose — forcing the category to choose between obfuscating location data and shipping a known tracking vector.
Third-order effects
- If the 2016-to-2024 sequence holds, location privacy in dating apps shifts from per-app bug fixes to a structural requirement: distance fuzzing and API access controls become baseline product features, and sensitive-community apps carry a disproportionate burden of proof that their proximity features cannot be weaponized.
The trend: Dating-app location disclosure has proven repeatedly exploitable across eight years of research, pushing the category toward treating precise proximity data as a liability to be engineered down rather than a feature to be showcased.