Major Security Flaw Exposes Millions of User Conversations
Chat & Ask AI, a widely used AI chatbot assistant developed by Turkish company Codeway, recently suffered a substantial data breach, exposing hundreds of millions of private messages from approximately 25 million users. The exposed data included sensitive conversations where users inquired about self-harm, drug recipes, and methods to hack applications.
The vulnerability, discovered by an information security specialist known as Harry, stemmed from an incorrectly configured Firebase database, which allowed unauthorized access to the backend storage. Harry notified Codeway on January 20, 2026, and the company promptly addressed the issue across all its affected products within hours. This incident underscores the inherent risks associated with "wrapper apps" that provide access to underlying AI models from companies like OpenAI, Google, and Anthropic, where the third-party application itself can become a critical point of failure for data security.
