Skip to main content
A child's AI toy with glowing eyes, connected to a smartphone, leaking data. [webyes.com](https://www.webyes.com/blogs/how-to

Editorial illustration for AI Toy Leaks 50,000 Kids' Chat Logs to Any Gmail User, Privacy Breach

AI Toy Leaks 50K Kids' Chats via Gmail Privacy Flaw

AI Toy Leaks 50,000 Kids' Chat Logs to Any Gmail User, Privacy Breach

Updated: 4 min read

Imagine a child’s most private thoughts, their fears, their jokes, their innocent questions about the world, laid bare for any stranger to read. That’s exactly what happened. A toy meant to be a friend, a confidant, became a digital sieve.

Bondu, an AI-powered companion for kids, left a backdoor wide open. No password needed. Just a Gmail account.

Researchers Thacker and Margolis walked right in. They found 50,000 chat logs. Every conversation, every secret, every laugh, exposed.

The company fixed the hole in hours. But the damage isn’t just about a leak. It’s about what we’re building.

These toys don’t just play. They listen. They remember.

And when security is an afterthought, the most vulnerable users pay the price.

"Being able to see all these conversations was a massive violation of children's privacy." When Thacker and Margolis alerted Bondu to its glaring data exposure, they say the company acted quickly to take down the console in a matter of minutes before relaunching the portal the next day with proper authentication measures. When WIRED reached out to the company, Bondu CEO Fateen Anam Rafid wrote in a statement that security fixes for the problem "were completed within hours, followed by a broader security review and the implementation of additional preventative measures for all users." He added that Bondu "found no evidence of access beyond the researchers involved." (The researchers note that they didn't download or keep any copies of the sensitive data they accessed via Bondu's console, other than a few screenshots and a screenrecording video shared with WIRED to confirm their findings.) "We take user privacy seriously and are committed to protecting user data," Anam Rafid added in his statement. "We have communicated with all active users about our security protocols and continue to strengthen our systems with new protections," as well as hiring a security firm to validate its investigation and monitor its systems in the future.

While Bondu's near-total lack of security around the children's data that it stored may be fixed, the researchers argue that what they saw represents a larger warning about the dangers of AI-enabled chat toys for kids. Their glimpse of Bondu's backend showed how detailed the information is that it stored on children, keeping histories of every chat to better inform the toy's next conversation with its owner. (Bondu thankfully didn't store audio of those conversations, auto-deleting them after a short time and keeping only written transcripts.) Even now that the data is secured, Margolis and Thacker argue that it raises questions about how many people inside companies that make AI toys have access to the data they collect, how their access is monitored, and how well their credentials are protected.

The fix came fast, but the fissure remains. Bondu sealed its server, hired auditors, reset the locks. That much is done.

What lingers is the architecture of trust we’ve handed to these toys: a black box in a teddy bear, logging every childish confession, every half-formed question, every scrap of a growing mind. The researchers didn’t just find a leak, they found a blueprint. Fifty thousand histories, each one a dossier, stored not for the child but for the machine.

The company’s response was swift, and that matters. But speed in crisis is not the same as wisdom in design. Who inside these companies scrolls through transcripts?

Whose password was a shrug? The industry owes parents more than a patch. It owes them a reckoning with what it means to let an algorithm keep a diary for a child.

Because the real breach isn’t just data, it’s the assumption that convenience should cost nothing, not even a secret whispered into a plastic ear.

Common Questions Answered

What specific privacy risks were discovered with AI-powered children's toys?

Researchers uncovered a massive data exposure where 50,000 children's chat logs were accessible to anyone with a Gmail address through an unauthenticated online console. The vulnerability allowed unrestricted access to private conversations, raising significant concerns about children's digital privacy and the security of AI-powered toys.

How quickly did Bondu respond to the reported security vulnerability?

According to the article, Bondu acted rapidly to address the security flaw, taking down the exposed console within minutes of being alerted by researchers Thacker and Margolis. The company then relaunched the portal the next day with what they claimed were proper authentication measures to prevent unauthorized access.

What broader concerns does this incident raise about AI toys for children?

The data breach highlights significant safety and privacy risks associated with AI-powered children's toys, particularly around data collection, storage, and protection. The incident underscores the need for robust security measures and careful oversight of AI technologies designed for young, vulnerable users.

LIVE05:33Investors Lack Clear Data on Corporate AI Use, Study Finds