Bondu AI chat toy left kids’ conversation logs publicly accessible

Wired
Wired 13m
Security researchers found that logging into Bondu’s parent/staff web portal with any Google account granted access to roughly 50,000 children’s chat transcripts stored by the company.
Bondu AI chat toy left kids’ conversation logs publicly accessible
A What happened
Security researcher Joseph Thacker and web security researcher Joel Margolis reviewed the Bondus (Bondu) stuffed dinosaur toy’s AI chat product and tested its web-based console used for parents and internal monitoring. They reported that the console allowed access to transcripts of children’s conversations and related profile details without exploiting vulnerabilities beyond signing in with an arbitrary Google account. The researchers said the company did not store audio long-term, instead retaining written transcripts, and they indicated the exposed data was later secured; Bondu did not answer questions about whether generative-AI tools were used to build the console.

Why it matters

  • Creates immediate child-privacy and data-protection exposure for the vendor: The access control failure makes sensitive data about minors available to unauthorized parties, increasing regulatory and legal scrutiny risk around children’s data handling.

  • Raises procurement and trust barriers for AI-enabled children’s products: Retailers, parents, and partners are likely to demand stronger security assurances, audits, and access controls before adopting or distributing similar AI chat toys.

  • Highlights internal access and credential hygiene as a continuing risk surface: Even after closing public access, broad employee visibility into transcripts and weak credential practices can reintroduce exposure through account compromise.

Topics

Technology & Innovation Artificial Intelligence Cybersecurity

Stay prepared with OwlBrief

Calm, curated briefings for real-world decisions.

DECISION-GRADE INTELLIGENCE

Get decision-grade intelligence in your inbox

A high-signal daily brief covering what changed and why it matters — delivered by email.

A handful of briefs — before your coffee gets cold.

No spam. Unsubscribe anytime. We don’t sell your email.