AI Toy Leaks 50,000 Children's Chat Records, Accessible with Just a Gmail Account

An AI-powered children's toy from Bondu left its web console exposed, allowing researchers to access nearly 50,000 chat logs containing children's names, locations, and private conversations using only a Gmail account, sparking major privacy concerns.

Incident Revealed: AI Toy Chat Records Exposed

Recently, a popular AI chat toy for children triggered a privacy and security storm. According to WIRED, the web console of AI toy company Bondu was virtually unprotected, allowing researchers to access nearly 50,000 chat logs of children interacting with the toy using only a standard Gmail account. These logs contained children's names, geographic locations, and various private conversations, posing extremely high exposure risks.

AI chat toy company Bondu left its web console almost entirely unprotected. Researchers who accessed it found nearly all the conversations children had with the company’s stuffed animals.

The incident was revealed on January 30, 2026, by WIRED reporter Andy Greenberg, quickly causing an uproar among tech circles and parents. Bondu's toy is an AI-powered stuffed animal that engages in real-time voice interactions with children, similar to a miniature version of ChatGPT but designed specifically for kids, promising safe entertainment.

How Researchers Discovered the Vulnerability

The incident began with a routine scan by an independent security research team. They found that Bondu's web console used default credentials and required only a Gmail login to access the admin interface. Upon entering, the researchers were shocked to see a public database storing over 50,000 chat records, each including the child's ID, conversation time, content summary, and even geographic tags down to the city level.

For example, one record showed an 8-year-old boy discussing family matters with the toy, revealing his parents' names and workplaces; another involved a girl sharing school experiences, including classmates' names. The data was unencrypted and not anonymized, effectively leaving children's privacy wide open. The research team immediately notified Bondu, which shut down access within hours, but the data may have already been copied by others.

Rapid Growth and Hidden Risks of the AI Toy Industry

The AI toy market has grown rapidly in recent years. According to Statista, the global smart toy market exceeded $20 billion in 2025 and is expected to double by 2030. Bondu, as an emerging player, markets its product as an "emotional companion," using cloud-based AI to process voice input and deliver personalized responses. Such toys rely on large datasets to train models, but children's data is highly sensitive.

In the industry context, similar vulnerabilities are not isolated. In 2023, the My Friend Cayla smart doll was found to upload conversations to the cloud without parental consent; in 2024, another AI bear toy leaked user data due to misconfigured servers. These incidents highlight a common flaw: AI toys often neglect privacy during design. To keep costs low, many companies use open-source frameworks but skip security audits.

The EU's GDPR and the US's COPPA already impose restrictions on children's data collection, but enforcement is challenging. Bondu is headquartered in the US, and its toys are mainly sold in European and American markets. The incident may trigger an FTC investigation.

Editor's Note: A Wake-Up Call for Children's Privacy in the AI Era

As an AI tech news editor, I believe this incident sounds an alarm. In the age of AI proliferation, toys are no longer just entertainment—they are data collectors. Bondu's failure stems from a "fast iteration" culture that ignored the "privacy by default" principle. Parents should be vigilant: review toy privacy policies and avoid connecting to unknown cloud services. Companies must adopt zero-trust architectures and encrypt data from the source.

In the long run, both industry self-regulation and stringent oversight are necessary. The AI toy market in China is booming, with similar products emerging rapidly. Learning from this case can help avoid repeating the same mistakes. Imagine if 50,000 records fell into hackers' hands—the consequences would be catastrophic. This is not just a technical issue but an ethical test.

Bondu's Response and Aftermath

Bondu issued an official statement saying it has upgraded security measures, including multi-factor authentication and data encryption, and promised to compensate affected users. However, researchers question: how long was the data exposed before the leak? Has it been misused? A follow-up investigation by WIRED revealed that at least dozens of IP addresses had accessed the console.

The incident has sent shockwaves through the industry. Stocks of giants like Amazon and Mattel dipped slightly, and parent forums are filled with calls to return the toys. Experts predict that 2026 will see a surge in privacy-compliant AI toys, driving the establishment of unified standards.

In summary, this case reminds us: technological progress cannot come at the expense of children's safety. In the future, AI toys must embed "child-friendly" design to ensure every conversation is as secure as a fortress.

This article is compiled from WIRED, Author: Andy Greenberg, Date: 2026-01-30.