On Monday March 20, 2023, a bug in the open-source redis-py client library caused ChatGPT to expose other users' chat history titles and the payment information of roughly 1.2% of ChatGPT Plus subscribers who were active during a nine-hour window between 1 a.m. and 10 a.m. Pacific time. Users first reported seeing strangers' chat queries in the sidebar of their conversation history and, on the subscription page, other people's email addresses, prompting OpenAI to take the service offline to investigate. In a post-mortem published on March 24, OpenAI explained that the redis-py bug had also made it possible for some users to see another active user's first and last name, email address, payment address, and the last four digits and expiration date of their credit card; full card numbers were not exposed at any point. Triggering the leak required specific conditions, including opening a subscription confirmation email or visiting the "Manage my subscription" page during the affected window, which OpenAI said kept the affected population small. The company submitted a patch to the Redis maintainers, validated the fix, and began contacting all users whose payment information had been exposed. CEO Sam Altman publicly apologized on Twitter, calling it a "significant issue" and saying the company felt "awful" about the incident.
Blog
Insights on AI security and development
Learn how to protect your code, understand AI risks, and build secure workflows with expert insights.

