
Gyazo Upload Server Flaw Leaks 23.62M Records and 490M Image IDs
Gyazo's image upload server compromise exposed 23.62 million user records and 490 million image metadata entries. The breach reveals systemic weaknesses in access controls and retention policies common to link-based image services. Affected users face ongoing risks from leaked session tokens and private image identifiers.
Helpfeel's notice details the breach path: unauthenticated arbitrary command execution on the upload server led directly to database exfiltration. Exposed fields include email addresses, bcrypt hashes, Twitter OAuth tokens, Google SSO emails, and login session identifiers. The company invalidated some authentication material but provided no timeline or confirmation that all session IDs were revoked. No CVE or vulnerability class was disclosed, leaving independent verification impossible.
The 490 million metadata entries cover primarily pre-2019 uploads and include EXIF geolocation, OCR text, upload IP addresses, and hashed passphrases for private images. Helpfeel admits it cannot rule out viewing of private captures after the attacker obtained the private-image index. This matches patterns seen in prior image-hosting incidents where link-only access controls failed once IDs leaked at scale.
Free accounts retain older captures indefinitely with no deletion option, amplifying long-term exposure. The absence of payment data limits immediate financial fraud but heightens risks of targeted phishing using real names, registration dates, and device IDs. Cross-service password reuse remains the primary vector for follow-on compromise.
Helpfeel has not published post-incident hardening details or third-party audit results. Users must treat all prior Gyazo links as public and monitor for credential-stuffing attempts over the next year.
Helpfeel: Within 90 days, at least 2% of affected accounts will show successful credential-stuffing logins confirmed via public breach forums.
Sources (3)
- [1]Helpfeel Security Notice(https://helpfeel.com/gyazo-incident-notice)
- [2]The Hacker News Report(https://thehackernews.com/2026/09/gyazo-breach-exposes-2362-million-user.html)
- [3]Have I Been Pwned Gyazo Entry(https://haveibeenpwned.com/breach/Gyazo)