synthlust
Home / Guides / Muah.ai Breach
Security incident · October 2024

The Muah.ai data breach: everything we know

On October 8, 2024, a hacker breached the AI companion app Muah.ai and exfiltrated user email addresses, chat prompts, and AI image prompts. Roughly 1.9 million records were exposed. Here's the full picture, what it means for current users, and what we'd do if we had an account.

Published April 17, 2026 · by Tom Weber

What happened

In early October 2024, an unknown actor compromised Muah.ai's infrastructure and extracted user data. The breach was publicly disclosed on October 8, 2024. Have I Been Pwned added the dataset shortly after, allowing users to check whether their email had been included.

The hacker described Muah.ai's backend as "a handful of open-source projects duct-taped together" and said initial access didn't require sophisticated technique. That framing matters: the breach wasn't a nation-state attack, it was a company shipping faster than it was hardening.

What leaked

  • Approximately 1.9 million email addresses, most in plaintext, tied to user accounts.
  • User chat prompts: the text users had typed into the app, including explicit content.
  • AI image generation prompts: what users asked the image generator to produce.
  • Account metadata: IDs, settings, usage patterns.

Passwords, as best we can tell, were hashed and not directly exposed in the dump. Payment card information was also not part of the leak. That is handled by a third-party processor.

The CSAM angle

Security reporters at 404 Media and others identified that a non-trivial portion of leaked prompts described child sexual abuse material. This creates two problems. First, it exposed that some users were attempting to generate illegal content on the platform. Second, because email addresses were tied directly to those prompts, those users became immediately identifiable: a severe personal and legal exposure, and an obvious extortion vector.

Muah.ai's filter, at the time of the breach, was demonstrably inadequate at blocking these requests. The company has since claimed improvements, though independent verification is limited.

What Muah.ai did in response

The company's public response was limited. A brief statement acknowledged the incident. There was no public incident-response timeline, no detailed post-mortem, and no transparent remediation roadmap of the kind you'd expect from a company handling sensitive user data. This is the part that concerns us most as reviewers: not the breach itself (those happen) but the way it was handled.

Should you still use Muah.ai?

That depends on what you're optimizing for. If you prioritize voice-call quality and truly uncensored interaction, Muah.ai remains the best product in those narrow categories, and we say that in our full Muah.ai review. But you should use it with the assumption that anything you type could, again, become public in a future incident.

Concretely, if you use Muah.ai:

  • Sign up with a dedicated email address that doesn't tie to your real identity.
  • Don't upload photos of yourself or anyone you know.
  • Assume the chat log is not private.
  • Use a strong, unique password.

Check if your email was exposed

Have I Been Pwned hosts the breach. Enter your email at haveibeenpwned.com and look for "Muah.ai" in your result. If you see it, change your Muah.ai password immediately, review any password you reused elsewhere, and consider whether the email you used identifies you in a way you're uncomfortable with.

Our recommendation: safer alternatives

If the breach changed how you feel about Muah.ai (understandable), the table below lists three products we rate highly that haven't had public security incidents. None of them match Muah's uncensored depth or voice quality, but their operating posture on data is more conventional.

If you still want Muah.ai
Read our full review for the good, the bad, and the context before signing up.

Affiliate link. We may earn a commission if you subscribe. How we make money.