YouTube Bug Leaked Emails, Ethical Hacker Cashed In
Back in early 2025, a security researcher who goes by BruteCat did what ethical hackers do best: they found a hole in YouTube, poked it politely, and told Google instead of auctioning it to the darkest corner of the internet. The hole was not a dramatic video-deleting glitch or a livestream hijack. It was a quiet, sneaky email-leaking machine. And it all started with the humble block button. 🐱💻

YouTube keeps a list of blocked users. That list, like a small-town HOA newsletter, is not supposed to be exciting. But when BruteCat visited the page and inspected its source, the page happily displayed the unique Google Account identifier for every blocked account. That was interesting, but not yet catastrophic. An account ID is not an email address. It is more like a locker number without the combination.
Then BruteCat found a second trick. In a live chat, clicking the three-dot menu beside another user fired a server request. If that request was intercepted, the response included the same Google Account ID. Suddenly, the researcher could harvest IDs without blocking anyone. No block button, no awkward social aftermath, just a neat little stream of identifiers. 😬
An ID alone was still not enough. So BruteCat began rummaging through other Google products, which is basically what happens when a curious hacker has too much coffee and a valid test account. The breakthrough came with Pixel Recorder. If a request was sent to share a sound file to a user via their Google Account ID, the server responded with the email address attached to that ID. In other words, the ID was the locker number, and Pixel Recorder was the overly helpful clerk who read out the locker owner's home address.
There was one problem: sharing a file normally sends a notification email to the target. That would be like a burglar ringing the doorbell to ask if the alarm was working. BruteCat needed silence. So they set the recording name to be 2.5 million letters long. That is not a typo. The name was far too large to fit into an email notification. The server still returned the email address when the sound file was shared, but no notification escaped into the wild. The target remained blissfully unaware. 🕵️
From there, automation was inevitable. BruteCat wrote a Python script that accepted a Google Account ID and returned an email address. Feed it an ID, get an address. It was less a magic trick and more a vending machine for personal data. If the wrong person had found this first, scammers could have harvested emails from YouTube users, content creators, commenters, and anyone else whose ID drifted past them. Phishing campaigns would have been planned with the enthusiasm of a shark convention. 🦈
The exploit chain looked something like this:
| Step | What happened | Why it mattered |
|---|---|---|
| 1 | Blocked users page source | Exposed Google Account IDs |
| 2 | Live chat three-dot menu request | Allowed ID harvesting without blocking |
| 3 | Pixel Recorder share request | Returned the email tied to the ID |
| 4 | 2.5 million-letter recording name | Suppressed the notification email |
| 5 | Python script | Automated the whole ID-to-email lookup |
Thankfully, BruteCat is an ethical hacker. Instead of selling the exploit, they wrote a detailed report and sent it to Google. Google fixed the problem and paid BruteCat $10,000. That is a solid payday for what was essentially a very persistent game of digital hide-and-seek. It also shows why bug bounty programs exist: sometimes the person who finds the crack in the wall is the one who tells the owner instead of charging admission to the neighborhood. 💰
As of 2026, the fix still stands, and the story remains a favorite in security circles. It is a neat reminder that small features, such as blocking, live chat menus, and file sharing, can combine into something much bigger when a clever researcher connects the dots. It is also a reminder that ethical hacking is not about wearing a hoodie and typing dramatically. It is about permission, responsible disclosure, and not being a jerk with someone else's data.
For anyone who dreams of getting paid to break things legally, there are ethical hacking courses for beginners, and the Certified Ethical Hacker (CEH) certification is still a recognizable badge in 2026. The line between ethical hacking and criminal hacking is not blurry at all: permission is the difference. Attacking a company without permission is not a clever career move. It is a one-way ticket to a very different kind of certification. 🚔
So the next time a block button seems boring, remember BruteCat. A single page of blocked users, a three-dot menu, and a sound file sharing feature almost became a giant email leak. Google patched it, paid up, and everyone moved on. That is the system working exactly as it should, with a little humor, a lot of curiosity, and a researcher who chose the white hat. 🎩