Skip to main content

With a public API, Venmo’s default privacy settings expose private user data

Image used with permission by copyright holder

Those who use Venmo as their primary money-transfer app, may want to consider changing their privacy settings. After a security researcher analyzed over 200 million Venmo transactions back in 2017, it became clear the app exposes a large amount of private details about its users, The Guardian reports.

The project was created by Berlin-based researcher Hang Do Thi Duc, who highlighted all of her findings via a website called “Public by Default.” On the site, she explains how she was able to learn an ‘alarming amount’ about Venmo’s users by pulling a total of 207,984, 218 transactions all via the app’s public application programming interface (API) — which can be accessed by anyone.

Recommended Videos

Even though Venmo does allow you to choose what is or isn’t public, all transactions are public by default — which some users may not realize. To protect your information, you can choose to make any future transactions visible by only the sender and recipient — that way, they won’t show up on the public feed. There’s also the option to make all past transactions private as well.

Please enable Javascript to view this content

Using the logged data via the API, Do Thi Duc was able to piece together the lives of five different Venmo users identified as: ‘The Cannabis Retailer,’ ‘The Corn Dealer,’ ‘The Lovers,’ ‘The YOLOist,’ and ‘The All Americans.’ Each one includes stories of who they are with specific details she was able to find simply by sifting through their transactions — including exactly how many transactions were carried out by each person in 2017. While she was also able to see full names, she did not publish that identifying information.

“This Venmo user — a young woman with a Greek last name — had 2,033 transactions in eight months’ time. And through her Venmo transactions emerges an unhealthy portrait. She loves Coca Cola (280 transactions) and pizza (209 transactions), and often goes for coffee with the same three friends. She also likes to eat a lot of sweets, especially donuts,” she writes about ‘The YOLOist.’

On the site, Do Thi Duc explains the project will hopefully shed light on the fact that companies should be putting user data protection first. While Venmo’s public feed seems harmless — and even a source of entertainment for some — we don’t truly realize how much information we’re sharing. This includes your first and last name, transaction history, and blatantly revealing where and with whom you’re spending your time by listing who it is the money is going to.

Brenda Stolyar
Former Digital Trends Contributor
Brenda became obsessed with technology after receiving her first Dell computer from her grandpa in the second grade. While…
MKBHD just revealed his smartphone of the year
Smartphones released in 2024.

Popular tech YouTuber Marques Brownlee, aka MKBHD, has just announced his selection for best smartphone of 2024 and, no, it’s not an iPhone.

In a new video that dropped for his 19.7 million followers on Thursday, Brownlee began by giving a shout-out to some of his top selections in the smartphone space, saving his top choice until the very end.

Read more
I wore an Oura Ring for all of 2024. Here’s why I love it and why I’m concerned
The side of the Oura Ring 4.

I’ve worn one wearable more than any other this year, and it speaks to not only its convenience but also its brilliance. It’s the Oura Ring, and I started off 2024 with the third-generation version on my finger, but I will close it with the Oura Ring 4.

While I’m going to generally sing its praises, I’m also going to share why I’m a little concerned about it, too.
How much have I worn the Oura Ring?

Read more
Tips to keep your smartphone just as safe as a government official’s
Safety check on iPhone

It’s the holiday season, and that means an onslaught of bad actors trying to ensnare digital shoppers into their scams. Even Google had to publish a self-pat-on-the-back alert covering celebrity scams, fake invoice traps, and digital extortion. Of course, Big G took the opportunity to regale the virtues of Gmail’s anti-spam tricks.

The government, however, is dead serious about the threats, which extend well into the domain of intricate cyberattacks and telecom breaches targeting high-ranking officials and senior politicians. To that end, the Cybersecurity and Infrastructure Security Agency (CISA) has issued a set of guidelines to protect smartphones.

Read more