2026 Persona age verification frontend exposure
Data compromised
Structural/architectural details of age verification flow; no direct user data
Technical writeup
Security researchers discovered frontend components from identity vendor Persona exposed on the open web, linked to Discord's age verification system. The exposed material did not grant direct access to user data but revealed structural details about how the verification flow operates. Discovery surfaced on X and spread across cybersecurity circles, adding pressure to Discord's 2026 compliance plans.
Root cause
Third-party vendor (Persona) frontend exposure; misconfigured or publicly accessible components