CMF by Nothing’s Student Referral Allegedly Left the Data of Participants Unencrypted

Main Image
  • Like
  • Comment
  • Share

CMF by Nothing is launching its first-ever smartphone today (July 8th) along with a TWS and a smartwatch. Naturally, the company is busy marketing its products, especially the CMF Phone 1. One of these marketing campaigns is the Student Referral Program, where participants can refer other students to climb up the leaderboard and earn a CMF Phone 1.

However, according to an X user, this program had several issues right from the start. Many users were unable to receive an OTP after entering their email addresses. User @PChillu77210 on X (formerly Twitter) was frustrated enough to use “response manipulation” and bypass the OTP verification. According to him, it was surprisingly easy to bypass the OTP verification on this program by CMF.

ALSO SEE: 4K Recording Mobile Phones Price List 2024

Once the OTP verification is done, the program asks you to enter your personal information, such as your name, address, and phone number. Once it has all the information that it needs, you can enter a referral code to earn a point (more on this later).

After a successful registration, @PChillu77210 on X (formerly Twitter) noticed that the URL of the webpage had something fishy going on. He found the API of the website appended to the URL. There, he found the database of several participants who had shared their personal information on the website as a part of the referral program.

The personal information includes—

  • Full name
  • Email address
  • Phone number
  • State
  • City
My personal data found in the database.

ALSO SEE: Telephoto Lens Mobile Phones Price List in India 2024

@PChillu77210 explained that anyone’s personal information can be searched using a referral code. They also stressed that this information is publicly accessible to anyone (webpage has now been taken down).

Now, the CMF by Nothing Student Referral program is about getting as many users into the program as you can. Each referral will get you 2 points and help you climb the leaderboard. The top 50 users on the leaderboard (with the most points) will get a free CMF Phone 1.

ALSO SEE: 1TB SSD Laptops Price List in India 2024

It’s not the first time…

It’s not the first time we have had a privacy issue with Nothing or its sub-brand. In the past, there have been some serious privacy slip-ups with CMF and Nothing. Take the CMF Watch Pro, for example, where the watch would display someone else’s watch face photo on other users’ watches.

Or the Nothing Chats mess, where unencrypted messages left users’ private conversations exposed. And let’s not forget the Nothing Community data leak, which made several users’ emails publicly accessible.

Nothing’s response?

Nothing is yet to issue an official statement on this. At the time of writing, the webpage in question seems to have been taken down. If this is indeed true, we urge Nothing to step up and issue a sincere apology.

They need to fix this as soon as possible and ensure top-notch security measures are in place to prevent future breaches. And remember—being transparent and determined about user privacy is key to building trust and maintaining credibility.

You can follow Smartprix on TwitterFacebookInstagram, and Google News. Visit smartprix.com for the latest tech and auto newsreviews, and guides.

Mehtab AnsariMehtab Ansari
Mehtab Ansari is a tech enthusiast who also has a great passion in writing. During his two years of career, he has covered news, features, and evergreen content on multiple platforms. Apart from keeping a close eye on emerging tech developments, he likes spending time at the gym.

Related Articles

ImageASUS Launches Four New Gaming Laptops With Nvidia RTX 5070 Graphics Processor: Check Specs And Price Here

ASUS India has unveiled four new gaming laptops, powered by the Nvidia RTX 5070 GPU. These include the TUF Gaming F16 with an Intel processor, the TUF Gaming A16 with an AMD processor, the ROG Strix G16, and the ROG Zephyrus G14. While the laptops feature top-tier specifications for running demanding video games, they also …

ImageCMF By Nothing Gets A Launch Date, Announces Community Review Program

In August 2023, the founder and CEO of Nothing, Carl Pei, announced a new company sub-brand, CMF. An Indian leakster also claimed that CMF has three new products in its pipeline, including a smartwatch, TWS earbuds, and a portable charger. Now, Nothing’s sub-brand has announced a launch date for its products, and it’s pretty close.  CMF …

ImageCMF by Nothing to launch Phone (1), Buds (2) & Watch Pro 2 soon: Company shares teaser

CMF by Nothing is all set to widen its portfolio of products by announcing its first affordable budget smartphone very soon. The past few weeks have seen various leaks and rumors surrounding the CMF Phone (1) which include the design, unique features, and expected price of the upcoming device. A few days ago CMF by …

ImageCMF by Nothing to launch CMF Phone 2 Pro, CMF Buds 2, Buds 2a or Buds 2 Plus on April 28

CMF By Nothing has exciting plans for this year. The sub-brand has announced the upcoming release of the CMF Phone 2 Pro, along with at least two models of TWS Buds, scheduled for April 28th. The announcement was made via their official X account, where they referred to the CMF Phone 2 Pro, CMF Buds …

ImageCMF by Nothing Shifts Gears: CMF Phone 2 Pro to Launch on April 28 with Triple Camera Setup

In a very, very surprising move, CMF by Nothing has announced that it will launch the CMF Phone 2 Pro instead of the anticipated CMF Phone 2. The CMF Phone 2 Pro, along with a trio of earbuds—Buds 2, Buds 2a, and Buds 2 Plus—will be unveiled on April 28, 2025, at 2:00 BST (6:30 …

Discuss

Be the first to leave a comment.

Related Products