Slide 1 of 28
Part 1 · What Is It?Slide 1
PART 1
What Is It?
Slides 1–8 · From story to definition
Slide 1 · The Setup
One researcher. One month. 207 million transactions.
No exploit. No credential theft. Just an API with no limits.
The Scenario

It's 2019. Venmo is a payment app used by millions of Americans to split rent, pay for groceries, and send money to friends. By default, all transactions on Venmo are public — visible to anyone with an internet connection, including the names, dates, amounts, and messages people attach.

Security researcher Dan Salmon noticed that Venmo had a public API endpoint that returned all public transactions. He wrote a script to call it continuously. There was no rate limiting. No daily cap. No authentication required. His script ran for a month.

In one month, his script downloaded 207 million Venmo transactions.

What was in those 207 million records

Real names. Transaction amounts. Personal messages that people wrote assuming only their friends would see them. Within the dataset, Salmon found evidence of drug purchases, relationship dynamics, rent arrangements, and financial dependencies — all in public, all enumerable in bulk because nothing stopped an automated client from calling the API as fast as it wanted.

Salmon published his findings to prove a point. He had not done anything "unauthorized" — he called a public endpoint. The API simply had no limits on how much any single client could consume.

Before we name it

Salmon didn't bypass authentication. He didn't exploit broken object IDs. He called the same endpoint a legitimate user would call — just millions of times in a row, faster than any human could. The API had no mechanism to say: "this client has consumed too much." That missing control is API4.

What do we call this? →