69.1 F
Chicago
Tuesday, August 11, 2026

Phoebe Gates & Co-Founder Caught In The Cookie Jar: Slack Logs Contradict Phia’s ’24-Hour Bug’ BS

Must read

Phoebe Gates & Co-Founder Caught In The Cookie Jar: Slack Logs Contradict Phia’s ’24-Hour Bug’ BS

When Bloomberg first caught Phia – the AI “personal shopping assistant” co-founded by Bill Gates’ daughter Phoebe Gates and climate-activist-turned-founder Sophia Kianni – claiming affiliate commissions on sales it had nothing to do with, the company’s ham-fisted damage control was a Silicon Valley classic: an unfortunate software bug, discovered “within the last 24 hours” – and of course it was ‘fixed immediately.‘ 

Except that’s total bullshit. 

According to a follow-up investigation published Tuesday, they knew about it for at least seven months – and Gates along with other execs were actively pushing for its use, according to internal Slack messages and people familiar with the matter.

Phoebe Gates

According to the report, an internal dashboard screenshot shows the automatic cookie-dropping behavior was a named feature flag that could be toggled remotely – independent researcher Ben Edelman identified it in Phia’s own code as enable_coupon_auto_drop. It was reportedly switched on December 10 and switched off July 7 – which happens to be the day Bloomberg first reached out for comment. Two people familiar with the matter confirmed the toggle meant the feature was live. So after seven months, the “bug” was magically cured the moment a reporter shot off an email. 

The Bug = The Business

A Phia data scientist estimated in a July 7 Slack message that cookie stuffing accounted for roughly 51% of the gross merchandise value the company claimed credit for in June, per Bloomberg. An internal revenue chart reportedly tells the same story: when the features went dark in early July, average daily revenue collapsed from about $80,000 to somewhere between $10,000 and $28,000.

The company disputes the math – a spokesperson called the 51% figure a preliminary analysis built on flawed methodology, and says the revenue cliff also reflects Phia voluntarily shutting down most of its monetization at the same time. Except – when switching off the “bug” vaporizes the majority of your revenue, that’s the business. 

The receipts

For readers unfamiliar with the affiliate marketing underworld: publishers earn commissions by dropping a tracking cookie when a shopper intentionally interacts with them – clicking a referral link, applying a coupon. Dropping cookies without user interaction is called cookie stuffing, it’s prohibited by essentially every affiliate network contract, and it works by hijacking credit (and commission) from whoever actually drove the sale.

Per Bloomberg, here’s what the founders were doing while their future PR statement about a 24-hour-old bug was still unwritten:

  • December 18: Gates, worried that Etsy commissions were coming in light, pressed developers on Slack to confirm that automatic cookie-drops were live across every site offering a coupon – so the company would monetize all merchandise value flowing through checkout. When an engineer confirmed cookies were being set even when shoppers never touched a coupon, she reportedly reiterated that every transaction should be captured regardless. (Phia’s explanation: she was concerned a broken pop-up meant users weren’t seeing coupons, which would also depress attribution. Noted.)
  • October through July: a feature internally dubbed “passive trigger” reportedly re-dropped a Phia cookie every two hours on any top-1,000 website where the user had ever interacted with the extension – potentially steamrolling other publishers’ legitimate referrals along the way. Bloomberg says its review of Phia’s historical source code confirmed the features existed.
  • A second feature, also per Bloomberg, reportedly set a cookie if a shopper clicked anywhere on the page after Phia’s pop-up appeared – including while trying to close it.
  • Kianni, after a colleague warned that dropping cookies on dismiss events violates Google’s Chrome extension policy, reportedly floated the idea of claiming users had been trying to open the extension and simply reversing charges if anyone complained – before cheering the team on to keep the cookies dropping by whatever means available. (A spokesperson says that particular feature was never implemented or launched.)

Oh, and the Slack exchanges in question? Per two people familiar with the matter, they’re no longer visible to Phia employees. Memory-holed, as it were.

Sophia Kianni and Phoebe Gates announce Phia, a digital fashion platform. Credit : Emma McIntyre/Getty

Ben Edelman – the advertising consultant who has spent 20 years dismantling deceptive marketing schemes – reviewed Phia’s source code and merchant data, corroborated Bloomberg’s findings, and described a multipart effort engineered to inflate Phia’s revenue while delivering nothing to merchants. His suggestion that the founders should have spent more time reading their contracts and less time building tricks is about as polite as this gets. Phia declined to comment on his analysis.

Sound familiar?

It should. This is the Honey playbook – the same last-click attribution hijacking that blew up in PayPal’s face in late 2024 and spawned a wave of class actions and a creator revolt. The difference is that Honey’s scandal was reconstructed from the outside. Phia’s, per Bloomberg, comes with the founders’ own fingerprints on the toggle. And cookie stuffing isn’t some novel gray area: a decade ago, in the infamous eBay affiliate cases, it ended in federal wire-fraud pleas.

The fallout is already rolling. Affiliate network Impact.com suspended Phia from its marketplace after Bloomberg’s first story and is reallocating unpaid commissions attributed to the startup since June 20. Phia has begun repaying retailers – and with the timeline now stretching back to at least December rather than July, that refund bill is unlikely to shrink. Nike, Gap and Nordstrom, all reportedly among the affected merchants, did not respond to Bloomberg’s requests for comment.

One question the piece leaves hanging: Phia announced a $35 million Series A led by Notable Capital on January 27, at a $185 million valuation – roughly seven weeks after the auto-drop toggle reportedly went live, and weeks after that December Slack thread. The launch announcement touted, among other things, a 40% increase in monetized GMV. The growth metrics were, evidently, impressive. It’s just that, if Bloomberg’s reporting holds, a meaningful chunk of that growth may have belonged to somebody else.

Phia, for its part, says all misattribution features were removed on July 7, that it is reviewing every transaction and issuing reversals to brand partners, and that it is hiring a head of compliance – a role whose necessity apparently revealed itself the same day Bloomberg’s phone number did. The company adds that it remains focused on giving users the best possible shopping experience, including its new digital closet feature.

But sure. It was a bug.

Tyler Durden
Tue, 08/11/2026 – 16:40

- Advertisement -spot_img

More articles

LEAVE A REPLY

Please enter your comment!
Please enter your name here

- Advertisement -spot_img

Latest article