Twitter Tip Jar may expose user's PayPal accounts

Headquarters
(Image credit: PayPal)

Twitter recently began testing out a new feature that allows users to tip select profiles to help support their work but concerns have arisen regarding senders having their PayPal information exposed.

English-speaking users of the social network's iOS and Android apps can now send tips through the company's Tip Jar to creators, journalists, experts and nonprofits around the world.

Twitter users interested in tipping the account holders of their favorite profiles can do so using a variety of payment methods including Bandcamp, Cash App, Patreon, PayPal and Venmo. While the company doesn't take any cuts from these tips, the payment networks themselves may charge users a small transaction fee for tipping.

Senior product manager at Twitter, Esther Crawford provided more details on how this new feature works in a blog post, saying:

“You’ll know an account’s Tip Jar is enabled if you see a Tip Jar icon next to the Follow button on their profile page. Tap the icon, and you’ll see a list of payment services or platforms that the account has enabled. Select whichever payment service or platform you prefer and you’ll be taken off Twitter to the selected app where you can show your support in the amount you choose.”

Exposed PayPal information 

Within a few hours of the Twitter's Tip Jar rolling out though, some users on the social network discovered that due to the way in which PayPal works, the shipping addresses of those tipping other users could be exposed online.

Hacker and CEO of the white hat hacker company focused on social engineering Social Proof Security, Rachel Tobac explained how this works in a tweet, saying:

“Huge heads up on PayPal Twitter Tip Jar. If you send a person a tip using PayPal, when the receiver opens up the receipt from the tip you sent, they get your *address*. Just tested to confirm by tipping @yashar on Twitter w/ PayPal and he did in fact get my address I tipped him.”

Thankfully though, the solution to this potential issue is quite simple as those using PayPal to send tips via Twitter's Tip Jar can select “No address needed” under the Shipping Address form before sending a payment on the social network. 

Twitter has since updated its tipping prompt and Help Center page on its website to clarify that other apps such as PayPal may share information between those sending and receiving tips.

Via BleepingComputer

Anthony Spadafora

After working with the TechRadar Pro team for the last several years, Anthony is now the security and networking editor at Tom’s Guide where he covers everything from data breaches and ransomware gangs to the best way to cover your whole home or business with Wi-Fi. When not writing, you can find him tinkering with PCs and game consoles, managing cables and upgrading his smart home. 

Read more
PayPal
This PayPal scam exploits new address feature to send out phishing scam emails
Smartphone with new logo X twitter app background. Application twitter old blue bird change X black and white new.
Phishing campaign targets prominent X users, accounts at risk
PayPal
PayPal fined by New York for cybersecurity failures
Hands typing on a keyboard surrounded by security icons
Your passwords aren't the key to protecting your online identity, your email address is
Someone checking their credit card details online.
Millions of credit card details leaked online - watch out if you're paying for Christmas
the YouTube logo on a screen in front of other YouTube logos covering a black background
Worrying YouTube security flaw exposed billions of user emails
Latest in Pro
The socket interface of the Intel Core Ultra processor
Intel unveils its most powerful AI PCs yet - new Intel Core Ultra Series 2 processors pack in vPro for lightweight laptops and high-performance workstations alike
Webex by Cisco banner on a Chromebook
Cisco warns some Webex users of worrying security flaw, so patch now
Microsoft UK CEO Darren Hardman AI Tour London 2025
Microsoft - UK can help drive the global AI future, but only with the proper buy-in
Red padlock open on electric circuits network dark red background
AI-powered cyber threats are becoming the biggest worry for businesses everywhere
Woman using iMessage on iPhone
Apple to take legal action against British Government over backdoor request
AOC Graphic Pro U32U3CV during our review
I reviewed the AOC Graphic Pro U32U3CV and it's a staggeringly pro-grade monitor for the price
Latest in News
A hand holding a phone showing the Android Find My Device network
Android's Find My Device can now let you track your friends – and I can't decide if that's cool or creepy
Insta360 X4 360 degree camera without lens protector
Leaked DJI Osmo 360 image suggests GoPro and Insta360 should be worried – here's why
A YouTube Premium promo on a laptop screen
A cheaper YouTube Premium Lite plan just rolled out in the US – but you’ll miss out on these 4 features
Viaim RecDot AI true wireless earbuds
These AI-powered earbuds can also act as a dictaphone with transcription when left in their case
The socket interface of the Intel Core Ultra processor
Intel unveils its most powerful AI PCs yet - new Intel Core Ultra Series 2 processors pack in vPro for lightweight laptops and high-performance workstations alike
An Nvidia GeForce RTX 5070
Nvidia confirms that an RTX 5070 Founders Edition is coming... just not on launch day