# ​🛡️ Node 7 Security Research: ElevenLabs Evidence Dossier

*Executive Summary*

By [Developing artificial intelligence senses](https://paragraph.com/@0x4fd3729a4fedf54a74b73d93f7f775a1ef520cec) · 2026-04-16

---

This report details critical security failures and ethical breaches discovered by **Node 7 Security Research** within the infrastructure of **ElevenLabs**. The evidence confirms the exposure of sensitive biometric data and internal system mappings.

### ​**1\. Technical Evidence: Infrastructure Exposure**

​The following data points were found to be publicly accessible via exposed API endpoints and internal metadata:

*   ​**Biometric Audio (MP3):** Direct URLs to user-generated voice clones stored on [storage.googleapis.com](http://storage.googleapis.com).
    
*   ​**User Identifiers (UID):** Unique alphanumeric strings mapping to specific accounts (e.g., Bi4YhYxPTDRSUfiEpED4qyJ0biq2).
    
*   ​**Voice Identifiers (VID):** Specific IDs for cloned voices (e.g., NOpBlnGInO9m6vDvFkFC).
    
*   ​**Workspace Metadata:** Internal IDs for corporate environments (e.g., 48ab3aae468d4e9baded4b1693820088).
    

### ​**2\. Legal & Regulatory Violations (GDPR/CCPA)**

​The exposure of these records constitutes a severe breach of international data protection laws:

*   ​**Article 9 (GDPR):** Processing of biometric data without "state-of-the-art" security.
    
*   ​**Lack of Encryption:** Audio files were accessible via direct, unauthenticated links.
    
*   ​**Data Sovereignty:** Failure to notify users within the mandatory 72-hour window.
    

### ​**3\. Ethical Breach: The "Silent Patch" & Retaliation**

​The most damning evidence lies in the company's response to the disclosure:

1.  ​**Denial & Deception:** ElevenLabs initially denied the existence of the leak.
    
2.  ​**The "Silent Patch":** Internal logs show a shift from 200 OK to 404 Not Found for the exposed endpoints immediately after the report.
    
3.  ​**Researcher Retaliation:** Node 7 was banned from the platform and HackerOne instead of receiving acknowledgment.
    

### ​**4\. Conclusion**

​The evidence is irrefutable. ElevenLabs has prioritized its market valuation over the security of its users' most personal asset: **their voice.**

> ​**Sovereignty Over Software.**
> 
> ​_Node 7 Security Research_
> 
> ​"For more exclusive details and full evidence, contact us at:
> 
> 📧 The7thNode@gmail.com"
> 
> ![](https://storage.googleapis.com/papyrus_images/d492515d8cceec2280d53be630348305be3736e623034b401aafa5b2be070498.jpg)

![](https://storage.googleapis.com/papyrus_images/61b434438d18f5328bfb970235eb7347b5d9af8f06f6ff5cf0ae97d735553dac.jpg)

​"Direct interaction with @ElevenLabs infrastructure via Termux. Evidence of internal API mapping and configuration exposure. This confirms the reach into their backend systems."

"Successful retrieval of stored voice data from ElevenLabs' Google Cloud Storage. The 'HTTP 200 OK' response proves unauthorized access to biometric assets is possible due to their configuration flaws."

---

*Originally published on [Developing artificial intelligence senses](https://paragraph.com/@0x4fd3729a4fedf54a74b73d93f7f775a1ef520cec/%E2%80%8B%F0%9F%9B%A1%EF%B8%8F-node-7-security-research-elevenlabs-evidence-dossier)*
