Phoebe Gates, Phia, and the Cookie Stuffing Saga — Affiliate Fraud's Wire Fraud Problem
2026-08-14
If you follow tech news at all, you've probably seen the name Phoebe Gates in the headlines this week — and not for the reason she'd like. The 23-year-old daughter of Bill Gates co-founded a shopping app called Phia, and a Bloomberg investigation this week claims she and co-founder Sophia Kianni knew their app was "cookie stuffing" — quietly stealing affiliate credit for sales it didn't drive — for at least seven months.
The kicker? Cookie stuffing is the same technique that has sent people to federal prison for wire fraud.
Let's dig into what Phia actually does, how cookie stuffing works under the hood, what the leaked Slack messages show, and why legal experts keep bringing up 20-year sentences.

What is Phia?
Phia is an AI-powered personal shopping assistant launched in April 2025 by Phoebe Gates and Sophia Kianni — former Stanford roommates. It ships as both a browser extension and a mobile app. Think Google Flights, but for shopping: it compares prices across new, resale, and luxury retail sites, hunts down discount codes, and even estimates resale value before you buy ("Should I Buy This?").
Here's the business model that matters for this story: affiliate marketing. When a shopper arrives at a retailer's site through Phia's referral, and that shopper buys something, Phia gets a cut of the sale. That's a totally normal model — Wirecutter, Honey, Rakuten, and half the internet run on it.
The company grew stupid fast. By June it claimed 1.5 million users, ~10,000 retail brand partnerships, and 350+ million products scanned. It raised $8M from Kleiner Perkins in September 2025, then a $35.5M Series A in January 2026 at roughly a $185M valuation — $43.5M total. The cap table is a celebrity guest list: Sydney Sweeney, Paris Hilton, Khloé Kardashian, Priyanka Chopra Jonas, Jessica Alba, Mindy Kaling, Karlie Kloss, Halsey, Ice Spice, plus Robinhood founder Vlad Tenev. It made TIME's Best Inventions of 2025.
What is cookie stuffing, actually?
Cookie stuffing is affiliate fraud. The mechanics are simple:
- A user visits a retailer's site — say, Nike.com. They got there on their own, or through a legit affiliate like a YouTuber's link, or via an outlet like Wirecutter.
- Someone else's code (in this case, Phia's browser extension) silently drops its own tracking cookie onto the user's browser — often in a hidden background tab, with zero user interaction.
- When the user checks out, the retailer's affiliate network sees Phia's cookie as "last touch" and pays Phia the commission. The actual referrer — the YouTuber, Wirecutter, whoever — gets nothing.
That's the "stuffing" part: you're stuffing a cookie that has no business being there into the attribution path. It doesn't just defraud the retailer (which pays commissions on sales it thought were referrals); it directly steals revenue from other affiliates who legitimately drove the traffic.
Browsers literally have a built-in defense against it: when a tab loads without user activation, most browsers strip third-party cookies set by that tab. So to beat the browser, you redirect through a real top-level navigation — an invisible tab that performs an actual redirect chain through the affiliate network. That's what Phia's extension did on iOS, per independent researcher Ben Edelman's write-up: forced background redirects that executed as genuine navigations, dropping Phia's affiliate cookie into the path.
Almost every affiliate program contract explicitly bans this. It's also potentially a crime.
The wire fraud connection — cookie stuffing has sent people to prison
Cookie stuffing maps cleanly onto federal wire fraud: 18 U.S.C. § 1343, which covers fraudulent schemes carried out over interstate wire communications — and the internet counts. Maximum penalty: 20 years in prison and a $250,000 fine. This isn't theoretical. There's a well-documented record of convictions:
The eBay "Trip Wire" sting (2006–2014). The most famous case. eBay partnered with the FBI to build a sting targeting its own top affiliate marketers. Shawn Hogan, eBay's largest affiliate, had been loading eBay resources on his own site to set affiliate cookies on visitors' browsers — then claiming credit for whatever they bought, to the tune of $28M in fraudulent commissions. He pleaded guilty to wire fraud and got five months in federal prison plus a $25,000 fine. His accomplice Brian Dunning pleaded guilty and got 15 months plus three years of supervised release.
The Alabama cookie-stuffing ring (2014–2015). The DOJ in the Southern District of Alabama prosecuted a group running cookie stuffing against Fareportal through Google and Linkshare's affiliate programs. Jefferson Bruce McKittrick pleaded guilty to wire fraud conspiracy in June 2014, and Jody Michael Smith pleaded guilty in January 2015 — same charge, same 20-year maximum exposure. Their "forced clicks" made unsuspecting web shoppers generate commissions the conspirators never earned.
PayPal Honey (ongoing). The most relevant precedent for Phia, honestly. Honey — the PayPal-owned coupon extension — used the exact same technique and was hit with a class action accusing it of overwriting other affiliates' referral cookies at checkout. It's civil, not criminal, but it shows the playbook: lawyers, discovery, and a long, expensive fight.
The pattern in every criminal case is the same: a scheme to deceive an affiliate network into paying unearned commissions, executed over the internet, = wire fraud. That's why Futurism and every legal expert quoted this week are pointing at § 1343 for Phia.
The Bloomberg investigation — first the "bug," then the Slack leaks
The story broke in two acts.
Act 1 — July 9. Bloomberg reported that testing by Bloomberg itself, competitor Capital One Shopping, and Ben Edelman found Phia's extension opening background tabs during checkout and injecting its own referral code — overriding legitimate codes from publishers who actually drove the traffic. Bloomberg tested it across 50+ retail sites. Phia's response: it was a bug, introduced in a recent release, discovered only when Bloomberg called, fixed within 24 hours. Impact.com suspended Phia's account pending review. TechCrunch covered the fallout here.
Act 2 — August 11. Bloomberg's follow-up blew the bug story apart, using leaked internal Slack messages. The receipts:
- The cookie-dropping behavior wasn't a bug — it was a purpose-built feature with an internal dashboard toggle literally labeled "enable coupon auto drop." It was switched on in December and switched off the same day Bloomberg first contacted Phia in early July.
- Gates and Kianni knew about it from the start. Slack shows Gates asking developers to confirm Phia was automatically dropping cookies across retailers so the company could monetize more sales.
- Kianni wrote, per the report: "Whatever we can do to keep these cookies dropping will be amazing thank you."
- A Phia data scientist's Slack message on July 7 estimated cookie stuffing accounted for ~51% of the merchandise value Phia claimed credit for selling.
- Affected retailers included Nike and Nordstrom, and Phia's daily revenue dropped significantly once the practice was disabled.
A Phia spokesperson told Bloomberg the company "rebuffed some of the publication's claims" but would "learn from this." To TechCrunch, they said the features were removed July 7, transaction reversals are underway, and they're hiring a head of compliance.
Seven months of "we had no idea" collapsed in one Slack screenshot.
No, Bill Gates isn't bankrolling Phia
One thing worth getting straight, because it's been a running theme: Phia is not funded by the Gates family. TechCrunch has flagged this repeatedly — "no, her parents are not bankrolling her startup." Phia's earliest money was $100K from Soma Capital, a $250K Stanford grant, and $500K in angels. Bill Gates explained why he deliberately stayed out: "I probably would have been overly nice." He's said his kids get less than 1% of his wealth. Phoebe herself has been vocal about building without the name: "I have a chip on my shoulder" and wanting success with "no ties to my privilege or my last name." The irony that she built an independent company and still ended up the face of an affiliate fraud story is not lost on anyone.
That independence cuts both ways, though: with no Gates money on the cap table, there's also no family soft-landing if partners sue or prosecutors come calling.
The earlier controversy you might have missed
This wasn't Phia's first trust problem. In November 2025, Fortune reported that security researchers found Phia's extension transmitting snapshots of virtually every web page users visited — including bank statements and private emails — back to Phia's servers, even when users weren't shopping. Phia said it was anonymous logging to find new retail sites. GDPR compliance lawyers disagreed. Same extension, same "trust us" posture.
Where things stand
- Impact.com, Rakuten, and Awin opened investigations; Impact.com already suspended Phia in July.
- Puck reported Phia lost nearly half its full-time staff since January, that brands were unaware they were listed in the app, and investors were spooked by how aggressively Phia leaned on affiliate revenue.
- Retailers are freezing payouts and auditing past attributions; users have been uninstalling in droves (the PayPal Honey comparison is brutal — Honey lost ~4M users after its scandal).
- No charges have been filed. But as one legal observer put it, cookie stuffing "can carry a maximum penalty of 20 years in prison" — and the Slack messages move this from "engineering bug" to "knowingly enabled," which is exactly the mens rea wire fraud requires.
The takeaway
The Phia story is a useful stress test for the whole affiliate economy. Attribution is an honor system running on cookies that no one can see, and the incentive to stuff them is enormous when your entire revenue model depends on commissions. The difference between a startup with a revenue problem and a federal defendant is usually just the audit trail — and Phia helpfully provided one in Slack.
If you run an affiliate program, today's homework is simple: audit your referrers for forced clicks, check for background-tab redirects, and make sure "enable coupon auto drop" isn't a config toggle your product team can ship. Cookie stuffing has been prosecuted as wire fraud for over a decade. Twenty years is a long time to explain a cookie.