Phia's Affiliate "Bug" Was Reportedly a Feature With an On/Off Switch. If You Run Affiliate Links, Nobody Alerts You When This Happens.
Phia's Affiliate "Bug" Was Reportedly a Feature With an On/Off Switch. If You Run Affiliate Links, Nobody Alerts You When This Happens.
In July, Bloomberg published an investigation showing that Phia, the shopping startup co-founded by Phoebe Gates and Sophia Kianni, was taking credit and commission for affiliate purchases it did not help generate. That practice is called cookie stuffing. At the time, a Phia spokesperson told Bloomberg the company only became aware of the issue when Bloomberg reached out.
On August 11, Bloomberg reported that the founders knew as far back as December, citing leaked Slack messages and sources familiar with the matter. The same reporting says the behavior was not a bug but a deliberately built feature that could be switched on and off, that it accounted for a meaningful share of Phia's sales, and that daily revenue dropped noticeably once it stopped. Nike and Nordstrom were among the affected retailers.
Phia told TechCrunch that "any features causing misattributions were immediately removed over a month ago on July 7," that it is reviewing every transaction, that it has begun issuing transaction reversals to brand partners, and that it is hiring a head of compliance. It disputes parts of Bloomberg's account.
I am not writing about this because of whose daughter runs the company. I am writing about it because it is the clearest documented example I have seen of a failure mode that quietly costs money to anyone publishing affiliate content, and almost nobody audits for it.
How the money actually moves
Most affiliate programs settle on last-click attribution. When someone buys, the network looks at the most recent affiliate cookie in that browser and pays whoever set it.
That rule is simple, cheap to implement, and completely indifferent to who did the work. If you spent four hours writing a comparison of six pairs of running shoes, and a reader clicks your link, and then a browser extension drops its own affiliate cookie on the checkout page before the purchase completes, the extension gets paid. Your click is in the network's logs. Your conversion is not.
The critical detail, and the reason this is a story about you rather than about a retailer's margin: the commission does not come out of Nike's pocket. Nike pays one commission on that sale either way. Cookie stuffing does not create a cost for the retailer, it reallocates a payment away from whoever actually drove the sale. It is not fraud against the merchant. It is a transfer from publishers to whoever fires last.
This is exactly why affiliate networks ban it contractually. When a platform signs into a marketplace, the agreement typically prohibits cookie stuffing outright, because the network's whole product is trustworthy attribution, and because the injured party has no other recourse. You do not have a contract with the extension. You have one with the network.
You will never get an alert
Here is what makes it worse than ordinary revenue variance: there is no signal.
A stuffed cookie produces no error, no email, no line item labeled "commission redirected." Your dashboard shows clicks going out and conversions coming in, and if the conversions are lower than they should be, that reads exactly like your content underperforming. You will conclude your post did not convert. You will rewrite the post.
Phia's case is instructive on timing here. Bloomberg's first investigation ran in July. The behavior reportedly ran from at least December. That is six-plus months during which every publisher losing commissions on Nike and Nordstrom purchases had no way to know, and every one of them had a plausible alternative explanation sitting right there: seasonality, algorithm changes, a bad month.
The check to actually run
Set aside twenty minutes and do this rather than reading more coverage of it.
Pull your affiliate dashboard's click-to-conversion ratio, broken out by network and by merchant, for the last 90 days. Then compare it against the same window a year ago, and against your own analytics for outbound link clicks.
The signature you are looking for is specific: clicks holding steady or rising while conversions fall, isolated to particular merchants rather than across the board. Traffic quality problems hit everything at once. Attribution theft hits the merchants where a competing extension has coverage, and leaves the rest alone. If your Amazon numbers look normal and one fashion retailer fell off a cliff while clicks held, that asymmetry is the tell.
While you are in there, read your network's terms and find the clause on attribution and prohibited practices. Two reasons. First, you need to know whether you have standing to complain, and you almost certainly do, because these clauses are close to universal. Second, most networks have a mechanism for reporting suspected misattribution and it is buried somewhere unhelpful. Find it before you need it, not during.
The realistic outcome, and I want to be honest about this, is that you find nothing conclusive. Attribution is noisy, 90 days is a short window, and a solo publisher's volume is often too small to distinguish theft from variance with any confidence. That is a real limitation and it is why this problem persists. But "I checked and the ratio is stable" is worth knowing, and it costs you twenty minutes.
What I'd actually do beyond the audit
Diversify what a click is worth to you. If a link's only value is the commission on a last-click window, you have handed a third party a switch that turns your revenue off. If the same click also puts someone on a list, or lands them on a page you own, or gets a comparison table in front of them that they come back to, then attribution theft costs you one payment rather than the entire value of the traffic.
That is not a workaround for cookie stuffing. Nothing a publisher does prevents cookie stuffing, because the mechanism lives in the buyer's browser, well outside anything you control. It is a way of making the theft survivable.
The other thing I would do is stop treating affiliate income as passive. The framing that sells courses is that you write once and collect forever. What the Phia case shows is that the collection half runs on infrastructure you do not own, governed by rules you did not write, monitored by nobody on your behalf. Passive is the wrong word for money that requires a quarterly audit to confirm you are still receiving it.
The honest counter
The founders'-knowledge claim rests on leaked Slack messages and unnamed sources in Bloomberg's reporting, and Phia disputes parts of the account. I have no independent way to verify it and neither do you. If you build an argument on "they knew since December," you are building on contested reporting, and it is worth being disciplined about that even when the reporting looks solid.
What is not contested, because Phia said it publicly in its own statement, is that features causing misattribution existed and were removed on July 7, and that reversals are being issued to brand partners. That is enough for everything in this post. The audit is worth running whether or not anyone at Phia knew anything, because the vulnerability is in last-click attribution itself, not in one company's ethics.
And a fair point in the other direction: browser extensions that apply coupons and cashback provide real value to shoppers, which is why people install tens of millions of them. The line between "found the user a discount and earned the commission" and "attached itself to a sale it did not influence" is genuinely blurry in a way that "cookie stuffing is theft" flattens. The clean cases are clean. Plenty of the volume is not.
Author
Lukas
@lukcombinatorSources
- Phoebe Gates and Sophia Kianni reportedly knew Phia was 'cookie stuffing' for months (TechCrunch)
- Phia accused of cookie stuffing, taking affiliate credit on purchases it didn't earn (TechCrunch, July 2026)
- Phia app co-founders pushed for features taking credit for sales it didn't drive (Bloomberg)
- Can Phia's affiliate model survive the scandal? (Puck)