On July 8, 2026, Phia told the public it had discovered a problem with its shopping app "within the last 24 hours." On August 11, Bloomberg published Slack logs showing the company's co-founders had been directing the exact feature at issue since December 2025, seven months earlier, according to Bloomberg's investigation. Those are two different companies. One of them is lying.
The feature at the center of the dispute is called enable_coupon_auto_drop. It was switched on December 10, 2025, and switched off July 7, 2026, the same day Bloomberg contacted the company for comment, according to Slack logs cited by ZeroHedge, Bloomberg, and independent researcher Ben Edelman. Edelman identified it as a server-side toggle that could be flipped remotely, meaning someone at Phia could turn cookie stuffing on and off without pushing new code. That is not the architecture of a bug. It is the architecture of a switch.
What the December Slack message actually says
On December 18, 2025, Phoebe Gates told developers on Slack to confirm that automatic cookie drops were live across every site offering a coupon, so the company could "monetize all merchandise value," according to the Slack logs Bloomberg obtained. Phia's defense is that this instruction was about a broken pop-up interface, not a directive to stuff cookies. The company says the coupon display wasn't rendering for users, which would have depressed attribution numbers regardless of whether cookies were dropping correctly, and that Gates was asking her team to isolate where the pipeline was failing.
That is a coherent technical explanation, and it deserves to be stated at full strength: engineers debug systems by checking each stage of a pipeline, and "confirm the cookies are dropping" is a normal diagnostic instruction if you suspect the failure is downstream of that step. If the pop-up was broken, checking cookie delivery first is exactly what a competent engineering lead would ask for.
The explanation runs into the same wall twice. First, the toggle stayed on for nearly seven months, not the length of a debugging sprint. Second, a Phia data scientist wrote in a Slack message on July 7 that cookie stuffing accounted for roughly 51% of the gross merchandise value the company claimed credit for in June 2026, according to Fortune's reporting. If the feature were a display bug incidentally interacting with attribution, it would not be responsible for half the company's claimed sales seven months after it was switched on and one day before it was switched off in response to a reporter's email.
The revenue chart Bloomberg found
The clearest evidence isn't the Slack logs. It's the money. When the cookie stuffing features went dark in early July, Phia's average daily revenue collapsed from about $80,000 to somewhere between $10,000 and $28,000, according to an internal revenue chart Bloomberg reviewed. That's a drop of 65% to 87.5% in daily revenue, depending on which end of the range you use, attributable to turning off a single feature the company describes as a minor bug.
A glitch that quietly generates two-thirds to seven-eighths of your daily revenue isn't a glitch. It's the business model. Bloomberg's retesting after the July 7 fix confirmed the automatic attribution behavior had actually stopped, according to HOKANEWS's account of the retest, which at least establishes that whatever was happening before July 7 was real and had a measurable, reproducible effect on revenue. That undercuts the idea that the whole episode was a display glitch with no meaningful commercial consequence.
What cookie stuffing actually does
Affiliate marketing pays companies like Phia a commission when a user they referred completes a purchase. The mechanism is a tracking cookie: when a user clicks a legitimate affiliate link, a cookie is set on their browser, and if they buy something within a window, the referrer gets credit. Cookie stuffing drops that cookie without a genuine referral, meaning the company collects a commission on a sale it did nothing to influence. The user gets no discount they wouldn't have gotten anyway. The retailer pays a commission twice, once perhaps to whoever actually earned it, and again to whoever stuffed the cookie last. It is a tax on merchants and legitimate affiliates, collected by a browser extension the user installed to save money.
Impact.com, one of the affiliate networks Phia works through, suspended the company's account, citing behavior that violated platform policies. Phia's own statement in response to that suspension was that the problematic code had been added in December 2025, according to BigGo Finance's reporting. That is Phia's own admission of the December start date, made to a business partner rather than the press, before the "24 hours" framing was offered publicly on July 8, according to Fortune.
The other half of Phia's case
Phia's stronger argument isn't about intent. It's about what happened after. The company disabled the disputed features, has begun issuing transaction reversals to affected partners, and has committed to hiring a chief compliance officer, according to reporting on the company's public response. Networks like Impact.com run their own independent traffic monitoring, the company notes, which is precisely how the suspension happened. That's a real point: if Phia were running a knowing, sustained fraud, the exposure came from an external auditor catching an anomaly, not from Phia self-reporting it. Companies engaged in deliberate, coordinated concealment don't typically leave a clean data trail for a network's fraud detection system to catch, and they don't typically have a data scientist writing internal Slack messages quantifying the exact percentage of GMV that was inflated.
That argument holds up for the question of what Phia did once caught. It does not hold up for the question of what Phia said once caught. The 24-hour claim is not a claim about remediation, it's a claim about discovery, and the Slack logs put the actual discovery date at December 2025, seven months earlier, per Bloomberg's timeline. A company can be genuinely remorseful about a scheme and still misrepresent when it learned about that scheme. Those are separable facts, and Phia's post-hoc compliance measures answer the first without touching the second.
Why the timeline is the story
Phia raised $35.5 million in a Series A in January 2026 at a $185.5 million valuation, bringing total funding to $43.5 million since its April 2025 launch, according to OuiSpeakFashion's reporting on the raise. That valuation was set in January 2026, a month after the December 10 toggle went live and eight days after the December 18 Slack message instructing developers to confirm cookies were dropping across every coupon-offering site. Investors who priced Phia at $185.5 million were pricing a growth curve that Bloomberg's revenue chart suggests was substantially inflated by an undisclosed attribution scheme, for the entire period their capital was being deployed.
This is where "glitch versus scheme" stops being a semantic argument and becomes a valuation question. A company that discovered a 24-hour bug in July has a disclosure problem contained to a single quarter. A company that knew for seven months, raised a Series A in the middle of that window, and told investors and users a materially different story has a disclosure problem that spans its entire funded life to date. The gap between those two versions of events is not a rounding error. It's the difference between an operational hiccup and the central fact an investor would have wanted before wiring $35.5 million.
Who this actually costs
The people paying for this aren't abstract. Merchants who paid affiliate commissions on sales Phia didn't generate lost margin they didn't need to lose. Legitimate affiliates who did the work of referring genuine customers had their commissions diluted or displaced by stuffed cookies claiming credit ahead of them. Series A investors priced a company on revenue figures that included a feature generating, by Phia's own data scientist's estimate, roughly half of a month's claimed gross merchandise value through means the company now says it has shut down. Users who installed Phia's extension to find real discounts got a browser plug-in quietly setting tracking cookies for purchases it had no role in, at no benefit and no cost to them individually, but at a cost to the market they were shopping in.
The founders benefit from the glitch framing regardless of which version is true, which is exactly why the framing needs the paper trail behind it, not the press release. Bloomberg supplied that paper trail. Phia has not yet supplied one that survives it.