Supabase Data Exposure Shows Vibe Coding’s Security Gap

AI has made building an app dramatically easier. Securing the database behind that app apparently hasn't become equally easy.

Cybersecurity firm UpGuard says it found roughly 16,000 databases hosted on Supabase exposing some amount of personal information to the public internet.

The exposed material included names, phone numbers, addresses and, in a smaller number of cases, passwords or authentication tokens.

Supabase says its projects are secure by default and argues that database configuration is a shared responsibility between the platform and its customers.

The incident is less about one traditional breach than a broader problem emerging from AI-assisted software development.

People can now build applications faster than they learn how to secure them.

Vibe coding changed who can create software

Generative AI has dramatically lowered the barrier to writing code.

A founder without deep engineering experience can describe an application in natural language and have AI generate significant portions of it.

That is powerful.

It is also dangerous when the same developer does not understand:

database permissions,

authentication,

API keys,

access controls,

or row-level security.

The app can appear to work perfectly.

The data underneath it may be completely exposed.

UpGuard's findings suggest this is already happening at meaningful scale.

The exposed data was not theoretical

Researchers found data associated with a wide variety of applications.

Among the examples reported were contact information connected to immigration and relocation services, U.S. vehicle-license-plate information and information from an African government's consular system in France.

Researchers also found data associated with a virtual SIM operation handling text messages used for online verification codes.

These examples illustrate why database misconfiguration can be so serious.

The developer may think they are exposing a backend API.

The attacker sees personal information.

Supabase has become infrastructure for the vibe-coding boom

Supabase has grown rapidly by offering developers an easier backend for applications.

It provides services such as databases, authentication, storage and APIs.

That makes it particularly attractive to developers building products quickly.

The company reached a $10 billion valuation earlier this year, with its growth helped by the surge in AI-assisted app creation.

That success also places Supabase in an unusual position.

The platform benefits when development becomes easier.

It also inherits some of the security problems created when increasingly inexperienced users build production applications.

“Secure by default” can only go so far

Supabase's security chief told TechCrunch that projects are secure by default and customers ultimately control how their own deployments are configured.

That is technically important.

The research does not establish that Supabase itself was hacked.

Instead, researchers say many customers configured systems in ways that exposed information publicly.

But the distinction raises a larger product-design question.

If thousands of users repeatedly make the same dangerous configuration mistake, when does user error become a platform-design problem?

Cloud providers have dealt with this question for years.

Public storage buckets created huge data leaks.

Providers eventually introduced increasingly aggressive warnings and safer defaults.

AI development platforms may have to evolve the same way.

The next developer may not understand security at all

Traditional software development created a rough filter.

Someone capable of building a database-backed web application usually had at least some exposure to programming concepts.

Generative AI removes part of that filter.

That is mostly positive.

More people can turn ideas into software.

But it also means someone can build an application containing highly sensitive information without understanding what a database permission actually does.

The AI generated the code.

The app works.

The founder ships it.

Nobody notices the table is publicly readable.

Until a security researcher does.

AI coding needs AI security checks

There is an obvious opportunity here.

If AI can generate an application, it can also inspect that application before deployment.

Coding platforms could automatically ask:

Is this database public?

Does this endpoint expose personal information?

Are passwords stored correctly?

Is this API key embedded in client-side code?

Are authentication rules actually enabled?

That could turn security into part of the creation workflow rather than a specialist review performed afterward.

The AI that creates insecure code could also become the system that stops it from shipping.

Fast development increases the security debt

Vibe coding encourages experimentation.

Build.

Deploy.

See whether users care.

Change it tomorrow.

That workflow is perfect for consumer prototypes.

It becomes dangerous when the application suddenly succeeds.

A prototype handling ten test records may eventually hold personal information belonging to 100,000 customers.

The security architecture may never catch up with the product's popularity.

That is how development speed becomes security debt.

What happens next?

AI coding is not going away.

If anything, increasingly capable models will make it possible for even more people to build applications without traditional software training.

Platforms such as Supabase therefore have an important challenge ahead.

The best developer experience may no longer simply mean making software easy to create.

It may mean making insecure software difficult to create accidentally.

Vibe coding democratized development.

The next phase has to democratize security too.

Our latest news