Skip to content

Security Firm Finds 16,000 Exposed Supabase Databases Tied to Vibe-Coded Apps

Short answer

Cybersecurity firm UpGuard found approximately 16,000 Supabase-hosted databases publicly exposing personal data — names, addresses, phone numbers, and some passwords — often due to misconfiguration in AI-generated ('vibe-coded') apps. Supabase says security is a shared responsibility; the exposures show how fast, AI-assisted app building can outpace basic access-control hygiene.

What this means for operators

If your team has used AI coding assistants or no-code/low-code tools to quickly stand up a customer database, internal dashboard, or lead-capture app on Supabase or a similar backend, this is a direct prompt to audit access rules now, not after a breach. Vibe-coded apps are often shipped by non-security-specialists who accept default settings, and the defaults are not always safe — UpGuard's findings show real production data (contact info, tokens, even intercepted verification codes) sitting open to the public internet. For a 10-200 person company, the fix is cheap relative to the exposure: a scheduled review of row-level security and public API access on every database backing a customer-facing or vibe-coded tool, treated as a standing item, not a one-time launch check.

Cybersecurity firm UpGuard has found around 16,000 databases hosted on Supabase that were exposing some degree of personal data to the public web. Supabase is a development platform that lets developers store and run databases behind their web and app projects, and it has grown quickly this year alongside the rise of AI-assisted 'vibe coding,' reaching a $10 billion valuation.

The exposed data included names, addresses, phone numbers, and in a smaller number of cases, passwords and authentication tokens. UpGuard cited specific examples: private conversations from an adult streaming site, license plate records from a U.S. valet service, contact details from an immigration and relocation service, records tied to an African government consulate, and a database used by a SIM farm to intercept verification texts, typically associated with scam and phishing operations.

Most of the exposed data was located in the United States, though UpGuard characterized the problem as global. The firm's findings build on earlier research that had already flagged exposed Supabase databases belonging to Y Combinator startups and other apps.

Supabase's Chief Information Security Officer, Bil Harmer, said the company had not reviewed UpGuard's specific research but described its projects as 'secure by default,' framing security as a shared responsibility between the platform and its customers. He said Supabase notifies affected customers when issues are found and continues to invest in making secure configuration easier.

The pattern is not new — misconfigured cloud storage and databases have caused breaches for years — but the scale tied to AI-assisted app building is notable. Vibe-coded apps are often built quickly by people without deep security expertise, and the underlying generated code or default database settings can leave data publicly accessible without the developer realizing it.

Source: TechCrunch AI

Next step

Discovery Sprint

If that argument holds for your operation, the next step is measuring it. Thirty minutes on one process, and we say whether the arithmetic is likely to close.

Put a time in the calendar

Thirty minutes, free. The sprint is what the call is about.

Fee
$2,500
Length
1-2 weeks

Ends in one of two answers: build this, or do not. The process map, the numbers and the ranked backlog are yours either way.