
What happened
UpGuard told TechCrunch it found around 16,000 Supabase-hosted databases exposing personal data such as names, addresses, phone numbers and passwords, with a smaller number of authentication tokens.
Why it matters
Supabase, which reached a $10 billion valuation on the back of vibe-coded apps, says projects are "secure by default," so the exposed data points to a shared-responsibility gap customers may be missing.
What to watch
The exposure count hinges on how many of those projects are misconfigured rather than breached, and Supabase has not seen UpGuard's research. Watch whether more exposed sets surface, as earlier research also hit Y Combinator startups.
WHO IT HITSThis lands hardest on developers and small teams running vibe-coded apps on Supabase who manage their own database configuration and may not know a setting is publicly reachable. Security and compliance staff at these startups likely need to audit their Supabase projects.
Summaries like this, in your inbox every morning.
Supabase's rise is tied to the boom in AI-assisted "vibe-coded" apps: developers can stand up a website or app quickly, but the generated code can carry security flaws, and the platform may need configuration the developer does not know about. UpGuard's research builds on earlier findings of exposed Supabase databases, including ones tied to Y Combinator startups and other popular apps, and the firm says it wanted to understand the scale of the problem across the platform. The examples it surfaced are varied: private conversations on an Indian adult streaming site, license plates from a U.S. valet service, contact information from an immigration and relocation service, a database belonging to an African government's consulate in France, and a virtual SIM farm used to intercept one-time passcodes.
Supabase has made changes over the years, including bolstering its platform and user access to databases, and its CISO, Bil Harmer, says the company notifies affected customers when security issues are discovered and that getting security right is ongoing work. The tension is that the two sides describe the same setup differently: UpGuard points to misconfiguration and improper security as the cause, while Supabase frames defaults as safe and configuration as the customer's responsibility.
How this plays out likely hinges on whether developers on the platform can find and fix their own exposed projects, and whether Supabase's "secure by default" position holds up if more of these datasets surface. For the startups and small teams building on Supabase, the practical question is whether their own databases are among those reachable from the open web.
For example, today's edition would include:
AI-summarized, only the topics you pick: one digest a day via Email, LINE, or Slack.
Free · 30 seconds with Google · unsubscribe anytimeWhat is AIToday? →
Ask AI anything about this article. The AI reads this article, earlier AIToday articles, and Wikipedia, and cites its sources. Q&As are published on this page for other readers too.
Tamara Grant, who finished Purdue University's Master of Science in Artificial Intelligence in spring 2026, wa…

Palo Alto Networks announced Prisma AIRS runtime security integrated with Google Cloud's Agent Gateway, a Gemi…

Zenity Labs published findings on September 24 detailing 'SalesBleed,' an attack chain that slipped hidden pro…

Google, OpenAI, and Anthropic announced a joint move on AI safety

In five experiments with 3,132 participants, mere access to AI advice — including answers shown automatically…

Hinton told the Atlantic that a smart AI given a goal will derive its own subgoals, and even without a bad act…
