16,000 Supabase Databases Expose Personal Data as Vibe Coding Security Risks Grow
UpGuard found about 16,000 Supabase databases exposing names, addresses and passwords worldwide, highlighting risks from misconfigured vibe-coded apps.
Summary
On September 25, 2026, UpGuard disclosed about 16,000 Supabase hosted databases exposing some personal information publicly. Accessible records included names, addresses, phone numbers and passwords, with fewer authentication tokens. Projects exposed private conversations with sex workers on an Indian adult streaming site, thousands of license plates from a U.S. valet service, immigration and relocation customers’ contacts, an African government consulate’s database in France, and text messages intercepted by a virtual SIM farm sending one-time passcodes for account verification, scams and phishing. Most datasets appeared U.S. based, but exposures were worldwide. Earlier research found vulnerable Supabase databases belonging to Y Combinator startups and popular apps.
Supabase reached a $10 billion valuation earlier in 2026 as developers increasingly hosted vibe-coded apps, but documented customer misconfigurations have exposed millions of records per database. AI tools simplify app development, yet generated code can contain flaws and inexperienced developers may overlook required security settings. Similar configuration failures have leaked military emails, immigration and visa applications, classified government files, hundreds of thousands of driver’s license scans and children’s data. Supabase has strengthened database access controls. Chief Information Security Officer Bil Harmer, who had not reviewed UpGuard’s findings, said projects are secure by default, customers control configurations, affected customers receive notifications and security remains a shared responsibility. UpGuard researcher Greg Pollock said the research should raise awareness.
Positives
- Supabase has strengthened its platform and customers’ database access controls over time.
- Bil Harmer says Supabase projects provide secure defaults and security tooling.
- Supabase notifies affected customers when it discovers security issues in their projects.
- Greg Pollock says UpGuard’s research can increase awareness of preventable data exposure.
Risks & concerns
- About 16,000 Supabase databases exposed some personal information to the public web.
- Public records included names, addresses, phone numbers and passwords, plus fewer authentication tokens.
- Individual exposures involved private sexual conversations, license plates, immigration contacts, consular data and intercepted one-time passcodes.
- Documented Supabase customer misconfigurations have exposed millions of records from individual databases.
- AI generated code can contain security flaws, while developers may overlook essential configuration requirements.
- Virtual SIM farm data involved passcodes commonly used to launch scams and phishing attacks.