Innovation & Tech

Supabase Hosts Thousands of Leaky Databases, UpGuard Finds

UpGuard found about 16,000 Supabase-hosted databases exposing personal data — names, addresses, phone numbers and passwords — as AI vibe-coding fuels a new wave of breaches.

By Nathan Brooks

3 min read

Updated

Some Supabase customers are publicly exposing reams of people’s data to the web
Some Supabase customers are publicly exposing reams of people’s data to the webelycefeliz / Openverse

What's News

  • UpGuard found around 16,000 Supabase-hosted databases with exposed personal data, including names, addresses, phone numbers and passwords.
  • Supabase reached a $10 billion valuation earlier this year, driven by developers hosting AI vibe-coded apps on the platform.
  • Supabase CISO Bil Harmer said projects are "secure by default" and that customers control how their own projects are configured.

Security firm UpGuard found roughly 16,000 databases hosted on Supabase that exposed some degree of personal data to the public web, turning the $10 billion development platform into the latest flashpoint in the wave of breaches tied to AI-built apps.

Supabase, which lets web and app developers store and run databases, reached a $10 billion valuation earlier this year. The surge came from developers hosting "vibe-coded" apps — software generated with AI tools — on the platform. The company has faced sustained criticism over user security, with widely documented cases of customers misconfiguring or unknowingly exposing their databases to the broader internet. In some instances, the exposures ran to millions of records each.

UpGuard told TechCrunch it found publicly accessible names, addresses, phone numbers and user passwords across the platform. The research also surfaced a smaller number of passwords and authentication tokens.

The findings point to a structural weakness in AI-assisted development. While AI tools let almost anyone build a working website or app, the generated code can contain security flaws. Apps may also require specific configuration that a developer never knows about.

What the databases contained

UpGuard said the exposed databases were linked to a wide range of projects. They included private conversations with sex workers on an Indian adult streaming site, thousands of license plates from a U.S. valet service, and contact information of people who used an immigration and relocation service. One database belonged to an African government's consulate in France.

Another database was used by a virtual SIM farm to intercept text messages carrying one-time passcodes for online account verification — a technique typically used to launch scams and phishing attacks.

The majority of the exposed datasets appear to be located in the United States, but UpGuard said the problem is worldwide. The findings build on earlier research that also documented a range of exposed Supabase-hosted databases, including ones belonging to Y Combinator startups and other popular apps.

Misconfigured storage servers, databases and websites have driven countless breaches over the years. Past incidents leaked sensitive military emails, immigration and visa applications, classified government files, hundreds of thousands of driver's license scans, and children's personal information. The boom in AI vibe-coding is now fueling a new wave of exposures, many of them linked to Supabase as adoption grows.

Supabase responds

Supabase has made changes to its platform over the years, including bolstering platform security and user access controls for databases.

When reached for comment, Supabase Chief Information Security Officer Bil Harmer said the company had not seen the research but stressed that its projects are "secure by default." He framed security as a shared responsibility between the company and its customers.

"We provide secure defaults and tooling, and customers control how their own projects are configured," Harmer said. He added that the company notifies affected customers when it discovers security issues.

"Security at Supabase is never finished. We care deeply about getting it right, and we'll keep making it easier for every developer to ship securely," said Harmer.

UpGuard security researcher Greg Pollock said the research mattered because it raised awareness about data exposures on the platform.

The episode leaves Supabase with a familiar tension for a platform business: its $10 billion valuation rests on explosive developer adoption, but that same low barrier to entry is producing thousands of misconfigured databases. Expect scrutiny of its "secure by default" claim to intensify as vibe-coded apps multiply.

Original: upguard.com

Share this article:

More from Nathan Brooks

Nathan Brooks

Show full bio

News editor covering marketplaces and e-commerce at Business Bearings.

242 articles

Related articles

« Previous articleNext article »