UpGuard Finds 16,000 Exposed Supabase Databases
Cybersecurity firm UpGuard has discovered that around 16,000 databases hosted on Supabase are exposing sensitive user data, highlighting the security risks of AI-driven vibe-coding.

Cybersecurity firm UpGuard has revealed that approximately 16,000 databases hosted on the development platform Supabase have publicly exposed sensitive user information. Supabase, which recently reached a $10 billion valuation, has become a highly popular backend choice for developers, particularly those utilizing artificial intelligence tools to rapidly build and deploy applications. However, this rapid development trend, often called "vibe-coding," has led to widespread security misconfigurations that leave massive amounts of data open to the public web.
According to UpGuard researcher Greg Pollock, the exposed datasets contained highly sensitive information, including names, addresses, phone numbers, passwords, and authentication tokens. Specific compromised databases included an African government consulate in France, a virtual SIM farm used to intercept text messages for phishing scams, a U.S. valet service containing thousands of license plates, and private chat logs from an Indian adult streaming website. While most of the exposed databases are located in the United States, UpGuard emphasized that the security issue is global.
The root of the vulnerability lies in how developers configure their databases. While AI code generators make it easy to spin up functional websites, they frequently generate code with security flaws or fail to prompt developers about critical security settings. Supabase Chief Information Security Officer Bil Harmer defended the platform, stating that its projects are "secure by default" and describing security as a "shared responsibility" where customers ultimately control their own configurations.
For software engineers and AI practitioners, these findings serve as a stark warning against relying solely on AI-generated code and default platform settings. Developers must actively audit their database access controls, implement row-level security, and avoid assuming that automated deployment pipelines handle security configurations. As the industry shifts toward rapid AI-assisted development, verifying security postures manually remains an indispensable step to prevent catastrophic data leaks.
This is our own summary of reporting by TechCrunch AI



