i
News
News · 2026-09-25

Supabase data exposure puts AI-built apps’ security defaults to the test

@neuronium_ai @neuronium_ai

About 16,000 Supabase databases exposed some form of personal information, according to security firm UpGuard, which shared its findings with TechCrunch. The exposed records included names, addresses, phone numbers and passwords. The scale matters because Supabase has become a popular place to store data for apps built with AI coding tools—where a project can be easy to launch and still be left open to the internet.

Cover: Supabase data exposure puts AI-built apps’ security defaults to the test

The data behind the count

UpGuard found databases tied to a range of projects:

Private messages with sex workers on an Indian adult website
Thousands of license plates collected by a US parking service
Contact details belonging to customers of an immigration and relocation service
Data from an African country’s consulate in France
Intercepted text messages used by a virtual SIM farm to send one-time verification codes, which are commonly used to create online accounts for fraud and phishing

Researchers found fewer passwords and authentication tokens than other kinds of personal data. Most of the exposed datasets were in the US, UpGuard said, though the company described the problem as global.

The study follows earlier work that also found exposed Supabase databases, including some connected to Y Combinator startups and other popular apps. Supabase has made changes in recent years to strengthen security and access controls, but the findings show that platform-level safeguards do not eliminate the consequences of a customer’s configuration choices.

A platform problem, and a customer problem

Supabase lets developers store databases and run them for websites and apps. Its valuation reached $10 billion earlier this year, amid growing use by developers building apps through prompt-based coding.

That growth has brought a familiar security risk into a new development workflow. AI tools can make it easier to create an app, but generated code can contain vulnerabilities, and secure deployment can require settings a developer does not know to change. Misconfigured databases and storage servers have been behind data exposures for years; the newer factor is how quickly more people can build and publish software.

Supabase’s chief information security officer, Bill Harmer, told TechCrunch the company had not yet reviewed the study. He said projects are “secure by default,” while stressing that security depends on both Supabase and its customers. The company provides secure settings and tools, but customers choose how to configure their projects. Harmer said Supabase notifies affected customers when it finds security issues.

He also said the company would continue working to make it easier for developers to launch apps securely. UpGuard security researcher Greg Pollock said the work matters because it draws attention to the problem of exposed data.

The missing measure

The count is striking, but it does not tell us how many people were affected, how long the databases were accessible, or whether anyone accessed the exposed information. Those details would help distinguish a broad inventory of misconfigurations from a measure of actual harm.

I think the harder test for Supabase is not whether its defaults are secure in principle, but whether they prevent a growing population of less experienced builders from publishing sensitive data by mistake. As AI coding tools lower the cost of building apps, the security burden shifts toward defaults and guardrails that work even when the person deploying a project does not know what to check.

Daily AI news

Every day we pick what actually matters in AI and explain it plainly — no hype, no filler. Subscribe if you want to follow where the industry is going.

Only what matters — every day

Follow on X