Cybersecurity firm UpGuard reported that roughly 16,000 databases hosted on the Supabase development platform were publicly reachable, revealing personal information. The investigation, disclosed to TechCrunch, identified varying degrees of data exposure across these instances. Supabase provides developers with tools to store and operate databases for web and mobile applications.
Earlier this year Supabase achieved a valuation of ten billion dollars, driven by a surge in developers deploying AI-generated, or “vibe-coded,” applications on its services. Critics have highlighted recurring security lapses, noting that users often misconfigure settings or unintentionally expose their databases, sometimes affecting millions of records. The rapid adoption of AI-assisted coding is amplifying these risks.
The exposed datasets included basic identifiers such as names, addresses, phone numbers, as well as user passwords and authentication tokens. Specific instances cited by UpGuard involved private chats with sex workers on an Indian adult-streaming platform, thousands of vehicle license plates from a U.S. valet service, and contact details of users of an immigration and relocation provider. Additional leaks comprised data from an African government consulate in France and a virtual SIM farm used to intercept one-time passcodes.
While most of the compromised databases were located in the United States, UpGuard emphasized that the issue extends globally. Earlier investigations had already uncovered exposed Supabase databases belonging to Y Combinator-backed startups and other popular applications. The breadth of the findings suggests a systemic challenge in securing cloud-hosted development environments.
Supabase’s chief information security officer Bil Harmer responded that the company had not seen the specific research but maintains that its projects are secured by default. He stated, “We provide secure defaults and tooling, and customers control how their own projects are configured,” framing security as a shared responsibility. Harmer added that Supabase notifies affected customers when vulnerabilities are detected and continues to improve protective measures.
UpGuard researcher Greg Pollock described the study as a valuable effort to raise awareness of data exposure risks. He highlighted the need for developers and platform providers to adopt stronger security practices, especially as AI-driven code generation becomes more prevalent. Pollock’s comments underscore the broader industry challenge of balancing rapid development with robust protection.