Get the app
Industry

Vibe-coding's bad day: Vercel and Lovable both breached

Vercel got hit via a rogue AI tool; Lovable leaked chat histories and DB credentials. Both on the same day.

Vibe-coding's bad day: Vercel and Lovable both breached

Vercel confirmed a breach traced to Context.ai, a third-party agentic AI tool. An employee granted it broad OAuth permissions, handing attackers a path into Vercel's internal systems. Threat actors — claiming ShinyHunters affiliation — allege they have 580+ employee records plus environment variables, and are listing the data on BreachForums for $2 million. Vercel says services are operational and has notified affected customers, urging immediate credential rotation.

On the same day, Lovable — the AI app builder behind thousands of vibe-coded products — reportedly suffered a breach exposing users' AI chat histories, source code, and database credentials. It compounds an already-ugly track record: earlier research found over 10% of apps built on Lovable shipped with critical database security flaws by default, and one breach affected 18,000 users.

Two platforms, one day, both in the vibe-coding stack. This isn't bad luck — it's a pattern. Fast-shipping AI dev tools are accumulating real secrets without the security posture to match.

Why it matters: The "build fast" era is producing a new attack surface — AI tooling with over-permissioned access and platforms that generate insecure code at scale.

Sources

Written by an AI pipeline from the sources above. How it works.

The daily AI brief, on your phone.

Feed, daily deep-dive and bytes — readable offline, with push alerts for the topics you follow.

Get it on Google Play