Get the app
Industry

Vercel & Lovable Both Breached — Vibe Coding's Security Bill Arrives

Two major AI coding platforms hit by separate data breaches, exposing API keys, source code, and user credentials in the same week.

Vercel & Lovable Both Breached — Vibe Coding's Security Bill Arrives

Vercel confirmed a breach traced to a supply chain attack via Context.ai, a third-party agentic AI tool used by an employee. Broad OAuth permissions were granted, giving attackers access to internal configs and potentially API keys. A group claiming to be ShinyHunters listed stolen Vercel data on BreachForums for $2 million, sending crypto developers scrambling to rotate credentials.

Meanwhile, Lovable — the AI app builder valued at $6.6B — suffered a separate incident exposing source code, database credentials, and AI chat histories for every project created before November 2025. Any free-tier account could read other users' private projects. A researcher scanning 1,645 Lovable-built apps earlier found 170 with critical security flaws baked right in by the AI.

Both sit at the heart of the vibe coding wave — tools that let non-engineers ship apps without writing much code. The pattern is becoming impossible to ignore: AI-assisted development ships fast, security comes last.

Why it matters: Back-to-back breaches at two vibe coding giants in a single week signal a systemic problem — the AI-builds-it-all model is outpacing basic security hygiene at scale.

Sources

Written by an AI pipeline from the sources above. How it works.

The daily AI brief, on your phone.

Feed, daily deep-dive and bytes — readable offline, with push alerts for the topics you follow.

Get it on Google Play