Vercel & Lovable Both Breached — Vibe Coding's Security Bill Arrives
Two major AI coding platforms hit by separate data breaches, exposing API keys, source code, and user credentials in the same week.

Vercel confirmed a breach traced to a supply chain attack via Context.ai, a third-party agentic AI tool used by an employee. Broad OAuth permissions were granted, giving attackers access to internal configs and potentially API keys. A group claiming to be ShinyHunters listed stolen Vercel data on BreachForums for $2 million, sending crypto developers scrambling to rotate credentials.
Meanwhile, Lovable — the AI app builder valued at $6.6B — suffered a separate incident exposing source code, database credentials, and AI chat histories for every project created before November 2025. Any free-tier account could read other users' private projects. A researcher scanning 1,645 Lovable-built apps earlier found 170 with critical security flaws baked right in by the AI.
Both sit at the heart of the vibe coding wave — tools that let non-engineers ship apps without writing much code. The pattern is becoming impossible to ignore: AI-assisted development ships fast, security comes last.
Why it matters: Back-to-back breaches at two vibe coding giants in a single week signal a systemic problem — the AI-builds-it-all model is outpacing basic security hygiene at scale.
Sources
Independent coverage
- Vercel confirms breach as hackers claim to be selling stolen data bleepingcomputer.com
- Vercel Breach Tied to Context AI Hack thehackernews.com
- Lovable platform faces scrutiny over app vulnerabilities and data leak scworld.com
Written by an AI pipeline from the sources above. Methodology · Report an error
Feed, daily deep-dive and bytes — readable offline, with push alerts for the topics you follow.