Get the app
Industry

Vercel & Lovable Both Breached — Vibe Coding's Security Bill Arrives

Two major AI coding platforms hit by separate data breaches, exposing API keys, source code, and user credentials in the same week.

Vercel & Lovable Both Breached — Vibe Coding's Security Bill Arrives

Vercel confirmed a breach traced to a supply chain attack via Context.ai, a third-party agentic AI tool used by an employee. Broad OAuth permissions were granted, giving attackers access to internal configs and potentially API keys. A group claiming to be ShinyHunters listed stolen Vercel data on BreachForums for $2 million, sending crypto developers scrambling to rotate credentials.

Meanwhile, Lovable — the AI app builder valued at $6.6B — suffered a separate incident exposing source code, database credentials, and AI chat histories for every project created before November 2025. Any free-tier account could read other users' private projects. A researcher scanning 1,645 Lovable-built apps earlier found 170 with critical security flaws baked right in by the AI.

Both sit at the heart of the vibe coding wave — tools that let non-engineers ship apps without writing much code. The pattern is becoming impossible to ignore: AI-assisted development ships fast, security comes last.

Why it matters: Back-to-back breaches at two vibe coding giants in a single week signal a systemic problem — the AI-builds-it-all model is outpacing basic security hygiene at scale.

Sources

Independent coverage

Written by an AI pipeline from the sources above. Methodology · Report an error

The daily AI brief, on your phone.

Feed, daily deep-dive and bytes — readable offline, with push alerts for the topics you follow.

Get it on Google Play