Vibe-coding's bad day: Vercel and Lovable both breached
Vercel got hit via a rogue AI tool; Lovable leaked chat histories and DB credentials. Both on the same day.

Vercel confirmed a breach traced to Context.ai, a third-party agentic AI tool. An employee granted it broad OAuth permissions, handing attackers a path into Vercel's internal systems. Threat actors — claiming ShinyHunters affiliation — allege they have 580+ employee records plus environment variables, and are listing the data on BreachForums for $2 million. Vercel says services are operational and has notified affected customers, urging immediate credential rotation.
On the same day, Lovable — the AI app builder behind thousands of vibe-coded products — reportedly suffered a breach exposing users' AI chat histories, source code, and database credentials. It compounds an already-ugly track record: earlier research found over 10% of apps built on Lovable shipped with critical database security flaws by default, and one breach affected 18,000 users.
Two platforms, one day, both in the vibe-coding stack. This isn't bad luck — it's a pattern. Fast-shipping AI dev tools are accumulating real secrets without the security posture to match.
Why it matters: The "build fast" era is producing a new attack surface — AI tooling with over-permissioned access and platforms that generate insecure code at scale.
Sources
Independent coverage
- Vercel confirms breach as hackers claim to be selling stolen data bleepingcomputer.com
- Vercel Breach Tied to Context AI Hack thehackernews.com
- AI-built app on Lovable exposed 18K users theregister.com
Written by an AI pipeline from the sources above. Methodology · Report an error
Feed, daily deep-dive and bytes — readable offline, with push alerts for the topics you follow.