Supabase Leaks and the Codebreaking Milestone
September 25, 2026

Supabase Leaks and the Codebreaking Milestone

Vibe-coded apps are leaking real people's data, and nobody's shocked enough

TechCrunch reported this week that some Supabase customers are publicly exposing large amounts of user data to the open web. Supabase is the backend-as-a-service layer that a huge share of AI-assisted and vibe-coded apps are built on, and the pattern is depressingly familiar: someone spins up a database quickly, ships fast, and never locks down the default access rules. The AI wrote working code. Nobody checked whether 'working' also meant 'secure.'

This isn't really a Supabase problem, it's a workflow problem. The entire pitch of vibe coding is that anyone can describe an app and get a working product in hours instead of months. That promise is real. What often gets skipped is the boring, unglamorous second half of the job: setting row-level security, auditing who can query what, and deciding what happens after launch when the app is actually handling customer data. We've made this argument before when we compared ViibeStack to Lovable on who runs the app after launch, and this Supabase story is exactly the failure mode that question was warning about. Speed to a demo and safety in production are not the same milestone, and treating them as interchangeable is how you end up in a TechCrunch headline for the wrong reason.

If you're a business leader who greenlit a vibe-coded internal tool or customer portal because it was fast and cheap, this is your prompt to go check its permissions today, not next quarter. The tools that generate code well are not automatically the tools that govern it well, and the gap between those two things is where liability lives. We've written before about what happens when that bill comes due -- see our take on ungoverned vibe-coded software -- and it's worth pairing any AI app builder decision with a hard look at how the platform handles security by default rather than as an afterthought.

Astra and Opus finishing Turing's codebreaking work is a genuinely useful benchmark

The more optimistic story this week, also from TechCrunch, is that frontier models -- Astra and Opus -- have completed pieces of Alan Turing's unfinished World War II codebreaking work. Turing's original test was about whether a machine could convincingly imitate a human in conversation. This is a different, arguably more honest test: can a model do genuinely hard, structured intellectual work that stumped one of history's sharpest minds for decades, using only what's on the page.

I'd push back gently on any framing that treats this as proof AI has 'solved' reasoning. Codebreaking is a bounded, rule-governed problem with a checkable answer -- it's the kind of task frontier models tend to be good at precisely because success is unambiguous. Most business problems aren't like that. Deciding whether to trust a vendor, price a product, or handle a messy customer complaint doesn't have a cryptographic solution waiting to be found. Still, the underlying capability is worth taking seriously: models that can hold a large, structured problem in their heads long enough to finish decades-old unsolved work are going to be useful for the unglamorous structured reasoning tasks businesses actually have -- reconciling records, auditing contracts, tracing down where a process broke. That's closer to what we've flagged in the ongoing frontier model price war than to science fiction: the capability is arriving faster than most companies' processes for using it responsibly.

The through-line: capability is outrunning caution

Put these two stories side by side and you get the actual state of AI in 2026: models are quietly getting good enough to do real intellectual heavy lifting, while the apps built with AI's help are shipping with the digital equivalent of an unlocked front door. Neither of these is a reason to slow down. Both are a reason to stop treating security and governance as a step you'll get to later. If your team is building or buying AI-assisted software right now, the question isn't whether the model is impressive. It's whether anyone checked the permissions.

If you found out today that one of your own vibe-coded tools had its database sitting open to the public, would you actually know how to check -- or would you be finding out the same way these Supabase customers just did?

Sources

Like what you're reading?
Add ViibeStack as a preferred source and see more of our stories in Google News Top Stories.
Add to Google News preferred sources
← Back to News