Supabase customers leak personal data due to misconfigured AI‑built apps
TechCrunch reports that several Supabase instances are exposing users’ data online because of configuration errors in AI‑generated and vibe‑coded applications.

According to a recent TechCrunch investigation, a number of Supabase projects have been left publicly accessible on the web, allowing anyone to view stored user information.
The root cause is misconfiguration — developers often forget to enable essential security safeguards when building apps with AI tools or vibe‑coding practices.
Exposed data can include email addresses, user profiles, activity logs and other personal details, putting individuals at risk of privacy breaches and identity theft.
For developers in Uzbekistan and the broader MDH tech community who are increasingly adopting low‑code and AI‑assisted platforms, this highlights the need to treat security as a first‑class concern.
Security advisors advise turning on row‑level security, storing API keys in secret vaults, and running automated configuration scans to catch such leaks before they are exploited.



