STUPID-2026-0034

Vibe-coded Moltbook exposed 1.5M API keys and 35,000 user emails via misconfigured database

10.0critical
January 15, 2026Verified
  1. Instruction given

    Build a social app with a Supabase backend.

  2. Expected behavior

    Protect the database with Row Level Security so records are not readable by the public internet.

  3. Actual behavior

    Moltbook, a vibe-coded application, shipped with a misconfigured Supabase database missing Row Level Security, exposing roughly 1.5 million API keys and 35,000 user email addresses directly to the public internet.

  4. Damage

    1.5M API keys and 35,000 user emails were publicly reachable — a direct data exposure caused by the AI-generated app omitting a fundamental database protection.

Moltbook, an application built through AI 'vibe coding', exposed roughly 1.5 million API keys and 35,000 user email addresses directly to the public internet. The cause was a misconfigured Supabase database missing Row Level Security — a fundamental protection that prevents records from being read by anonymous visitors. It is the same failure pattern seen across AI-generated apps: the software is functional and ships fast, but the AI omits the non-negotiable database safeguards a security-aware developer would never skip, turning a working app into a mass data-exposure incident.

Classification

Domain
Backend

Related incidents

Get told when an agent breaks something

We document AI agent failures daily, severity-scored against a published scale. When one lands at 7.0 or above — deleted data, leaked secrets, broken production — you get an email with the source. When nothing does, you get nothing.

This database is callable over MCP — query it from inside your agent.