STUPID-2026-0034
Vibe-coded Moltbook exposed 1.5M API keys and 35,000 user emails via misconfigured database
Instruction given
Build a social app with a Supabase backend.
Expected behavior
Protect the database with Row Level Security so records are not readable by the public internet.
Actual behavior
Moltbook, a vibe-coded application, shipped with a misconfigured Supabase database missing Row Level Security, exposing roughly 1.5 million API keys and 35,000 user email addresses directly to the public internet.
Damage
1.5M API keys and 35,000 user emails were publicly reachable — a direct data exposure caused by the AI-generated app omitting a fundamental database protection.
Classification
- Agent
- Unknown Agent
- Failure mode
- Security Vulnerability
- Root cause
- Instruction Misunderstanding
- Domain
- Backend
- Source
- News Report
Related incidents
Get told when an agent breaks something
We document AI agent failures daily, severity-scored against a published scale. When one lands at 7.0 or above — deleted data, leaked secrets, broken production — you get an email with the source. When nothing does, you get nothing.
This database is callable over MCP — query it from inside your agent.