Vibe coding upstart Lovable denies data leak, cites 'intentional behavior,' then throws HackerOne under the bus
An AI coding startup just got caught in a security mess—and blamed the bug bounty platform. Here's what actually happened.

Why it matters
Lovable, a rising AI coding tool, faced a data exposure incident that raises questions about security governance in fast-growing AI startups and the liability chains between platforms and third-party vulnerability disclosure services.
The key facts
9 to knowLovable denied involvement in data leak, attributed to 'intentional behavior'
Company publicly blamed HackerOne for the incident
Incident involves potential customer/user data exposure
Raises governance and security audit concerns for AI developer tools
Published April 20, 2026
Lovable denies data leak, attributes exposure to 'intentional behavior'
Company shifts blame to HackerOne security disclosure platform
Incident involves potential mishandling of user data in AI coding context
Published April 20, 2026 — emerging transparency/governance issue in AI developer tools
Go to the source
The Register AI/MLgo.theregister.com