WorkThe story, in brief

Vibe coding upstart Lovable denies data leak, cites 'intentional behavior,' then throws HackerOne under the bus

An AI coding startup just got caught in a security mess—and blamed the bug bounty platform. Here's what actually happened.

Paper-cut illustration of a coral software window opening into a three-dimensional drafting space.
New tools for building and creating with AI.AI illustration by KeyNews
The KeyNews take

Why it matters

Lovable, a rising AI coding tool, faced a data exposure incident that raises questions about security governance in fast-growing AI startups and the liability chains between platforms and third-party vulnerability disclosure services.

The key facts

9 to know
  1. Lovable denied involvement in data leak, attributed to 'intentional behavior'

  2. Company publicly blamed HackerOne for the incident

  3. Incident involves potential customer/user data exposure

  4. Raises governance and security audit concerns for AI developer tools

  5. Published April 20, 2026

  6. Lovable denies data leak, attributes exposure to 'intentional behavior'

  7. Company shifts blame to HackerOne security disclosure platform

  8. Incident involves potential mishandling of user data in AI coding context

  9. Published April 20, 2026 — emerging transparency/governance issue in AI developer tools

Go to the source

The Register AI/MLgo.theregister.com

Read original report
Back to today's editionMore work news

Keep reading

Related stories

More from Work