We independently scanned 500+ Lovable-deployed apps as part of a larger study of 1,764 vibe-coded apps. The RLS problem is systemic — not a one-off. X% of Lovable apps we tested had wide-open Supabase tables where the anon key could read/write everything. The $6.6B question isn't whether the product is useful, it's whether the security liability of millions of deployed apps becomes a material risk. We published the full breakdown: securityscanner.dev/reports/2026-q2
That valuation is more insane than most, I would’ve loved to hear the arguments for it, it was a given they would have to compete with the companies who provides them with the models, anyone who thought they would just leave that market alone is a damn fool (the vendor lock-ins are great too, add some hosting, domain selling, etc and you got free money).