How Lovable attacks its own platform to find vulnerabilities.
Sophia Nabil Gustafsson
We hack ourselves for a living...
Inside Lovable, swarms of AI agents are hacking our own platform right now! They probe our systems like real attackers, looking for ways into places they shouldn’t be able to reach. But there’s one important rule: we don’t take an agent’s word for anything.
To prove a vulnerability exists, the agent has to capture a flag - a hidden string placed somewhere it should never have been able to access.
No flag, no proof.
This means our security team spends less time sorting through low-severity noise and more time fixing vulnerabilities that matter. Meanwhile, our offensive security researchers can move faster because the agents have already done much of the grunt work of finding potential ways in.
And no, the agents haven’t replaced our hackers ;) Human researchers still decide where to look, how to orchestrate the swarm, and which attack paths are worth pursuing.
If you’re curious about what happens when you let a swarm of AI agents loose on your own infrastructure, read the full story here