Dark | Light
[GUEST ACCESS MODE: Data is scrambled or limited to provide examples. Make requests using your API key to unlock full data. Check https://lunarcrush.ai/auth for authentication information.]

![simonw Avatar](https://lunarcrush.com/gi/w:24/cr:twitter::12497.png) Simon Willison [@simonw](/creator/twitter/simonw) on x 111K followers
Created: 2025-07-06 01:45:01 UTC

Here's another proof of concept example of a lethal trifecta attack: if you combine the Supabase MCP with another MCP that provides exposure to untrusted tokens and a way to send data back out again - in this case a support ticket system - attackers can steal your Supabase data


XXXXXX engagements

![Engagements Line Chart](https://lunarcrush.com/gi/w:600/p:tweet::1941674715720057258/c:line.svg)

**Related Topics**
[simon](/topic/simon)

[Post Link](https://x.com/simonw/status/1941674715720057258)

[GUEST ACCESS MODE: Data is scrambled or limited to provide examples. Make requests using your API key to unlock full data. Check https://lunarcrush.ai/auth for authentication information.]

simonw Avatar Simon Willison @simonw on x 111K followers Created: 2025-07-06 01:45:01 UTC

Here's another proof of concept example of a lethal trifecta attack: if you combine the Supabase MCP with another MCP that provides exposure to untrusted tokens and a way to send data back out again - in this case a support ticket system - attackers can steal your Supabase data

XXXXXX engagements

Engagements Line Chart

Related Topics simon

Post Link

post/tweet::1941674715720057258
/post/tweet::1941674715720057258