Replicate
Disclosed May 23, 20242 years agoUnverified
Tenant isolation flaw could expose all Replicate customers' AI prompts and results
Wiz researchers uploaded a malicious model to Replicate, gained root in their container and hijacked an authenticated Redis session shared across the platform, a path that could have exposed the private models, prompts and results of all customers. Replicate mitigated it after January 2024 disclosure and no customer data was compromised.
What is known
| People affected | Not stated in the sources we have |
|---|---|
| Disclosed | May 23, 2024 |
| Discovered | Jan 2024 |
| Attack | Exposed data |
| Data exposed | Prompts and chats, Training data |
| Sector | AI · US |
| Status | Unverified: not yet confirmed by an official notice, a filing or the organization |
Sources
| Source | |
|---|---|
| Wiz Research team discovers a major risk to AI systemswiz.io · News | News |
Notices filed
| Where | Filed | People |
|---|---|---|
| Researchtotal | May 23, 2024 |
History of this record
- 2026-09-25 · added · seed source
First seen 2026-09-25 (Research). Record counts are as reported. Not legal advice.