Skip to content

Replicate

Disclosed May 23, 20242 years agoUnverified

Tenant isolation flaw could expose all Replicate customers' AI prompts and results

Wiz researchers uploaded a malicious model to Replicate, gained root in their container and hijacked an authenticated Redis session shared across the platform, a path that could have exposed the private models, prompts and results of all customers. Replicate mitigated it after January 2024 disclosure and no customer data was compromised.

What is known

People affectedNot stated in the sources we have
DisclosedMay 23, 2024
DiscoveredJan 2024
AttackExposed data
Data exposedPrompts and chats, Training data
SectorAI · US
StatusUnverified: not yet confirmed by an official notice, a filing or the organization

Sources

Notices filed

WhereFiledPeople
ResearchtotalMay 23, 2024
History of this record
  • 2026-09-25 · added · seed source

First seen 2026-09-25 (Research). Record counts are as reported. Not legal advice.

Everything about Replicate

New breaches by email

Wednesdays, only in weeks with newly disclosed breaches, the largest first.

Double opt-in. Unsubscribe any time.