WICCON 2026

WICCON 2026

Supabase Shenaningans: Extended Edition
2026-10-29 , Main Hall

In one week, Eden pentested two completely separate applications built on Supabase, and both had Row-Level Security disabled. This talk walks through both engagements, the surprising ways developers misunderstand Supabase's security model, and why this vulnerability class keeps appearing even when the documentation warns you plainly. If you've ever shipped a Supabase app and didn't think twice about RLS, this one's for you.


This talk covers two real-world penetration testing engagements conducted within the same week, both targeting applications built on Supabase. The findings were independently discovered, disclosed responsibly, and are now public on skelli.win.

The talk covers how Supabase's permissive defaults work and why they exist, the architectural mistake of rolling custom auth instead of using Supabase Auth, common RLS policy gaps, remediation patterns for Supabase developers, and what good responsible disclosure looks like from both sides.
The intended audience is anyone who builds with or recommends modern BaaS platforms, and anyone interested in how subtle architectural decisions create severe vulnerabilities. Technical enough for practitioners, accessible enough for developers just starting to think about security.

Eden Stroet is a security researcher and SOC analyst at Hadrian Security in Amsterdam, where they focus on vulnerability research, automated scanning, and pentesting. They are a volunteer with the Dutch Institute for Vulnerability Disclosure (DIVD) and an active bug bounty hunter on HackerOne and Intigriti. Eden runs two online cyber security communities called Digital Overdose and Hard Way Hacking and Coding. When they're not hacking, they're on an aerial hoop or playing videogames with friends.