Skip to content

WritingAugust 14, 2026

Klaviyo Leaked Passwords For 21 Months. Called It Nothing.

signaldigestai-fundingdata-privacysmb

Klaviyo's sign-up form leaked new customers' passwords to Facebook, Google, and five other ad trackers for at least 21 months — and never told anyone. That's this week's clearest data point on the gap between what a vendor ships and what it discloses.

This week the signal split into two stories that are actually one story. Capital kept pricing AI coding tools like the growth curve is real: Lovable doubled to a $13.3B valuation in eight months, Cognition is reportedly chasing $40B three months after its last raise, and DeepSeek's cost-per-token collapse gave every buyer a reason to shop providers. Production data backs some of that confidence — Vercel's own agent stack now merges a third of its weekly PRs without a human, and an OpenAI-backed roll-up's tax-prep agent is running at 98% accuracy on real returns. But the same week, a SaaS vendor sat on an undisclosed password leak for nearly two years, Anthropic's new watermark turned out to burden the honest user more than the person trying to evade it, and Washington's answer to the trust gap protects licensed security vendors, not the SMB actually getting breached. Same industry, same week, opposite trend lines.

flowchart TD A["Lovable: $6.6B → $13.3B<br/>in 8 months"] --> C{Capital chasing<br/>proven revenue} B["Cognition: $26B → $40B talks<br/>in 3 months"] --> C C --> D["DeepSeek: under 1% → 25%<br/>of gateway tokens in 3 months"] D --> E["Cost per token<br/>down 13.6% in July"] F["Vercel's ai-sdk-factory:<br/>25-35% of PRs, autonomous"] --> G{Capability<br/>is real} H["Thrive Holdings TaxAI:<br/>98% accuracy, 7,000+ returns"] --> G G -.->|but the trust layer<br/>hasn't caught up| I["Klaviyo: 21-month leak,<br/>never disclosed"] G -.-> J["Anthropic watermark:<br/>burdens the honest user,<br/>per Stratechery"] I --> K{{"Audit what you<br/>can't see"}} J --> K

Models + launches

DeepSeek didn't just gain share on Google. It lapped it. DeepSeek went from under 1% of Vercel AI Gateway's token volume in April to 25% in July, while Google fell from 24% to 10.7% over the same three months — DeepSeek V4 Flash alone now runs more tokens than all of Google combined. [1] Gateway-wide cost per token fell 13.6% in July as teams routed to cheaper open-weight models. If your stack is still hardcoded to one provider, that's a tax nobody else in your position is still paying.

Bar chart showing DeepSeek's share of Vercel AI Gateway token volume rising from under 1% to 25% while Google's share falls from 24% to 10.7% over three months Source: Vercel — DeepSeek overtakes Google on volume, cost per token falls

Anthropic started watermarking Claude's output — and the reason isn't misuse. Every model shipped after August 2 auto-watermarks text and files under the C2PA standard, and the mark survives copy-paste. [2] It exists to comply with the EU AI Act's Transparency Code, not to catch bad actors. Stratechery's read is blunter: the compliance-driven design is "a terrible idea, first and foremost for philosophical reasons," because it's built to flag the honest employee who pastes Claude output into a work doc, not the person deliberately trying to evade detection. [3]

Tooling shifts

Vercel's own AI SDK repo is now partly run by an agent, and the numbers are public. The ai-sdk-factory agent stack merges 25–35% of the repo's weekly PRs and closed over 75% of July's issues without a human writing the fix, cutting the open-issue count from 1,022 to 844 in six weeks. [4] That's the bar "let AI handle your maintenance backlog" gets measured against now — a shrinking backlog with a timestamp, not a demo.

SMB angles

A password leak ran for at least 21 months. Klaviyo says it affected fewer than 200 people — based only on the logs it kept. Independent researcher Sam Jadali found that Klaviyo's sign-up form leaked customer emails, passwords, company names, and phone numbers to Facebook, Google, HubSpot, Microsoft, LinkedIn, and X trackers embedded on the page, from at least February 2024 through November 2025. [5] Klaviyo never disclosed it publicly and won't say how far back its logs actually go, which makes "fewer than 200 people" a claim about its own visibility, not a ceiling. If you signed up for Klaviyo in that window, rotate the password today — and audit every embedded tracker on your own sign-up forms while you're at it.

The clearest AI-ROI proof this week wasn't a demo. It was a roll-up buying accounting firms. OpenAI-backed Thrive Holdings raised $2B at a $12B valuation to keep acquiring accounting and IT firms and bolting on AI — its TaxAI has processed 7,000+ real returns at 98% accuracy and cut prep time over 30%, while its IT arm's AI agent sped up help-desk resolution 36x. [6] If your rollout is still stuck at "cute demo, nobody lets it touch anything real," this is the boring back-office proof that the ROI story is realest where nobody's filming it.

Adjacent to watch

Two AI-coding valuations moved this week, and both moved on revenue, not hype. Lovable doubled from $6.6B to $13.3B in eight months on a $500M annualized-revenue run rate and 900 million monthly visitors. [7] Three months after its last raise at $26B, Cognition is reportedly already in talks for $40B off a $1B run rate. [8] Vibe-coding and coding-agent valuations are tracking real usage now, which is exactly why the price war between them, Codex, and Claude Code is going to get uglier before it gets cheaper for you.

Washington's "hack-back" headline undersells what actually shipped — and oversells what it does for you. The new policy lets vetted private firms run offensive cyber operations against foreign criminal groups, but only under joint DOJ/Homeland Security supervision, with a forfeitable $1M compliance escrow — it explicitly does not authorize a breached company retaliating on its own. [9] If you're the SMB that actually got hit, this protects the handful of licensed vendors who can now sell that service. It gives you no new legal path of your own.

This week's moveWhat happenedWhy it matters for your stack
Klaviyo password leakSign-up form leaked passwords to 7 ad trackers for at least 21 months, never disclosedIf you signed up in that window, rotate the password — and audit your own site's trackers
DeepSeek overtakes GoogleVercel Gateway share went from under 1% to 25% in 3 months; cost per token fell 13.6% in JulySingle-provider lock-in is a tax nobody else in your position still pays
Vercel's ai-sdk-factoryAutonomous agent stack merges 25-35% of weekly PRs, cut backlog from 1,022 to 844 issuesThe bar for "AI handles your maintenance backlog" just became production data, not a demo
Thrive Holdings raises $2BOpenAI-backed roll-up hits $12B valuation; TaxAI runs 7,000+ real returns at 98% accuracyThe AI-ROI story is realest in boring back-office work, not flashy demos
Lovable + Cognition fundingLovable: $6.6B → $13.3B in 8 months. Cognition: $26B → $40B talks in 3 monthsCoding-agent valuations now track revenue — the price war gets uglier, not cheaper, next
Anthropic watermarks ClaudeNew models auto-watermark text for EU compliance; Stratechery says it's trivially strippedThe honest employee pasting Claude output gets flagged. Nobody trying to evade it does
US "hack-back" policyLicensed firms can run DOJ/DHS-supervised offensive ops against foreign criminal groupsProtects specialist vendors, not the SMB that actually gets breached

Watermarks catch the employee who follows the rules. They don't catch the one who doesn't.

None of this means the capital chasing Lovable and Cognition is wrong, or that Vercel's agent stack and Thrive's TaxAI aren't real progress — they are, and the production numbers back it up. It means the trust side of the ledger didn't move at the same speed: a vendor sat on a leak for 21 months, a compliance watermark burdens the wrong person, and the one policy response this week protects licensed vendors instead of the businesses actually getting hit. I map exactly this kind of exposure — what a vendor can see, what it discloses, what an agent can touch — into every agentic automation engagement I scope, the same audit discipline that shaped how I rebuilt The Hub's stack. If a vendor's undisclosed behavior is starting to sound familiar, I went deep on a version of this exact problem a few weeks back.

What I'm watching: whether any regulator asks Klaviyo the question TechCrunch already did — how far back do the logs actually go — or whether "fewer than 200, based on what we kept" quietly becomes the final number.

Sources

[1] Vercel — DeepSeek overtakes Google on volume, cost per token falls — vercel.com

[2] TechCrunch — Anthropic says it will watermark text generated by its AI models — techcrunch.com

[3] Stratechery — Anthropic's Watermarking, How It (Probably) Works, Worse Than It Seems — stratechery.com

[4] Vercel — Building a software factory for the AI SDK — vercel.com

[5] TechCrunch — Signed up for Klaviyo? Dozens of advertisers may have seen your password — techcrunch.com

[6] TechCrunch — OpenAI-backed Thrive Holdings raises $2B to bring AI to the enterprise — techcrunch.com

[7] TechCrunch — Lovable confirms new $13.3B valuation, raises another $400M — techcrunch.com

[8] TechCrunch — AI coding startup Cognition reportedly already in talks to raise at $40B valuation — techcrunch.com

[9] TechCrunch — In a first, US will allow some private firms to carry out cyberattacks — techcrunch.com

The short version

  • Klaviyo's sign-up form leaked customer passwords to 7 ad trackers for at least 21 months (Feb 2024–Nov 2025) and was never publicly disclosed; Klaviyo claims fewer than 200 people were affected, based only on the logs it kept.
  • DeepSeek's share of Vercel AI Gateway token volume went from under 1% to 25% in three months while Google fell to 10.7% — gateway-wide cost per token dropped 13.6% in July.
  • Vercel's autonomous ai-sdk-factory now merges 25-35% of the AI SDK repo's weekly PRs and cut its issue backlog from 1,022 to 844 in six weeks.
  • OpenAI-backed Thrive Holdings raised $2B at a $12B valuation; its TaxAI processes 7,000+ real returns at 98% accuracy — the clearest AI-ROI proof of the week came from back-office work, not a demo.
  • Lovable ($6.6B → $13.3B in 8 months) and Cognition ($26B → $40B talks in 3 months) both moved on revenue growth, not hype.
  • Anthropic's new EU-compliance watermark on Claude output reliably flags the honest user who pastes it into a document — and is reportedly trivial for anyone actually trying to evade it.
  • A new US policy lets licensed private firms run government-supervised offensive cyber operations against foreign criminal groups — it protects specialist vendors, not the SMB that actually gets breached.

Drafted with Claude, reviewed and edited by Bryan before publish.