Vercel Got Hacked, Lovable Blamed Users, and Opus 4.7 Costs More Than You Think - This Week in AI episode artwork

EPISODE · Apr 22, 2026 · 35 MIN

Vercel Got Hacked, Lovable Blamed Users, and Opus 4.7 Costs More Than You Think - This Week in AI

from Agents Hour · host Mastra

A Vercel employee's Google Workspace was compromised via a third-party AI tool — attackers pivoted from the OAuth app into Vercel's environment variables, moving at a speed attributed to AI assistance.  René Brandel, founder of Casco (YC X25) and ex-founding member of AWS's Generative AI team, joins live to break down the attack chain and walk through the exact Google Workspace admin setting that could have prevented it. In a separate incident, every Lovable project created before November 2025 was readable by any free account, exposing database credentials and chat histories. Their response blamed unclear documentation rather than the underlying issue — and the contrast with Vercel's handling is stark.   Beyond security: Claude Opus 4.7 launched to mixed reactions. The benchmarks look good, but Simon Willison measured the new tokenizer at 1.46x the tokens of 4.6 on identical content — at unchanged prices, that's ~40% cost increase, and 3x for images. Anthropic's own docs said 1–1.35x. Independent measurements landed at 1.47x. Theo called the redesign "vibe-coded," and a locally run open-source Qwen model drew a better pelican SVG than Opus 4.7 at thinking level max.   Anthropic launched Claude Design, which lets you make prototypes, slides, and one-pagers by talking to Claude, powered by Opus 4.7. OpenAI shipped a major Agents SDK update with Codex memory and GPT-Rosalind for biomedical research. Cloudflare shipped Artifacts and memory primitives for agents, Factory AI raised $150M at $1.5B, Qwen 3.6-35B went Apache 2.0.   🎙️ GUEST - René Brandel — Founder & CEO, Casco (YC X25) Casco is your always-on security engineer: agentic red-teaming for AI agents, apps, APIs, and cloud infrastructure. https://casco.com https://x.com/renebrandel https://x.com/getcasco 🔗 LINKS Jensen Huang on Dwarkesh: https://x.com/scaling01/status/2044502834230579437 Allbirds pivots to AI: https://x.com/KobeissiLetter/status/2044409012989407252 Vercel security bulletin: https://x.com/vercel/status/2045865072074035664 Guillermo's incident post: https://x.com/rauchg/status/2045995362499076169 Vercel bill meme: https://x.com/avgdatabaseceo/status/2045907399035298250 Lovable mass data breach: https://x.com/weezerOSINT/status/2046170666131669027 Lovable's response: https://x.com/lovable/status/2046270357674299623 Claude Opus 4.7 launch: https://x.com/claudeai/status/2044785261393977612 Boris Cherny's Opus 4.7 tips: https://x.com/bcherny/status/2044847848035156457 Qwen beats Opus 4.7 (Simon Willison): https://simonwillison.net/2026/Apr/16/qwen-beats-opus/ Opus 4.7 token count analysis: https://simonwillison.net/2026/Apr/20/claude-token-counts/ Tokenizer cross-check: https://www.claudecodecamp.com/p/i-measured-claude-4-7-s-new-tokenizer-here-s-what-it-costs-you Theo on Claude Code desktop: https://x.com/theo/status/2044680030706663726 Claude Design launch: https://x.com/claudeai/status/2045156267690213649 Claude Code desktop redesign: https://x.com/claudeai/status/2044131493966909862 Routines in Claude Code: https://x.com/claudeai/status/2044095086460309790 OpenAI Agents SDK update: https://x.com/stevendcoffey/status/2044465818239701041 Codex memory preview: https://openai.com/index/codex-for-almost-everything/ GPT-Rosalind: https://x.com/openai/status/2044861690911850863 OpenAgents: https://x.com/nicoalbanese10/status/2043745569278251112 Gemini CLI subagents: https://x.com/geminicli/status/2044460062320554319 Cloudflare Artifacts: https://x.com/Cloudflare/status/2044766515065499957 Cloudflare memory for agents: https://x.com/mattzcarey/status/2044404529085526158 Salesforce Headless 360: https://x.com/benioff/status/2044981547267395620 Factory AI $150M Series C: https://x.com/factoryai/status/2044822365494993000 Qwen 3.6-35B-A3B: https://x.com/Alibaba_Qwen/status/2044768734234243427 runthisllm.com: https://runthisllm.com/ Caveman repo: https://github.com/JuliusBrussee/caveman   📚 MASTRA RESOURCES https://mastra.ai https://x.com/mastra_ai https://mastra.ai/community/discord https://github.com/mastra-ai https://mastra.ai/course https://mastra.ai/books/principles-of-building-ai-agents https://mastra.ai/books/patterns-of-building-ai-agents   ⏱️ CHAPTERS 00:00 — Cold open 00:30 — Welcome to Agents Hour 01:20 — WTF Is Going On — Jensen's "we are not a car" + Allbirds pivots to AI 04:37 — The Security Horror Show — Vercel breach, Lovable mass data leak, René's Google Workspace tip 14:37 — Claude Opus 4.7 reality check 22:33 — Claude ships — Design, Code desktop, Routines 25:05 — OpenAI ships — Agents SDK, Codex memory, GPT-Rosalind 26:44 — Quick Hits 33:43 — GitHub Star Party — caveman token compression

Episode metadata supplied by the publisher feed · Published Apr 22, 2026

Embed this episode

A Vercel employee's Google Workspace was compromised via a third-party AI tool — attackers pivoted from the OAuth app into Vercel's environment variables, moving at a speed attributed to AI assistance. René Brandel, founder of Casco (YC X25) and ex-founding member of AWS's Generative AI team, joins live to break down the attack chain and walk through the exact Google Workspace admin setting that could have prevented it. In a separate incident, every Lovable project created before November 2025 was readable by any free account, exposing database credentials and chat histories. Their response blamed unclear documentation rather than the underlying issue — and the contrast with Vercel's handling is stark. Beyond security: Claude Opus 4.7 launched to mixed reactions. The benchmarks look good, but Simon Willison measured the new tokenizer at 1.46x the tokens of 4.6 on identical content — at unchanged prices, that's ~40% cost increase, and 3x for images. Anthropic's own docs said 1–1.35x. Independent measurements landed at 1.47x. Theo called the redesign "vibe-coded," and a locally run open-source Qwen model drew a better pelican SVG than Opus 4.7 at thinking level max. Anthropic launched Claude Design, which lets you make prototypes, slides, and one-pagers by talking to Claude, powered by Opus 4.7. OpenAI shipped a major Agents SDK update with Codex memory and GPT-Rosalind for biomedical research. Cloudflare shipped Artifacts and memory primitives for agents, Factory AI raised $150M at $1.5B, Qwen 3.6-35B went Apache 2.0. 🎙️ GUEST - René Brandel — Founder & CEO, Casco (YC X25)Casco is your always-on security engineer: agentic red-teaming for AI agents, apps, APIs, and cloud infrastructure.https://casco.comhttps://x.com/renebrandelhttps://x.com/getcasco 🔗 LINKSJensen Huang on Dwarkesh: https://x.com/scaling01/status/2044502834230579437Allbirds pivots to AI: https://x.com/KobeissiLetter/status/2044409012989407252Vercel security bulletin: https://x.com/vercel/status/2045865072074035664Guillermo's incident post: https://x.com/rauchg/status/2045995362499076169Vercel bill meme: https://x.com/avgdatabaseceo/status/2045907399035298250Lovable mass data breach: https://x.com/weezerOSINT/status/2046170666131669027Lovable's response: https://x.com/lovable/status/2046270357674299623Claude Opus 4.7 launch: https://x.com/claudeai/status/2044785261393977612Boris Cherny's Opus 4.7 tips: https://x.com/bcherny/status/2044847848035156457Qwen beats Opus 4.7 (Simon Willison): https://simonwillison.net/2026/Apr/16/qwen-beats-opus/Opus 4.7 token count analysis: https://simonwillison.net/2026/Apr/20/claude-token-counts/Tokenizer cross-check: https://www.claudecodecamp.com/p/i-measured-claude-4-7-s-new-tokenizer-here-s-what-it-costs-youTheo on Claude Code desktop: https://x.com/theo/status/2044680030706663726Claude Design launch: https://x.com/claudeai/status/2045156267690213649Claude Code desktop redesign: https://x.com/claudeai/status/2044131493966909862Routines in Claude Code: https://x.com/claudeai/status/2044095086460309790OpenAI Agents SDK update: https://x.com/stevendcoffey/status/2044465818239701041Codex memory preview: https://openai.com/index/codex-for-almost-everything/GPT-Rosalind: https://x.com/openai/status/2044861690911850863OpenAgents: https://x.com/nicoalbanese10/status/2043745569278251112Gemini CLI subagents: https://x.com/geminicli/status/2044460062320554319Cloudflare Artifacts: https://x.com/Cloudflare/status/2044766515065499957Cloudflare memory for agents: https://x.com/mattzcarey/status/2044404529085526158Salesforce Headless 360: https://x.com/benioff/status/2044981547267395620Factory AI $150M Series C: https://x.com/factoryai/status/2044822365494993000Qwen 3.6-35B-A3B: https://x.com/Alibaba_Qwen/status/2044768734234243427runthisllm.com: https://runthisllm.com/Caveman repo: https://github.com/JuliusBrussee/caveman 📚 MASTRA RESOURCEShttps://mastra.aihttps://x.com/mastra_aihttps://mastra.ai/community/discordhttps://githu

Distinct summary based on available episode metadata or transcript content.

NOW PLAYING

Vercel Got Hacked, Lovable Blamed Users, and Opus 4.7 Costs More Than You Think - This Week in AI

0:00 35:28

No transcript for this episode yet

We transcribe on demand. Request one and we'll notify you when it's ready — usually under 10 minutes.

No similar episodes found.

No similar podcasts found.

Frequently Asked Questions

How long is this episode of Agents Hour?

This episode is 35 minutes long.

When was this Agents Hour episode published?

This episode was published on April 22, 2026.

Can I download this Agents Hour episode?

Yes. Use the download control on the episode player to save the publisher-provided media file.
URL copied to clipboard!