LOADING THE FEED ▮
NICHE OF ONE
--:--
← The Feed

The Suno Hack Didn't Reveal a Secret. It Revealed a Receipt.

/A breach of Suno's source code confirms what musicians have suspected for two years: the AI music generator scraped YouTube, Deezer, Genius, and more at industrial scale. Vivian on why "outdated code" isn't the alibi Suno wants it to be.

post to X email it
Halftone manga-style illustration of an old computer terminal and a printer on a desk, a long blank paper tape unspooling from the printer and coiling across the surface beside a tape reel and stacked boxes.
// the everything pass All-Access The whole catalog, the members vault, and the back room where the operators talk shop. $37/yr →

Somebody broke into Suno’s house and came out holding the receipts. Not user passwords, not credit card numbers, though those were in the pile too. The thing that matters is the source code, and the source code does not lie the way a spokesperson does.

TL;DR: A hacker handed 404 Media a cache of Suno’s internal code, and buried in it was the company’s actual data pipeline: YouTube Music, Deezer, Genius, Pond5, Jamendo, Freesound, IMSLP, MuseScore, podcast RSS feeds, all funneled in at a scale measured in tens of thousands of hours per source. Suno has spent two years telling courts and journalists it trained on “publicly available” files. The code doesn’t say public. It says scraped, and it names exactly where from.

Suno’s official line, when 404 Media came calling, was that the incident “primarily involved outdated source code that is no longer in use at Suno.” That’s the kind of sentence a lawyer writes for you when the truth is inconvenient but not, strictly, deniable. Nobody said the code was fake. Nobody said the numbers were wrong. They said it’s old news, which is a different thing than saying it isn’t true.

Say it out loud. Go on. Primarily involved outdated source code that is no longer in use.

Primarily. That word is load-bearing and it is doing the work of about four lawyers.

I have written copy for a live read my whole career, so I know exactly what that sentence is built to do. It is written to be repeated accurately by a journalist and understood incorrectly by everybody else.

The breach traces back further than the coverage says

The breach itself traces back further than most people covering it seem to realize. It started in November 2025, when the Shai-Hulud worm chewed through an employee’s npm credentials in a supply-chain attack that had nothing to do with music and everything to do with how brittle modern software dependencies are. Suno says it caught the intrusion and shut it down fast. Maybe so. But “fast” doesn’t undo the fact that whatever left the building during that window eventually landed with a hacker willing to hand it to a reporter, and what landed was the plumbing.

A lot of the coverage garbled these numbers into a disagreement between analysts, and they were never that. Every figure comes from one place, the internal file comments 404 Media reviewed, and they are separate buckets rather than competing estimates of the same bucket: 113,879 hours of YouTube Music, another 152,162 hours of tagged YouTube tracks, 62,117 hours from Pond5, 17,615 in a set labeled genius_hq, 12,287 from Deezer, and documented plans to pull roughly a million hours of podcast audio through RSS feeds. Stack them instead of arguing about them and the shape is plain: this was ingestion at industrial scale, across essentially every platform an actual human being might use to listen to music, including the ones that pay rightsholders for the privilege.

Does “outdated code” get them off the hook?

Here’s the thing about “we don’t use that code anymore.” It’s a timestamp. If the pipeline described in the leak trained the models currently generating songs on suno.com, then whether the code itself is still running is irrelevant. The training already happened. The weights already learned whatever they learned from those YouTube rips and Genius lyric scrapes. You can retire the scraper and keep the model, the way you can burn the blueprint and keep the house.

And that’s the part the RIAA, Universal, and Sony have presumably already circled in red ink. Their lawsuits against Suno allege exactly this kind of wholesale copying, and until now the company’s public posture has leaned on a fair-use argument dressed up in “publicly available” language vague enough to cover both a Creative Commons archive and a straight rip of a Drake track. The leak doesn’t settle the fair-use question in court. Courts move slowly and fair use is a genuinely unresolved legal frontier for generative AI, not a foregone conclusion either way. But it does something narrower and arguably nastier: it takes “we don’t know exactly where our training data came from” off the table as a posture, because now there’s a document trail naming the platforms and the hour counts.

Why should anyone outside a courtroom care?

Because most people encountering Suno right now aren’t lawyers. They’re hobbyists, indie musicians, people building a radio station’s worth of instrumental beds from a text prompt, and the pitch to all of them has been some version of “clean tool, no drama.” A generator you can point at a genre and walk away from without wondering whose Tuesday-afternoon YouTube upload got chopped into training data along the way.

That pitch gets harder to make with a straight face once the plumbing is public. Not because using the tool is now illegal, it isn’t, and the legal exposure here sits with Suno as a company, not with someone generating a backing track. But the comfortable fiction that this was all trained on some tidy licensed corpus is gone. It was trained on the open internet, aggressively, including from platforms whose entire business model is paying artists for exactly the content Suno’s pipeline apparently helped itself to.

Nothing happens fast

Nothing fast. Litigation like this runs on years, not news cycles, and a leak is evidence, not a verdict. But leaks have a way of reshaping what plaintiffs’ attorneys ask for in discovery, and a spokesperson’s “outdated and no longer used” is going to look thin the first time it’s read aloud in a deposition next to a hard number like 113,879 hours.

The music industry has spent two years arguing in the abstract about what these models learned and how. This is the first time the argument came with an itemized invoice attached.

Frequently asked questions

Was any user data exposed in the Suno hack?

Reports on the leak note that a spokesperson for Suno said no payment data was compromised, though the same breach reportedly exposed user account information alongside the source code. The company’s public statements have focused mostly on disputing the significance of the exposed training pipeline rather than the user-data question.

Is Suno currently being sued over this?

Yes, separately from the hack. The Recording Industry Association of America, along with Universal Music Group and Sony Music Entertainment, have ongoing lawsuits against Suno alleging copyright infringement in how its models were trained. The leaked code doesn’t create those lawsuits, but multiple outlets reported it lines up closely with what the plaintiffs have already alleged.

// comments
Full search on OneSearch: the network, the ring, and the open web →esc closes · ↑↓ move · ↵ opens