top of page
OutSystems-business-transformation-with-gen-ai-ad-300x600.jpg
OutSystems-business-transformation-with-gen-ai-ad-728x90.jpg
TechNewsHub_Strip_v1.jpg

LATEST NEWS

Leaked source code confirms Suno AI scraped millions of songs from YouTube, Deezer, and Genius

  • Marijan Hassan - Tech Journalist
  • 2 days ago
  • 2 min read

A security breach at generative music pioneer Suno AI has exposed internal source code explicitly detailing the mass scraping of major audio and lyric platforms. Leaked internal source code and database logs obtained by a hacker using the alias "ellie.191" provide the first concrete evidence of Suno's aggressive data harvesting techniques. The repository explicitly lists streaming networks, lyrics archives, and stock media giants as the foundational pillars used to train its viral music generation engine.


Editorial credit: Robert Way / Shutterstock
Editorial credit: Robert Way / Shutterstock

The technical blueprints, verified and first reported by investigative media outlet 404 Media, reveal a highly systemic data operation running throughout 2023 and 2024. Internal developer comments scattered across the codebase detail pipelines explicitly built to target major corporate ecosystems. Most notably, a directory titled “youtube_music” recorded the direct ingestion of 2,013,545 distinct music clips.


The files also document the systematic extraction of 12,287 hours of streaming audio from Deezer, 17,615 hours of musical metadata from the crowdsourced lyric repository Genius, and over 62,000 hours of audio files pulled from the stock library Pond5.


Bypassing Security to Isolate Human Stems

The technical disclosures also lay bare the tactical workarounds Suno deployed to optimize its models. The code reveals that the startup utilized residential proxy networks from proxy provider Bright Data to systematically circumvent YouTube’s automated anti-scraping firewalls and rate limits.


Furthermore, scripts show developers deliberately targeting isolated a cappella tracks across the web, explicitly trying to strip away background instrumentation so the neural network could train on clean, high-fidelity human vocal stems.


The breach concurrently exposed a vulnerability in Suno's commercial systems, exposing customer email addresses, phone numbers, and partial Stripe billing tokens. Suno downplayed the event, claiming it occurred in November 2025 and only affected "outdated, deprecated source code" while compromising no sensitive consumer data.


Upending the Fair Use Legal Battle

The real-world fallout of this leak is poised to be felt inside federal courtrooms. The Recording Industry Association of America (RIAA), alongside industry titans Universal Music Group and Sony Music, are embroiled in active copyright litigation against Suno. The labels have long argued that Suno built its business through illicit "stream ripping" - a practice that explicitly violates the anti-circumvention provisions of the Digital Millennium Copyright Act (DMCA).


Suno’s baseline legal defense rests entirely on the fair use doctrine, publicly asserting that its models are trained on publicly available internet files while respecting paywalls. However, because platforms like Deezer require active premium authentication and paid tiers to access their catalogs, the leaked scraping commands threaten to dismantle Suno's fair use defense entirely.


While Warner Music Group chose to settle its corporate dispute out of court to collaborate with Suno, these concrete technical logs hand the remaining litigants an incredibly powerful weapon to prove willful copyright infringement.

 
 
wasabi.png
Gamma_300x600.jpg
paypal.png
bottom of page