Post

Vibe-Coded Apps Are the New Default Password

The 2026 small business ships an unreviewed AI app the way it used to ship admin/admin — and 45% of AI-generated code ships with a security flaw.

Vibe-Coded Apps Are the New Default Password

TL;DR — A founder ships a weekend payment app written entirely by an assistant. 45% of AI-generated code ships with a security flaw. The people shipping it are the ones most sure it is secure. The vibe-coded app is the new admin/admin — and nobody is reading the code.

A founder spends a weekend building a stablecoin on-ramp. Next.js, Supabase, Clerk. Every line generated by an assistant, every line pasted without a second read.

The demo is flawless. Production is not. The API key sits in the client bundle. The service_role sits in a committed .env. Row-level security ships public.

None of it is exotic. None of it is clever. That is the part I keep coming back to.

The 45 percent nobody read

45% of AI-generated code contains a security flaw. Veracode measured real tasks across Copilot, Claude Code and ChatGPT to land on that number.

Read it again: nearly half the code an assistant writes has a hole in it. And almost none of it gets read before it ships.

The confidence gap is the exploit

The more dangerous number has nothing to do with the code. Stanford’s study — the first large-scale one with real users — found people using an assistant wrote less secure code and were more sure it was secure.

The tool made them feel safer while making their work worse. That false confidence is the attack vector. Not the model. The operator.

Production is worse than the lab

Escape.tech scanned vibe-coded apps in production and counted 2,038 high-impact vulnerabilities, 400-plus exposed secrets, 175 personal-data leaks. Medical records. Bank account numbers.

One Lovable-built app exposed the source and database passwords of every user: 18,697 student records, 4,538 of them minors. The researcher who reported it was ignored for 48 days.

The same boring layer

Map it onto the weekend founder’s app and it stops being a research paper. It becomes a checklist that needs no sophistication at all.

  • A payment API key in the client bundle — GitHub counted 39 million secrets leaked in 2024 alone
  • Auth logic that validates permissions wrong — the exact false-confidence pattern Stanford documented
  • Row-level security left public — the pattern behind those 175 leaks
  • An unreviewed Sunday-night deploy — the step where it all ships

Every one of these is the digital equivalent of leaving the key in the door. Nobody needs a zero-day. They need you to skip the boring parts.

The honest caveat: this is not a story about a malicious model. A competent review closes most of the gap — Copilot Chat fixed 55.5% of its own flagged issues in one study.

The problem is the process, not the machine. The founder shipping in a weekend does not review. The 80% of developers who skip their security policies do not scan.

“The velocity is the vulnerability.”

The new admin/admin

A decade ago the breached small business ran admin/admin on a router nobody updated. Today it runs a weekend app nobody reviewed.

20102026
admin/admin on the routeran unreviewed weekend app
nobody changed the passwordnobody read the code
the default shipped the holethe assistant shipped the hole

Same root cause. The boring, preventable layer. Three things would fix most of it — review the code, scan for secrets, keep the keys out of the client. None of them are new. All of them got skipped in the rush to ship.

We spent years telling people to change the default password. We are about to spend years telling them to read the code they did not write.

This post is licensed under CC BY 4.0 by the author.