Play: 18,000 Users from College Student to Minors Caught in #lovable #vibecoding #vibehacking
Video

18,000 Users from College Student to Minors Caught in #lovable #vibecoding #vibehacking

6:16 • Published March 4, 2026 • Watch on YouTube ↗

A security researcher just found 16 vulnerabilities — 6 critical — in a Lovable-built EdTech app featured on their own Discover page. 18,000+ users exposed, including college students and minors. The core bug? AI-generated authentication logic that was literally inverted — blocking logged-in users while granting full access to strangers. This is “vibe hacking” — exploiting AI-generated code that was never properly reviewed. And it’s about to become a much bigger problem. In this video I break down exactly what happened with the Lovable exploit, why AI-generated code has a systemic security problem (with data from CodeRabbit, Veracode, and Escape.tech), how vibe hacking is already hitting open source infrastructure like cURL and Tailwind CSS, and what you can do about it right now — using the same AI that wrote your code to ruthlessly audit it before you ship.

THE “BRUTAL AUDIT” PROMPT After you vibe-code your app, paste your code back into Claude/ChatGPT/Cursor and use this: “Now be a brutal security reviewer. Assume this code was written by a careless junior developer. Find every vulnerability. Check for broken access controls, exposed API keys, missing authentication, insecure data handling, SQL injection, XSS, and logic errors in permission flows. Try to break this. Attack it. Rip it apart. Show me exactly how an attacker would exploit each weakness, and tell me how to fix it.” It’s not a full pentest. But it catches the basics — and the basics are what took down that Lovable app.

SOURCES Lovable Breach: → The Register (Feb 27, 2026) — AI-built app on Lovable exposed 18K users https://www.theregister.com/2026/02/27/lovable_app_vulnerabilities/ → TechRadar (Mar 2, 2026) — Vibe coding service Lovable accused of hosting malware-ridden apps https://www.techradar.com/pro/security/vibe-coding-service-lovable-accused-of-hosting-malware-ridden-apps-exposing-thousands-of-users-it-says-they-should-take-more-care AI Code Quality: → CodeRabbit (Dec 17, 2025) — State of AI vs Human Code Generation report (470 GitHub PRs) https://www.coderabbit.ai/blog/state-of-ai-vs-human-code-generation-report → Escape.tech (Oct 29, 2025) — 2,000+ Vulnerabilities in Vibe-Coded Apps https://escape.tech/blog/methodology-how-we-discovered-vulnerabilities-apps-built-with-vibe-coding/ Vibe Coding Scale: → TechCrunch (Mar 2025) — 25% of YC Winter 2025 startups have 95% AI-generated codebases → Microsoft / Replit Case Study — 75% of Replit enterprise users are not software engineers https://www.microsoft.com/en/customers/story/26105-replit-azure-openai-in-foundry-models → Growth Unhinged (Mar 19, 2025) — Inside Replit’s path to $100M ARR https://www.growthunhinged.com/p/replit-growth-journey Open Source Impact: → BleepingComputer (Jan 28, 2026) — cURL ending bug bounty after flood of AI slop https://www.bleepingcomputer.com/news/security/curl-ending-bug-bounty-program-after-flood-of-ai-slop-reports/ → The New Stack (Feb 15, 2026) — Daniel Stenberg at FOSDEM 2026: AI slop is DDoSing open source https://thenewstack.io/curls-daniel-stenberg-ai-is-ddosing-open-source-and-fixing-its-bugs/ → DEV Community (Jan 8, 2026) — Tailwind CSS lays off 75% of engineering team https://dev.to/kniraj/tailwind-css-lays-off-75-of-engineering-team-as-ai-tools-disrupt-revenue-model-1l3d → Socket.dev — Tailwind CSS layoffs as LLMs reshape OSS business https://socket.dev/blog/tailwind-css-announces-layoffs Broader Threat Landscape: → Dark Reading (Aug 2025) — Proofpoint: tens of thousands of malicious Lovable URLs https://www.darkreading.com/cyberattacks-data-breaches/cybercriminals-abuse-vibe-coding-service-malicious-sites → BleepingComputer (Jan 7, 2026) — Hackers want AI: vibe hacking & HackGPT https://www.bleepingcomputer.com/news/security/in-2026-hackers-want-ai-threat-intel-on-vibe-hacking-and-hackgpt/ → The New Stack (Jan 20, 2026) — Vibe coding could cause catastrophic “explosions” in 2026 https://thenewstack.io/vibe-coding-could-cause-catastrophic-explosions-in-2026/

ZORZ Website → https://www.zorz.com LinkedIn → https://www.linkedin.com/in/keithposehn 💬 Have you shipped vibe code without a security review? No judgment — drop a comment. 🎬 Want to see me vibe-hack a Lovable app live? Let me know and that might be the next video. #vibecoding #vibehacking #lovable #aisecurity #cybersecurity #viberecoding #cursor #claude #aicode #softwaresecurity

← Back to all videos