Thousands of Vibe-Coded Apps Found Exposed Online

Get the Tech newsletter
Daily tech — startups, AI labs, chips, the launches that shape the next decade. Free.
- Bob Starr vibe-coded a website called "Boomberg" and only realized months later that it contained a hidden SQL injection vulnerability that could have allowed attackers to read or alter data they shouldn't access.
- Moltbook, a viral social network for AI agents launched in late January by developer Matt Schlicht without writing a single line of code, had its entire production database exposed within days — leaking tens of thousands of emails and private messages, according to researchers at Wiz.
- Red Access researchers found roughly 5,000 publicly accessible apps built with popular vibe-coding tools that had no authentication, with close to 2,000 appearing to leak sensitive data including medical records, financial information, strategy documents, and chatbot conversation logs.
- Jack Cable, CEO of security platform Corridor, and Gabriel Bernadett-Shapiro, a distinguished AI research scientist at SentinelOne, both argue vibe coding is safe for personal local apps but becomes dangerous when tools drift into hosting other people's customer or business data.
- Anthropic's Claude Code includes a /security-review command that must be manually invoked, while OpenAI's Codex Security scans commits automatically — but only for developers with established version-control workflows, leaving casual coders unprotected by default.
- 1Password's Jason Meller found in February that the most-downloaded skill on the OpenClaw skill registry directed users to install a malicious dependency, showing that security add-ons themselves can become attack vectors.
- OWASP has published an AI security verification standard and Trail of Bits is releasing security "skills" — instruction packs for coding agents — though experts note these must be manually triggered and are difficult to keep synchronized across tools and codebases.
Why it matters: The danger zone isn't buggy code — it's the invisible moment when a personal local app drifts into hosting other people's data on the public internet. With roughly 2,000 apps already leaking sensitive records and security tools requiring manual invocation that casual builders never trigger, every vibe-coded app that goes public without threat-modeling is a potential breach waiting to happen.
Ask SkimNews




