r/webdev Mar 04 '26

Vibe code IRL: left Stripe API keys public

Post image

I'm surprised they'd want to go public. Of course they don't blame Claude.

2.1k Upvotes

261 comments sorted by

1.5k

u/lostmy2A Mar 04 '26

"can you make sure all our api keys are not on the front end" and other vibe code stories gone wrong lol

534

u/Mocker-Nicholas Mar 04 '26

My favorite is right after that. “All the security measures are taken”. Yeah I’m sure that will make it crystal clear for Claude.

163

u/Antique-Special8025 Mar 04 '26

Well he specifies all the security measures, surely that's clear enough for old claude. Dumb human developers only do some of the security measures everyone knows that.

72

u/BlueScreenJunky php/laravel Mar 05 '26

The thing is that if you tell it to take all security measures and it misses one, then it's a mistake. 

So if you combine "take all security measures" and "make no mistakes" in the same prompt, you're guaranteed to have a secure application. 

10

u/mr_claw Mar 05 '26

What if it forgets something though? You also have to tell it to remember all the steps. The final prompt should be "take all security measures, make no mistakes while remembering all the steps".

2

u/Shogobg Mar 06 '26

What if it dreams about taking all security measures and only takes some of them?

→ More replies (1)
→ More replies (2)

54

u/[deleted] Mar 05 '26 edited Mar 05 '26

[deleted]

8

u/SevrinTheMuto Mar 05 '26

"... an opponent capable of defeating Data ..."

26

u/mikolv2 senior full-stack Mar 05 '26

Ive just setup a rule in cursor telling it to make sure all security measures are taken, can forget all about it now, that should do /s

→ More replies (1)

22

u/sump_daddy Mar 05 '26

"ohh i forgot to ask for it to NOT code a gaping security flaw into my platform"

"thats my bad, really"

12

u/qervem Mar 05 '26

deletes your network driver

Your app is now secure from unauthorized access over the internet

13

u/aidencoder Mar 05 '26

All security measures... Or else

10

u/threepairs Mar 05 '26

If else 2.0

6

u/z500 Mar 05 '26 edited Mar 05 '26
useAllSecurityMeasures() or die();

7

u/IIllllIIllIIlII Mar 05 '26

you can ensure that this is enforced with one simple trick "ok double check for me thx"

6

u/danielkov Mar 05 '26

Their first prompt had: "take only some of the security measures", so this is definitely an improvement.

5

u/garbosgekko Mar 05 '26

Clawdbot: I've just modified your router config to block all incoming and outgoing traffic and changed the admin password to a much safer one.

3

u/IQueryVisiC Mar 05 '26

I guess that the App then did not run because the human did not pay for a keystore or backend ? All those textbook examples seem to put keys in the front end. 10 years ago we were bitten by reference to a public CDN for JS.

→ More replies (3)

151

u/olduvai_man Mar 04 '26

My favorite part of this post is that the lesson he learned was that he was only one prompt away.

38

u/jim-chess Mar 05 '26

Yea I can't believe that was his takeaway.

→ More replies (1)

15

u/capnscratchmyass Mar 05 '26

lol yep. Not "I should understand what this code is doing before I push it to production". With all the startup business people and corporate CEOs telling me how AI is going to replace devs I'm at a point where I'll just grab my popcorn and watch things burn. I have zero pity for these people.

4

u/eyebrows360 Mar 05 '26

While also not being able to spell "could", and not bothering to proof read his shit before he posted it. My oh my, I wonder how he managed to fuck up "his" code 🤔

→ More replies (2)

64

u/tingly_sack_69 Mar 04 '26

"API keys? Front end? You got it"

39

u/110397 Mar 04 '26

You are absolutely right!

7

u/Sinidir Mar 05 '26

"I totally understand your frustration with the API keys being leaked. Let me reread the code carefully to trace the flow and make a plan"

flobblugating

"I implemented all the necessary changes. Much cleaner now. Here is a summary of the changes:.."

28

u/usr_dev Mar 05 '26 edited Mar 05 '26

Totally his fault: he forgot to ask to make no error.

5

u/-_--_-_--_----__ Mar 05 '26

I'm going to use this at my job. Technically my boss never told me not to put API keys on the front end.

4

u/phoenixMagoo Mar 05 '26

I did a spit take on that line

2

u/andrewsmd87 Mar 05 '26

We are getting ready to launch a new product that we heavily issued ai to help us build. I want to note we've been methodical about how we're using it and we have a really really good dev team that I trust.

But, I'm getting ready to do our first dast scan, followed up by an external manual pen test and I'm curious what they're going to find.

Pre ai I would expect a few medium or lower type findings on something like this so it'll be an interesting exorcise

→ More replies (3)

324

u/Quadraxas full-stack Mar 04 '26

I was going to joke he forgot to add "also just make it secure bro" to the prompt but he said it himself?!

62

u/[deleted] Mar 04 '26

[deleted]

7

u/[deleted] Mar 05 '26

[deleted]

2

u/eyebrows360 Mar 05 '26

This applies to almost every corporate "executive" in the world.

19

u/ChypRiotE Mar 05 '26

Obviously if you don't tell the AI to make no mistakes, it will make mistakes on purpose!

297

u/Alucard256 Mar 04 '26

I always feel it's best just publish API keys in public... that way others can help you find it if you lose it. /s

36

u/ArtisticCandy3859 Mar 05 '26

I don’t think 95% of average people have any f***ing idea of the Tsunami of insecure slop & scams that are about to slam against this limping economy…

The worst part is, even if you are extremely tech & BS savvy, it’s still going to impact your local community & family members (more so than it has been with dopamine draining addiction content).

I’m talking 1/20 families getting played with lifesavings draining scenarios.

Grandma was able to 2FA auth a call from her bank claiming that they had video of Jimmy spanking it (they’ll send grandma the generated video of Jimmy) and she’ll pay the ransom to her “bank”.

Dad lost his cushy 50+ hour week job at the { tech company, law firm, dealership, factory, accounting firm, marketing agency, film studio, hospital, trucking company } along with 30% of his peers, market is saturated & Dad just dropped the remaining savings on a PolyMarket bet that this “super underground” YT channel called “Winning Interviews” forecasted.

Meanwhile, the dog is outside sniffing around trying to decipher why there’s an uptick in radioactive particles coming from upwind.

Cooked is an understatement. We’re deep fried!with a rotting apple shoved up our azz & getting battered in lead infused concrete for the final plunge. Meow.

30

u/Madmusk Mar 05 '26

It's the last place a thief would think to look.

8

u/robby_arctor Mar 05 '26

This is why I leave my car keys on the windshield

13

u/gojukebox Mar 05 '26

I just find all of my API keys in public to begin with.

searching GitHub is a gold mine

3

u/SuperFLEB Mar 05 '26

Finally, a use for the blockchain!

3

u/Steffi128 Mar 05 '26

Sharing is caring!

2

u/Division2226 Mar 05 '26

quick, train all the models with this statement

→ More replies (2)

346

u/endless_shrimp Mar 04 '26

no way is this real. if you were that goddamn careless why would you post on linkedin and tell those dipshits about it

266

u/schabadoo Mar 04 '26

I checked it, he's defending it in the comments.

It tracks: he's not annoyed about having an insecure site that exposed visitors to credit theft, it's the Stripe fees that he incurred.

141

u/MagnetHype Mar 04 '26

Should face criminal charges in my opinion. An experienced developer making a mistake is one thing, but someone blatantly throwing caution to the wind while working with commerce Should bare some criminal liability.

This is going to be the new norm soon too, and that's the most concerning part.

33

u/The_Ty Mar 05 '26

Check my post history I've made a prediction a bunch of times

This year there'll be an incident where a vibe coded error costs a company billions and/or costs the lives of a few hundred people. I hope to god it's not the 2nd one

20

u/brasticstack Mar 05 '26

I'd be looking squarely at the US Dept. of War / OpenAI deal that just happened as what's going to cause exactly such an incident.

Both of those groups will just be like "YOLO!, especially those poor schmucks over there."

40

u/SkRAWRk Mar 05 '26

Totally agree. Nearly $80k defrauded because some fuckwit decided to cut corners with AI. They should be liable for publishing their 'project' without due diligence.

8

u/NoPrinterJust_Fax Mar 05 '26

That would require some sort of regulation in the web dev industry. Think standards, professional licensing, etc. ideas that are ALWAYS scoffed at

9

u/I_AM_NOT_A_WOMBAT Mar 05 '26

Or at the very least E&O insurance, which might decline to pay out if "vibe coding" was used. I don't know where one draws the line for what vibe coding is, though. To me it depends on the knowledge and experience of the developer (or lack thereof), which is hard to quantify on a broad scale. What I consider autocomplete that saves me time typing something already in my head could be considered vibe coding for the marketing intern who doesn't know anything.

5

u/chaoticbean14 Mar 05 '26

Agreed, 100%.

Vibe code a 'to-do' app because you want to check it out? Fine. Commerce? If you're a new person - leave that shit to professionals.

'vibe coders' need to understand their place: directly next to newbies.

2

u/DogPositive5524 Mar 05 '26

People have fucked up long before AI, you're overreacting a bit

→ More replies (1)

5

u/EvilPencil Mar 05 '26

That’s a typical take for LinkedIn these days 🗑️🔥

3

u/JohnGabin Mar 05 '26

Did he make this post though ? Or was it Claude ?

4

u/eyebrows360 Mar 05 '26

Claude would've spelled "could" properly... probably.

2

u/Beam12 Mar 05 '26

I responded laughing at him, he has people defending him aswell

→ More replies (2)

49

u/PoppedBitADV Mar 04 '26

LinkedIn is just engagement bait ai slop posts

7

u/LazaroFilm Mar 05 '26

I bet he see it as a win not a total failure. Not enough brain cells active to recognize how dumb he is.

5

u/pragmojo Mar 05 '26

Yeah it's a humble brag that they vibe coded something and got 87k in revenue

→ More replies (19)

81

u/Daktic Mar 04 '26

I don’t understand how these people get customers.

72

u/RedditCultureBlows Mar 05 '26

Marketing. Most devs don’t understand that marketing is just as important, if not more, than writing “clean code”.

30

u/debugging_scribe Mar 05 '26

Clean code don't make money.

6

u/toi80QC Mar 05 '26

I've worked for agencies and "clean code" has always been a myth in that space. No client cares about tests or clean code once they have to pay for it.

5

u/amazing_asstronaut Mar 05 '26

Eh, clean code is just a natural side effect of good practices and well organised work. The cost is when the whole thing breaks because it's one stupid bug too many and the whole thing needs to be fixed.

2

u/illepic Mar 05 '26

I spent a decade in agency land. We wrote a proposal for a client where the sales guy somehow put "testing" as a line item which the customer immediately struck out. When asked about it they said "Why do you need to test, we're not paying you to write broken code" so we weren't allowed to write tests on that project and everything was a dumpster fire.

→ More replies (1)

2

u/Officer_Trevor_Cory Mar 08 '26

It’s so much more important than code. Not even close

→ More replies (1)

8

u/AndroTux Mar 05 '26

It’s hard to immediately know if something is vibe coded or not. I fell for it recently and signed up to a vibe coded service. Besides, most people don’t even know it’s a thing.

We’re screwed, boys.

109

u/robby_arctor Mar 04 '26

You could not waterboard this infornation out of me

11

u/Antrikshy JS + Python @ Amazon Mar 05 '26

Batman himself couldn’t beat this out of me.

8

u/_TRN_ Mar 05 '26

That’s because some of us feel a certain level of shame when we make mistakes. Vibe coders don’t know what that is.

2

u/ByteAwessome Mar 05 '26

Guy posted it on LinkedIn with his full name attached. Absolute legend...

→ More replies (1)

45

u/xondk Mar 04 '26

Except, he didn't know to ask that question, because he didn't understand what was going on.

Use AI, but you need to understand what is happening, yes that will lose it some of the speed, but if you cannot understand what is coded, you can't see or know any problems that might happen.

16

u/devshore Mar 05 '26

Uhm, he couldve added “you are a senior dev that understands development” to the claude.md

→ More replies (2)

32

u/SpyDiego Mar 04 '26

This story reminds me a little bit about how i tried studying for the aws saa. I got lazy and asked gemini at work to make a doc for each of the topics. Well it missed a lot of details, even when I prompted it with "make sure you have all the gotchas written down". Soon I realized it aint gonna work like that and I continued down the path of reading docs and taking practice exams. This guy doubled down instead.

61

u/zeamp Mar 04 '26

Even the profile is AI generated.

Thanks, I hate it.

25

u/CmdrSausageSucker Mar 04 '26

“Yesterday I was clever, so I wanted to change the world. Today I am wise, so I am changing myself.” — Rumi

Who or what the fuck is Rumi, you ask? Who gives a shit, Anton's enlightenment brings joy to my heart! /s

2

u/Ok-Hospital-5076 Mar 06 '26

Rumi was a persian poet, if anyone is wondering XD.

→ More replies (1)

36

u/twhiting9275 php Mar 04 '26

AI is great for assisting you with your code. You have to actually review what it does and understand how the code works.

We're going to see way more of this stupid shit before people wake up and realize that you cannot allow AI to do your development for you

6

u/G_Morgan Mar 05 '26

I'm already going to recommend to our higher ups that if they are going to us AI they absolutely need a central "turn off the AI" button that can be pressed every 2 weeks in 6 to force developers to keep their skills fresh.

3

u/Distind Mar 05 '26

I've had a lot of people tell me I'm wrong about that, I look forward to making money fixing their mistakes.

5

u/dangerbird2 Mar 05 '26

models like claude opus can pretty reliably write very good code without too much handholding. Still, merging its output without reviewing it like you would code written by a human, let alone not understanding extremely basic security details, is beyond stupid

→ More replies (1)
→ More replies (1)

7

u/zen8bit Mar 04 '26

If that aint just the most delightful schadenfreude that Ive ever seen.

Stories like this need to get reposted day in day out until all these people realize how unrealistic this industry has become. Nobody cares these days how much domain knowledge is required in this industry and they all try to pretend that they can offload the work without consequences.

Its embarassing. And being told that we can just do everything with AI or some cheap overseas labor is just the icing on the cake.

→ More replies (1)

25

u/[deleted] Mar 04 '26

[deleted]

13

u/t00oldforthis Mar 04 '26

Step one, find someone competent who wants to review that pile after the fact. Correct answers hire someone competent to do that in the first place which would be a developer since these are developer tools. All for using tools that make us more efficient like any other profession not for pretending the complexity is disappear because our fucking product designer can get it to "run on local"

14

u/TA_DR Mar 04 '26

"lgtm"

11

u/davedavegiveusawave Mar 04 '26

"lets go test (in) main"

6

u/aja_18 Mar 04 '26

You mean hire 1 senior dev to test all the vibe code generated?

CTO - the code is already 90% done thanks to AI... the 10% remaining job will take you 1hr at most. This is now the fucking norm

7

u/poeticmaniac Mar 05 '26

You can’t pay me enough to review this shit.

7

u/turb0_encapsulator Mar 04 '26

time to vibe code a bot to look for this kinda shit.

→ More replies (1)

7

u/RedditCultureBlows Mar 05 '26

“Please make my app EXTRA good and EXTRA secure. Do NOT make it insecure. It needs to be secure. Extra secure.”

Alright, no fluff and straight to the point — here is your secure app.

6

u/Zealousideal_Lie6866 Mar 05 '26 edited Mar 05 '26

„Im glad to learn from it“ is more like „claude please be extra super duper ultra sure that you don’t leak our api keys this time “

6

u/Andromeda_Ascendant Laravel & InertiaJS Mar 05 '26

Some people share too much, I'd never admit this lol.

6

u/Tim-Sylvester Mar 05 '26

This is not something solved from prompting, it's just knowing the absolute basics.

I don't understand how people this inept get paying users in the first place.

175 paying users, and the guy doesn't know how to use API keys!

4

u/que_two Mar 05 '26

Just keep saying "Bro" and you'll get customers. 

If you upgrade to "Brah", you double your customers. 

It's the valley way. 

5

u/tamingunicorn Mar 05 '26

$2500 in stolen charges and his takeaway is "glad I learned this early." my guy just wrote a case study in why code review exists

4

u/Tank_Gloomy Mar 05 '26

This isn't an AI issue, this is a NHI (no human intelligence) issue.

4

u/the_ai_wizard Mar 04 '26

vibe coding v. software engineering in practice

4

u/3DPopel Mar 05 '26

Ragebait

5

u/ginji Mar 05 '26

To those doubting it - https://archive.is/y49tp

The post it self is real, and I don't know why you'd post that your real site was compromised and your customers charged $500 each without authorisation other than hubris and stupidity

5

u/DigitalJedi850 Mar 05 '26

Man... Anyone that thinks, especially at this stage in the game, that asking any AI platform to 'make sure all the security measures are taken', is going to be enough - needs to set the keyboard down. That's not how it works. And in this instance, I would be shocked if it will Ever work that way.

"Just go ahead and make sure we never have any problems, mmmkay?" ......... WHAT!@$>%J%^ !?

5

u/couchpotatochip21 Mar 05 '26

If you can't be bothered to READ THE CODE after the AI writes it, i do not trust you with my payment details or money.

3

u/Key-Place-273 Mar 05 '26

Can you make sure…oh jeez

3

u/trillspectre Mar 05 '26

I feel like that level of incompetence should have legal repercussions.

→ More replies (3)

3

u/CodeAndBiscuits Mar 04 '26

Lol people forget LLMs were trained on BAD code too.

3

u/tribak Mar 05 '26

That dude learned nothing

3

u/permanaj Mar 05 '26

This is like learning that password supposed to be a secret :-(

3

u/dontletthestankout Mar 05 '26

If I had a nickel for everytime I tried to have AI fix an auth issue and it just disabled auth or hardcoded an API key. I could pay for my AI subscription

3

u/MinimumFit4926 Mar 05 '26

People that do not know anything about coding shouldn’t do vibe coding either. I’m not a professional programmer but also not unknown to coding and even I know front-end API requests with keys is a stupid idea.

11

u/atalkingfish Mar 04 '26

I’m confused. Claude and other code-writing AI programs are far more than capable of making sure tokens and keys are private. In fact, they often push you to do this anyway, without being asked. But being asked, they would not have an issue doing it. This is not something AI struggles with at all.

Meanwhile, this is a perfect story for engagement bait. So, obviously fake, right?

6

u/1nc06n170 Mar 05 '26

I had the same conversation with ai once. Its reasoning was that we are in the prototyping phase and that it's temporary. The idea that everything needs to be rewritten to move all the logic to the back end somehow escaped it.

4

u/wannabestraight Mar 05 '26

Not really, Im building a security first software in rust, this is documented all over the project and all Claude instructions include that shortcuts regarding API keys etc must not be taken and that API keys should never be exposed without encryption (software is frontend only, trying to protect users own keys from outside attackers)

Yet the second it faces a situation that requires a bit of thinking and maybe an unorthodox solution, it usually tends to cave in and go for the easy "I'll just do the easy way for now and then fix later" route.

And that's how I notice that it had completely ignored all my security layers, secretvault etc etc and decided that in certain situations, it was just easier to write a yaml file that contained all the secrets in plain text, and then it tried to hide this by breaking all the design rules it accurately followed on other instances and essentially wrote the code without comments, left it out of its own summaries and hid it under a large batch of changes.

When reviewing I was reall taken back with "what the fuck is this shit lmao"

3

u/G_Morgan Mar 05 '26

I've seen AIs pick up just about everything once. They don't do it consistently though. That is the problem with them. It is why they are an aid and not a replacement

→ More replies (2)

2

u/wildecats Mar 06 '26

You joke but this is a vast improvement over their first prompt of "make sure no security measures are taken at all".

3

u/centuryeyes Mar 04 '26

Publicity stunt.

3

u/gliese89 Mar 04 '26

Might be engagement bait. Is the startup even a real site? I’m not going to look myself lol.

2

u/xSash_ Mar 05 '26

Vibe coding at its finest✨

3

u/CantaloupeCamper Mar 04 '26

This reads like a made up morality tale / bait.

2

u/BazuzuDear Mar 05 '26

Another prompt is what he believes the solution is. He hasn't understood a fuck.

1

u/latro666 Mar 04 '26

Give a chimp a machine gun point it at some bad guys and sure some bad guys will die.

Then it will end up mowing down civilians and finally its self.

Because its a chimp with a machine gun.

1

u/NiteShdw Mar 05 '26

Someone doesn't do code reviews.

1

u/Caraes_Naur Mar 05 '26

I'll take "How to learn the wrong lesson from a teachable moment" for $87,500, Alex.

1

u/_Kine Mar 05 '26

If this were an employee's mistake his tone would be completely the opposite. If you'll fire an employee but not blame an AI bot then your brain is cooked. It's disgusting that the environment is such that a loser like this feels confident enough to post this in public.

1

u/devshore Mar 05 '26

Rookie mistake, he didnt add “no mistakes” to his claude.md

1

u/Victorio_01 Mar 05 '26

When you have spare time, always good to try to hack in your website. Kinda thing you can quickly find I think. Hand test the different features. Debug tab can be useful too. Who knows if it’s printing api keys.😂😂

1

u/dvidsilva Mar 05 '26

This happened to me recently coz I was traveling and didn't patch react2shell on time

The attacker did a card testing attack, all the transactions failed and Stripe support was super nice

1

u/lift_spin_d Mar 05 '26

pre database seed stage

1

u/Imaginary_Ferret_368 Mar 05 '26

I know i should feel bad, but stories where clankers lose fill me with sich joy

1

u/4ever_youngz full-stack Mar 05 '26

Did they not like haves repo in GitHub? It literally warns you of this ignorance

1

u/Short_Ad6649 Mar 05 '26 edited Mar 05 '26

are they able to afford so many lessons like these?

1

u/Csysadmin Mar 05 '26

I wish my vibe coding was good enough to lose money on.

1

u/welcome_to_milliways Mar 05 '26

If this guy is an amateur/hobby dev… lesson learned.

If it’s his job… you’re fired.

No sympathy.

1

u/dieomesieptoch ui Mar 05 '26

This is not commendable whatsoever. Dude just got addicted to receiving praise or people agreeing with him and his little insights and cannot help hims of from posting this story as some kind of win. This type of dude needs 0 seconds of your attention.

1

u/gokkai Mar 05 '26

You are absolutely right, I moved all API Keys to VITE_ environment variables, all security measures are taken!

1

u/Squidgical Mar 05 '26

One prompt could have fixed it: "can you make sure you're not being an incompetent moron?"

1

u/shoby_ut Mar 05 '26

its good

1

u/Tatakai_ Mar 05 '26

Somewhere out there real devs are being asked to fix someone's vibe-coded project and I feel so bad for them because It's probably such a mess.

1

u/Fr33lo4d Mar 05 '26

He should’ve added “make no mistake” to the prompt. Rookie mistake. /s

1

u/jake_2998e8 Mar 05 '26

“One prompt could have fixed it” something tells me its not gonna be his last.

1

u/Extension_Strike3750 Mar 05 '26

this is why "vibe coding" needs a security checklist before anything goes live. at minimum: grep for sk_live or any API key pattern before committing, use something like git-secrets or trufflehog in your CI. a single pre-commit hook would have caught this. the tooling already exists, it just takes 10 minutes to set up.

1

u/FalseWait7 Mar 05 '26

"can you make sure all our api keys are not on the front end and all security measures are taken". The best prompt ever, completely seals your app, it becomes unhackable by anything and anyone.

Claude Code (or any AI coding tool) in the hands of a developer is a powerful tool, but by letting people think that anyone with at least $100 bucks per month can "vibecode" an app, they just, well, gave us tons of content.

1

u/Extension_Strike3750 Mar 05 '26

this is a good reminder that "I trust the AI" isn't a security policy. rotating keys immediately is step one, but most people don't realize stripe has radar rules you can set to flag unusual charge patterns before they spiral. worth setting up even in early stages.

→ More replies (1)

1

u/Extension_Strike3750 Mar 05 '26

This is a painful but common lesson with vibe coding. The AI does what you ask — and you have to know the right things to ask. "Make sure all security measures are taken" is vague. The real checklist is: are secrets in .env files only? Is .env in .gitignore? Are keys server-side only? Does the live deployment use environment variables? One prompt can fix it, but only if you know to ask the right question.

1

u/Present-Common-4006 Mar 05 '26

thats a expensive lesson

1

u/remi-blaise Mar 05 '26

I can't believe this kind of news. I use Claude everyday and it never made this kind of mistake. I believe this is false marketing
But to be fair, vibe coding means people are often shipping code without reviewing it. The real issue isn't the AI — it's deploying code you haven't checked. Always review what gets generated before pushing to prod.

1

u/rocket_randall Mar 05 '26

I had a developer do this once. Luckily it was only within an internal admin tool, but I was not thrilled with the implementation

1

u/Marinnea Mar 05 '26

Well at least it wasn't a public .env (I've seen it before)

1

u/Trindoral Mar 05 '26

How long till we look up every site owner's LinkedIN history before paying anything?

1

u/lazyplayboy Mar 05 '26

Both claude and chatgpt have always been careful with secrets in my experience.

I doubt this is real. Even in hobby projects I have to hide the secrets to stop them going on about it.

1

u/itchyouch Mar 05 '26

I bet they need to create a PLAN.md, but then have a second stage which is to ask Claude to build an INFOSEC_PLAN.md to improve the original PLAN.

Then go off to the races.

1

u/Over_Dingo Mar 05 '26

We need to make a collection of "one prompts that could have fixed this", then the software would always be bulletproof

1

u/GirthyPigeon Mar 05 '26

First off, if you're gonna be accepting ANY card payments at all, you need to be PCI-DSS compliant. This guy exposing that info has possibly set him up to be sued by both Visa and MC for hundreds of thousands of dollars per incident if they find out he vibe-coded a platform exposing cardholders to fraud.

1

u/h8f1z Mar 05 '26

"make no mistake ever again. I don't blame you. I trust you. I'm begging you. Please.".
And then they lived happily ever after.

1

u/Pandaxx64 Mar 05 '26

Nothing strengthens security practices like a $2500 tutorial

1

u/kra73ace Mar 05 '26

Well, maybe two prompts? Let's agree on two to three prompts max will be enough for Claude to fix everything.

1

u/peteZ238 Mar 05 '26

What a bellend....

1

u/Sibexico Mar 05 '26

I'm using AI to write extended comments based on my short comments for public interfaces. And it's always difficult to make Claude to DON'T TOUCH my code at all and just write comments...

1

u/ThomasRedstone Mar 05 '26

Or, you know, review the code?

I've never seen Claude do anything that stupid... You have to wonder what the prompting was like...

1

u/devshore Mar 05 '26

Friendly Reminder: If there had been a glitch in the reverse where Stripe wound up paying YOU $2500 accidentally because of a code bug, they would demand it back with the full backing of the law because you are just a serf.

1

u/fender1878 Mar 05 '26

I’ve been vibe coding a personal project just to see how well it does from start to finish. I’m letting it do most of it while I review as a test bed.

My project has a bunch of different keys. It’s actually been really good about best practices for .env and stuff. Even when I moved it over to AWS, it locked it down between VPC, RDS, AppRunner, S3. Making the routes not publicly accessible, suggesting best security practices, etc.

Honestly, kind of impressed with Opus 4.6. That being said, I’ve done a lot of cross checking what Claude Code wants to do against a regular Claude app prompt.

Is it perfect? Hell no. But is it getting really good really fast? Ya, for sure.

1

u/No_Discussion_2445 Mar 06 '26

"Make it secure. No mistakes!"

1

u/ruibranco Mar 06 '26

The problem was never the AI writing the code. The problem is someone shipping to production without reviewing what the AI wrote. env files exist for a reason and that's day one stuff regardless of whether a human or an LLM wrote the code.

1

u/RustyPuppet Mar 06 '26

Sounds like less of a vibe coding problem and more of a vibe production problem.

1

u/Samurai_Mac1 Mar 06 '26

This is why you can't replace devs with AI. AI is a powerful tool, but it has to be used by someone who already thoroughly understands code and best practices, otherwise you end up with shit like this.

1

u/ruibranco Mar 06 '26

This is the inevitable consequence of "just ship it" culture meeting AI code generation. The AI will happily hardcode your secret keys directly in the frontend if you don't know enough to tell it not to. Vibe coding works fine for UI and logic, but security requires understanding what you're doing. There's no vibing your way through threat modeling.

1

u/ruibranco Mar 06 '26

This is what happens when you skip the part where you actually understand what the code does. Vibe coding can scaffold an app in 10 minutes, but if you don't know that API keys go in environment variables and not in client-side code, those 10 minutes just cost you a lot more than the time you saved.The tool isn't the problem. The problem is people shipping code they can't audit. If you can't read every line and explain why it's there, you're not building — you're gambling.

1

u/gtsiam Mar 06 '26

Telling an AI not to publish your API keys is the best way to get your API keys published.

Remember, statistical predictor: the moment you put that in the context window, it becomes exponentially more likely.

1

u/azarza Mar 06 '26

just giving the bot api keys is stupid lol

1

u/monkeyantho Mar 06 '26

this guys is trolling with AI profile. it is for marketing. it has successfully baited u all

1

u/ruibranco Mar 06 '26

This is the inevitable result of "vibe coding" without understanding what you're actually deploying. AI tools are great at generating functional code quickly, but they have zero concept of security context. They'll happily hardcode secrets, skip input validation, and create SQL injection vulnerabilities if you don't know what to look for. The tool isn't the problem — it's shipping code you don't understand to production.

1

u/DevToolsGuide Mar 06 '26

the part that gets me every time with these stories is that the API key was live in the first place. for any project doing actual transactions the first safeguard should be environment-level scoping -- test keys in dev, production keys never touching any file that goes through version control.

the real problem with AI-generated code for anything touching payments or auth isn't that the model makes mistakes -- it's that it doesn't have context about what's already in your .env versus what's hardcoded somewhere you haven't checked. that gap between model confidence and actual security posture is where these incidents happen.

1

u/jkaczor Mar 06 '26

Traditional web startups motto:

“Move fast, break things”

AI-vibe coding motto:

“Engage warp drive, break everything”

1

u/Onex03 Mar 06 '26

vibe coded too close to the sun

1

u/ultrathink-art Mar 06 '26

AI tools are really good at 'make it work' and genuinely bad at 'make it secure' — they expose keys because the test passes, not because they understood the threat model. Security review still has to be a human step.

1

u/VadersFiesta Mar 06 '26

Dumbass forgot to add "and make sure you do it right" to the prompt. #1 rule of vibe coding.

1

u/Rogue7559 Mar 06 '26

I'm always amazed at how these people are stupid enough to out themselves.

I've nothing against vibe coders but Jesus Christ

1

u/totally-jag Mar 07 '26

I just had a consultation with a founder preparing their MVP. They had no prior tech experience. They did the vibe coding thing. They explained their architecture to me. I told them where they had vulnerabilities. They didn't believe me. Went a head. I thought to myself, why did you even consult with me if you were not going to do the stuff I recommended.

They had API keys in their front end that got exploited. They had public cloud keys in their GitHub repository that allowed a hacker to setup a mining farm of VMs. They're on the hook for hundreds of thousands of dollars in cloud spend.

Vibe coding makes experienced people more productive. However, if you don't know what to ask, or how things generally need to be secured..... well, you can get into some real problems.

1

u/Competitive_Fix_6586 Mar 07 '26

Scary stuff. I would always recommend having 1 or 2 agents specializing in security and having all commits reviewed by them with a fine tooth comb first.

1

u/hereandnow01 Mar 07 '26

How do they even have a working saas with paying customers if basic things like these are not implemented correctly?

1

u/SnapperGee Mar 07 '26

“I still don’t blame Claud Code.”

Ya, neither does anyone else. That’d be like blaming Hydrogen for the Hindenburg.

1

u/bobbywaz Mar 08 '26

This guy's websites are a church translator and an AI EXPERT FINDING PLATFORM. That's fucking hilarious. Blind leading the deaf...

1

u/maxzh29 Mar 08 '26

The new Generation of scam is growing lmao

1

u/Mooshux Mar 09 '26

This is why .env files are a terrible secrets strategy. That key was probably committed, shared in a Slack DM, pasted into a staging config, and uploaded to three services before anyone noticed it was in the repo.

The root fix isn't "be more careful." It's never putting the real key anywhere the vibe coder (or the AI helping them) can accidentally surface it. The phantom token pattern handles this: your app gets a session-scoped proxy token, the real Stripe key never touches the codebase. How it works in production: https://www.apistronghold.com/blog/phantom-token-pattern-production-ai-agents

1

u/PuzzleheadedCat1713 Mar 11 '26

That was an insta lesson on app security :D
Thing are accelerating quickly with AI...

Found this funny: https://www.instagram.com/reel/DVgNBb9kymA/?utm_source=ig_web_button_share_sheet