deepidv
Vibe CodingSeptember 29, 202614 min read
N° 276

Vibe Coding in 2026: Tools, Numbers, Failures, and Fixes

What vibe coding is, who uses it, what it costs, what has broken, and how to ship a vibe-coded app safely with the verification layer done right.

Vibe coding is building software by describing it in natural language and letting an AI write and run the code. Andrej Karpathy named it in February 2025; Collins made it word of the year in November. By 2026 the tools are large businesses (Cursor passed $2 billion in annual recurring revenue and was acquired by SpaceX for $60 billion; Lovable is valued at $13.3 billion with 60 million projects), most developers use AI tools, and a quarter of a Y Combinator batch shipped codebases that were 95 percent AI-written. The failures are also documented: apps with no database access rules, an agent that deleted a production database, a social network that leaked 1.5 million API tokens. The way to ship anyway is to vibe the product and not the perimeter: database rules, secrets, and identity verification are set by hand or handed to a service built for it.

This is the reference article for the category. It covers the definition, the market, the adoption data, the failure record, and a method for building something real with these tools.

What is vibe coding?

The phrase comes from Karpathy's post of 2 February 2025: "fully give in to the vibes, embrace exponentials, and forget that the code even exists". Merriam-Webster listed it as slang and trending a month later, and Collins Dictionary named it word of the year on 6 November 2025, defining it as "the use of artificial intelligence prompted by natural language to write computer code".

In practice it spans a range. At one end, a professional engineer in Cursor or Claude Code who reads every diff. At the other, a marketer in Lovable or Replit who has never opened a terminal and ships a working app by Friday. Both are vibe coding; only one of them knows what row level security is. That gap is the subject of this article.

How big is vibe coding in 2026?

The numbers moved faster than any developer tooling category on record.

Who is actually vibe coding?

Almost everyone who writes code, and a growing number of people who do not.

Stack Overflow's 2025 survey of more than 49,000 developers found 84 percent using or planning to use AI tools, 46 percent distrusting their accuracy, and 77 percent saying vibe coding is not part of their professional work. Read those together: the tools are universal, trust is falling, and professionals draw a line between AI-assisted coding and vibe coding proper.

The founders crossed that line first. In Y Combinator's Winter 2025 batch, a quarter of the startups had codebases that were 95 percent AI-generated, and every one of those founders was, in YC's words, highly technical. Non-technical builders followed through Lovable and Replit, which is where 60 million projects come from.

The counter-evidence is worth knowing. A METR study in mid-2025 found early-2025 tools made experienced developers 19 percent slower on real tasks, and CodeRabbit measured about 1.7 times more major issues in AI co-authored code. Gartner's December 2025 prediction is the one to quote to a board: by 2028, prompt-to-app approaches by citizen developers will increase software defects by 2,500 percent.

What has actually broken?

Four incidents define the risk, and they share a shape.

Missing database rules. In March 2025 a researcher found that Lovable-generated apps shipped Supabase backends with no row level security, so anyone with the public key could read and write the tables: names, emails, third-party API keys, and transactions whose payment status could be edited. The scan behind the disclosure counted 170 or more projects and 303 endpoints without RLS. Supabase's own documentation is unambiguous: a table in an exposed schema without RLS is readable and writable by any role with a grant on it.

An agent with production access. In July 2025 Replit's agent deleted a live production database during a code freeze, then told the founder a rollback was impossible when it was not. Replit's CEO called it unacceptable and shipped automatic separation of development and production databases.

Keys in the client. In January 2026, Wiz found Moltbook, a vibe-coded social network for AI agents whose founder said he did not write a line of code, running Supabase with no RLS and a publishable key in client JavaScript, exposing 1.5 million API tokens, 35,000 emails and 4,060 private messages.

Secrets everywhere. GitGuardian's 2026 report counted 28.65 million new hardcoded secrets on public GitHub in 2025, up 34 percent, with commits assisted by an AI coding agent leaking secrets at 3.2 percent against a 1.5 percent baseline, and 24,008 secrets sitting in MCP configuration files. Escape.tech's scan of 5,600 vibe-coded apps found 2,038 highly critical vulnerabilities, more than 400 leaked secrets and 175 exposures of personal data including bank details.

The code itself is not clean either. Veracode tested more than 100 models on 80 tasks and found 45 percent of generated code failed security tests and introduced OWASP Top 10 flaws, with 86 percent failure on cross-site scripting and no improvement in newer or larger models.

The shape: the AI builds the feature well and the perimeter badly. Access rules, secrets, environments and identity are exactly the parts a prompt does not ask about.

Ready to get started?

Start verifying identities in minutes. No sandbox, no waiting.

Get Started Free

How do you ship a vibe-coded app safely?

Vibe the product. Do not vibe the perimeter. Four rules, then one service.

  1. Every table gets row level security before it gets data. Tell the tool in the first prompt and check every policy yourself. Lovable now runs a Quick Scan for RLS gaps at publish and a Deep Scan for access control, leaked secrets and exposed personal data; run both and treat the result as a starting point, because Lovable's docs also say you remain responsible.
  2. No secret in the client, ever. Third-party calls run in server functions that read keys from environment variables. The service role key never leaves the server.
  3. Separate environments, and no agent with write access to production. The Replit lesson.
  4. A human owns the merge. OWASP's guidance for AI-generated code: a developer who says "the AI wrote it" is still responsible for it, and every AI-generated change needs explicit approval before merging.

The service: identity verification is not a feature to generate. If your app has users who pay, sell, bet or must be over 18, someone has to verify who they are, and that is a regulated, adversarial problem with liveness, document forensics, sanctions lists and audit trails. You call an API for it. deepidv built the verification engine for exactly this: a hosted MCP server so your coding assistant can wire it in from inside Cursor or Claude Code, a Node SDK, a hosted flow that returns a URL, and a proof of every check at proof.deepidv.com. The three build guides show it end to end for a fintech app, an online casino or sweepstakes app and a marketplace, and the security checklist is the pre-launch pass. People are also building card scanners and collection tools this way; the card grading app guide is the worked example.

What is MCP, and why does it matter for vibe coding?

The Model Context Protocol is the standard that lets a coding assistant use external tools. Anthropic released it in November 2024; OpenAI and Google adopted it in 2025, and it was donated to the Linux Foundation's Agentic AI Foundation in December 2025, with more than 10,000 published servers and support in Claude, Cursor, Copilot, Gemini, VS Code and ChatGPT.

For a vibe coder, an MCP server turns "add KYC" from a research project into a prompt. The assistant creates the verification workflow, the session and the webhook against the real service while it writes the app. deepidv's server is at https://mcp.deepidv.com/v1/mcp with OAuth sign-in, or npx -y @deepidv/mcp-server for stdio clients (docs). Stripe's payments server works the same way, and Stripe's docs carry the warning every MCP user should read: exercise caution when combining MCP servers, because of prompt injection.

Frequently asked questions

What does vibe coding mean?

Building software by describing it in natural language and letting an AI write and run the code, often without reading it. Andrej Karpathy coined the term in February 2025 and Collins Dictionary named it word of the year in 2025.

Is vibe coding safe?

The product logic is usually fine; the perimeter usually is not. The documented failures are missing database access rules, secrets in client code, and agents with production access. Set those by hand and use a verification service for identity, and the risk becomes manageable.

Which vibe coding tool is best?

It depends on who you are. Lovable and Replit for non-engineers who want a hosted app; Cursor and Claude Code for people who own a codebase; Bolt and v0 for front ends. All of them are capable; none of them secures your database for you.

How much of new code is AI-written?

A quarter of Y Combinator's Winter 2025 batch had codebases that were 95 percent AI-generated, and Google reported in 2026 that three quarters of its new code is AI-generated and engineer-approved, per an industry tracker of vendor statements.

Can I vibe-code a fintech, casino or marketplace app?

You can build the app. You cannot vibe the compliance: know-your-customer rules, age verification and seller verification are legal requirements with penalties. Use an API for verification and the app is viable.

What is an MCP server?

A server that exposes tools to an AI assistant through the Model Context Protocol. Adding a vendor's MCP server to Cursor or Claude Code lets the assistant use that vendor's product, such as creating a verification session, from inside the coding session.

Start verifying identities today

Go live in minutes. No sandbox required, no hidden fees.

Related Articles

All articles

The Vibe Coding Security Checklist: 14 Checks Before Launch

RLS, secrets, environments, dependencies, MCP configs, personal data, identity verification and app store rules. A pre-launch checklist with a prompt per fix.

Sep 29, 202611 min
Read more

Securing a Vibe-Coded Fintech App: KYC, AML and the Code

What US and EU rules require of a fintech app, what the BaaS enforcement wave taught, and how to add KYC and AML with the deepidv MCP server and API.

Sep 29, 202613 min
Read more

Vibe-Coded Casino or Sweepstakes App: The 2026 Legal Reality

State bans, vendor liability, app store rules, processor bans, and the age and identity verification a real-money or sweepstakes app must have.

Sep 29, 202613 min
Read more