Close Menu
Fin Street NewsFin Street News
  • Home
  • Business
  • Finance
    • Banking
    • Stocks
    • Commodities & Futures
    • ETFs & Mutual Funds
    • Funds
    • Currencies
    • Crypto
  • Markets
  • Investing
  • Personal Finance
    • Loans
    • Credit Cards
    • Dept Management
    • Retirement
    • Mortgages
    • Saving
    • Taxes
  • Fintech
  • More Articles

Subscribe to Updates

Get the latest finance and business news and updates directly to your inbox.

Trending
Steven Spielberg, 79, said his wife gave him one rule before he started DreamWorks

Steven Spielberg, 79, said his wife gave him one rule before he started DreamWorks

June 1, 2026
My family of 5 lives with my in-laws. The more I protected my own balance, the more I noticed the pressure on my husband.

My family of 5 lives with my in-laws. The more I protected my own balance, the more I noticed the pressure on my husband.

June 1, 2026
Inside the unseen operation to turbocharge Claude Code

Inside the unseen operation to turbocharge Claude Code

June 1, 2026
I moved to Japan alone. Building cabins in the countryside helped me feel at home.

I moved to Japan alone. Building cabins in the countryside helped me feel at home.

May 31, 2026
United flight turns around over Atlantic after onboard device sparks alarm

United flight turns around over Atlantic after onboard device sparks alarm

May 31, 2026
Facebook X (Twitter) Instagram
  • Privacy Policy
  • Terms of use
  • Press Release
  • Advertise
  • Contact
June 1, 2026 3:01 am EDT
|
Facebook X (Twitter) Instagram
  Market Data
Fin Street NewsFin Street News
Newsletter Login
  • Home
  • Business
  • Finance
    • Banking
    • Stocks
    • Commodities & Futures
    • ETFs & Mutual Funds
    • Funds
    • Currencies
    • Crypto
  • Markets
  • Investing
  • Personal Finance
    • Loans
    • Credit Cards
    • Dept Management
    • Retirement
    • Mortgages
    • Saving
    • Taxes
  • Fintech
  • More Articles
Fin Street NewsFin Street News
Home » Hot AI startup Lovable’s security stumble shows one big risk in vibe coding
Hot AI startup Lovable’s security stumble shows one big risk in vibe coding
Finance

Hot AI startup Lovable’s security stumble shows one big risk in vibe coding

News RoomBy News RoomApril 21, 20264 ViewsNo Comments

Lovable’s recent security fumble just gave pro software engineers one more reason to be wary of vibe coding.

On Monday, an X user called Lovable out and said that the Swedish AI-coding startup suffered a mass data breach “affecting every project created before November 2025.”

The individual, who goes by the username “Impulsive” on X, said that they were able to access another user’s code, AI chat histories, and customer data through their free Lovable account.

“Nvidia, Microsoft, Uber, and Spotify employees all have accounts. The bug was reported 48 days ago. It’s not fixed. They marked it as duplicate and left it open,” they wrote.

In response, Lovable denied there was a data breach and said that seeing public projects’ code was a deliberate decision.

After backlash on X about the message’s clarity and how users should secure their data moving forward, Lovable shared a second statement.

The company explained that it allowed others to view “public” projects “to make it easy to explore what others were building.” It added that since December, it has switched off public visibility by default across all subscription tiers.

In the second statement, Lovable also acknowledged the security error that the original X post first flagged.

“Unfortunately, in February, while unifying permissions in our backend, we accidentally re-enabled access to chats on public projects,” Lovable wrote. “Upon learning this, we immediately reverted the change to make all public projects’ chats private again. We appreciate the researchers who uncovered this.”

Some users said they appreciated Lovable’s transparency, while others said the company’s first message was akin to “gaslighting.”

Tom Van de Wiele, founder of security firm Hacker Minded, told Business Insider the incident is “another unfortunate example of lacking secure defaults and a failure to threat model for the automated and AI age.”

He added that relying on users to understand what’s public and what’s not “always falls flat eventually.”

Jake Moore, global cybersecurity advisor at ESET, said the debate over whether the incident qualifies as a breach risks missing the bigger issue.

“It isn’t really a traditional breach but it’s also not harmless either,” he told Business Insider. “It’s essentially more of a design flaw, seeing as data was exposed rather than hacked.”

“When a company argues semantics instead of impact, it usually means security wasn’t baked in from day one, which is the reality of what caused this,” he added.

A trade-off

In general, professional developers discourage overreliance on AI because it can produce messy, untested code. They say vibe coding comes with information security concerns, including company data being exposed.

Van de Wiele said companies building these tools often face a trade-off between making products easy to use and keeping them secure — but that doesn’t excuse weak protections.

“Companies are often caught between a rock and a hard place, wanting to lower friction for new users while trying to protect against data scrapers,” he said, adding that there are real consequences for users whose information may be scraped and resold.

Moore said vibe-coding tools can make these risks worse if users don’t fully understand what’s being exposed.

“Vibe coding continues to accelerate bad defaults and users need to be explicitly aware of this and have fail-safes and backups in place,” he said.

That dynamic could make incidents like this more common, he suggested.

“If users can accidentally expose sensitive data through AI coding defaults, attackers don’t need to hack anything at all,” Moore said.

String of security mishaps

The Lovable error comes after two other major data leaks from AI companies in the last few weeks.

In late March, Anthropic mistakenly leaked an archive of nearly 2,000 files and 500,000 lines of code. Anthropic said at the time that “no sensitive customer data or credentials were involved or exposed.”

Earlier this week, website hosting platform Vercel said it had identified an incident that gave unauthorized users access to certain internal Vercel systems.

Vercel said that the incident started with a compromise of Context.ai, a third-party tool used by a Vercel employee. The attacker used that access to take over the employee’s Google Workspace account, which also gave them access to some Vercel environments.

“We are actively investigating, and we have engaged incident response experts to help investigate and remediate. We have notified law enforcement and will update this page as the investigation progresses,” Vercel said in a statement on Monday.

On a February podcast, Andreessen Horowitz general partner Anish Acharya said that companies shouldn’t use AI-assisted coding for every part of their business because it’s not worth the risks. Plus, relying on AI to write code carries risks, he said.



Read the full article here

big coding hot Lovables risk security shows startup stumble vibe
Share. Facebook Twitter LinkedIn Telegram WhatsApp Email

Keep Reading

Steven Spielberg, 79, said his wife gave him one rule before he started DreamWorks

Steven Spielberg, 79, said his wife gave him one rule before he started DreamWorks

Ukraine has a war lesson for NATO forces: Drone units need to be constantly on the move with command centers buried deep

Ukraine has a war lesson for NATO forces: Drone units need to be constantly on the move with command centers buried deep

I reinvented myself by losing 300 pounds and moving from the US to Spain. Now I have a happier and healthier lifestyle.

I reinvented myself by losing 300 pounds and moving from the US to Spain. Now I have a happier and healthier lifestyle.

Erin Brockovich says people are angry because data centers are being ‘shoved down their throats’ in secrecy

Erin Brockovich says people are angry because data centers are being ‘shoved down their throats’ in secrecy

The US Army is tearing down old tech walls so its weapons can talk to each other

The US Army is tearing down old tech walls so its weapons can talk to each other

I was recently laid off and am struggling to find a job. I’m in my 50s, and I wonder where I fit in this current job market.

I was recently laid off and am struggling to find a job. I’m in my 50s, and I wonder where I fit in this current job market.

I spent 2 nights in an Amtrak bedroom and tried both bunks. The smaller bed won me over.

I spent 2 nights in an Amtrak bedroom and tried both bunks. The smaller bed won me over.

We moved to Japan 3 years ago. We have a lower cost of living and travel more.

We moved to Japan 3 years ago. We have a lower cost of living and travel more.

I drive from Canada to the US to shop at Trader Joe’s. These 9 items make the trip worthwhile.

I drive from Canada to the US to shop at Trader Joe’s. These 9 items make the trip worthwhile.

Add A Comment
Leave A Reply Cancel Reply

Editors Picks

My family of 5 lives with my in-laws. The more I protected my own balance, the more I noticed the pressure on my husband.

My family of 5 lives with my in-laws. The more I protected my own balance, the more I noticed the pressure on my husband.

June 1, 2026
Inside the unseen operation to turbocharge Claude Code

Inside the unseen operation to turbocharge Claude Code

June 1, 2026
I moved to Japan alone. Building cabins in the countryside helped me feel at home.

I moved to Japan alone. Building cabins in the countryside helped me feel at home.

May 31, 2026
United flight turns around over Atlantic after onboard device sparks alarm

United flight turns around over Atlantic after onboard device sparks alarm

May 31, 2026
Zelenskyy makes a pitch to Silicon Valley’s defense startups: Bring your AI, we’ll bring the battle experience

Zelenskyy makes a pitch to Silicon Valley’s defense startups: Bring your AI, we’ll bring the battle experience

May 31, 2026

Latest News

Ukraine has a war lesson for NATO forces: Drone units need to be constantly on the move with command centers buried deep

Ukraine has a war lesson for NATO forces: Drone units need to be constantly on the move with command centers buried deep

May 31, 2026
When my family of 5 moved in with my parents, there was an adjustment period. Now, they don’t want us to leave.

When my family of 5 moved in with my parents, there was an adjustment period. Now, they don’t want us to leave.

May 31, 2026
I reinvented myself by losing 300 pounds and moving from the US to Spain. Now I have a happier and healthier lifestyle.

I reinvented myself by losing 300 pounds and moving from the US to Spain. Now I have a happier and healthier lifestyle.

May 31, 2026

Subscribe to News

Get the latest finance and business news and updates directly to your inbox.

Advertisement
Demo
Facebook X (Twitter) Pinterest TikTok Instagram
2026 © Prices.com LLC. All Rights Reserved.
  • Privacy Policy
  • Terms
  • For Advertisers
  • Contact

Type above and press Enter to search. Press Esc to cancel.