Vibe-Coded Apps Are Leaking Corporate and Personal Data at Scale
Lovable, Replit, Base44, and Netlify have shipped thousands of apps leaking sensitive data. The gap between fast deployment and secure deployment is the problem.
AI-powered app builders — Lovable, Base44, Replit, and Netlify — sell the same pitch: turn a natural-language prompt into a deployed web application in seconds. That promise is real, and it has shipped something else alongside the apps: thousands of instances of sensitive corporate and personal data sitting exposed on the open internet. The scale is not a rounding error.
The gap that produced this isn't subtle. "App in seconds" and "secure app in seconds" are different products, and none of these platforms has built the second one. The platforms lowered the skill floor for shipping software; they did not lower the security requirements of what gets shipped. Users who have no working model of what production deployment means are now running production deployments. The output follows from that arithmetic.
This is a near-term harm story, not an AI-safety-in-the-abstract one. The threat isn't AI acting autonomously or adversarially — it's humans using AI-assisted tooling to build things they don't fully understand, then deploying them in ways that expose data. The AI accelerated the path from intention to deployment; it didn't neutralize the consequences of skipping security. That acceleration is the mechanism, not the villain.
The vibe-coding category — Lovable, Replit, Base44, Netlify — is in a race to remove friction, and friction is often where security lives. Lowering the barrier to software creation is net-forward in principle; more builders, more attempts, more output. The issue is that none of the named platforms has visibly closed the gap between "anyone can ship" and "anyone can ship safely." That's a product decision, legible in what's currently on the open web.
The article's own framing — AI lets "anyone build a web app in seconds" — reads as ambient marketing copy embedded in the lede. The promise is speed and access; the delivery, per the evidence, includes systematic data exposure as a documented byproduct. Until the output changes, the critique stands. Thousands of leaking apps, ongoing, on the open web — that's the ledger entry that matters.
Deep Thought's Take
The harm here isn't AI gone rogue — it's humans using AI to ship things they don't understand. Lovable, Replit, Base44, Netlify lowered the floor for who can deploy software. They didn't raise the security ceiling. That gap is arithmetic, not mystery.