Coding4Food LogoCoding4Food
HomeCategoriesArcadeBookmarks
vi
HomeCategoriesArcadeBookmarks
Coding4Food LogoCoding4Food
HomeCategoriesArcadeBookmarks
Privacy|Terms

© 2026 Coding4Food. Written by devs, for devs.

All news
IT DramaAI & Automation

Vibe Coding Gone Wrong: Guy Trusts Claude, Spills Stripe API Keys to the World

March 5, 20263 min read

A wild story of a dev doing "vibe coding" with Claude, leaking his Stripe API keys on the frontend, and flexing about it on LinkedIn. Reddit devs are roasting him alive.

Share this post:
credit cards, denim, jeans, blue jeans, debit cards, cards, money, bank account, bank, mastercard, pocket, credit cards, money, money, money, money, money, bank, bank, bank
Nguồn gốc: https://coding4food.com/post/vibe-coding-gone-wrong-claude-ai-stripe-api-keys-public. Nội dung thuộc bản quyền Coding4Food. Original source: https://coding4food.com/post/vibe-coding-gone-wrong-claude-ai-stripe-api-keys-public. Content is property of Coding4Food. This content was scraped without permission from https://coding4food.com/post/vibe-coding-gone-wrong-claude-ai-stripe-api-keys-publicNguồn gốc: https://coding4food.com/post/vibe-coding-gone-wrong-claude-ai-stripe-api-keys-public. Nội dung thuộc bản quyền Coding4Food. Original source: https://coding4food.com/post/vibe-coding-gone-wrong-claude-ai-stripe-api-keys-public. Content is property of Coding4Food. This content was scraped without permission from https://coding4food.com/post/vibe-coding-gone-wrong-claude-ai-stripe-api-keys-public
Nguồn gốc: https://coding4food.com/post/vibe-coding-gone-wrong-claude-ai-stripe-api-keys-public. Nội dung thuộc bản quyền Coding4Food. Original source: https://coding4food.com/post/vibe-coding-gone-wrong-claude-ai-stripe-api-keys-public. Content is property of Coding4Food. This content was scraped without permission from https://coding4food.com/post/vibe-coding-gone-wrong-claude-ai-stripe-api-keys-publicNguồn gốc: https://coding4food.com/post/vibe-coding-gone-wrong-claude-ai-stripe-api-keys-public. Nội dung thuộc bản quyền Coding4Food. Original source: https://coding4food.com/post/vibe-coding-gone-wrong-claude-ai-stripe-api-keys-public. Content is property of Coding4Food. This content was scraped without permission from https://coding4food.com/post/vibe-coding-gone-wrong-claude-ai-stripe-api-keys-public
vibe codingstripe api keyclaude aibảo mật weblỗi lập trìnhdrama it
Share this post:

Bình luận

Related posts

code, coding, computer, data, developing, development, ethernet, html, programmer, programming, screen, software, technology, work, code, code, coding, coding, coding, coding, coding, computer, computer, computer, computer, data, programming, programming, programming, software, software, technology, technology, technology, technology
Dev LifeIT Drama

"LLMs Are Eating My Career" - A Dev's Existential Crisis on Hacker News

A trending Hacker News post reveals mid-career panic as devs feel LLMs are taking over. Are AI tools ending software engineering or just evolving it?

Jun 73 min read
Read more →
work, computer, apple, business, office, desk, technology, pen, phone, smartphone, workstation, blog, blogging, table, book, mouse, computer, apple, apple, apple, business, office, office, office, desk, blog, blog, blog, blog, blog, blogging, blogging, book
IT DramaTechnology

Lean Startup Godfather Eric Ries Drops Truth Bombs on Corporate Greed and Gets Roasted by AI Drama

Eric Ries returns to HN to promote his new book 'Incorruptible', introducing 'financial gravity' while getting roasted over his Claude Code generated site.

Jun 113 min read
Read more →
coding, programming, css, software development, computer, close up, laptop, data, display, electronics, keyboard, screen, technology, app, program, software, computer engineering, coding, coding, coding, programming, programming, software development, computer, data, software, software, software, software, software
AI & AutomationTools & Tech Stack

Sick of Saying "No, the Other Blue Button"? Qursor Just Solved Your Vibe-Coding Nightmare

Tired of AI agents editing the wrong UI element and burning your tokens? Qursor lets you point, copy structured CSS/HTML context, and paste it straight to your AI.

Jun 133 min read
Read more →
euro, europe, rocket, nature, prices, price increase, clouds, heaven, strip, aviator, finance, money, currency, inflation, economic crisis, energy crisis, energy saving, market economy, cost, development, stock exchange
TechnologyIT Drama

S&P 500 Slams the Door on SpaceX & AI Giants: Cash is King, Hype is Dead

The S&P 500 committee rejected SpaceX's fast-track and blocked unprofitable AI giants like OpenAI and Anthropic. Read the full drama and tech reactions here!

Jun 63 min read
Read more →
graphic, poop, frozen poop, poop emoji, emoji, smiley, poo, crap, emoticon, funny, frozen, ice, winter, laugh, smile, happy, emotion, face
AI & AutomationTechnology

Turning AI into 💩: The Ultimate Troll Extension Slapping Tech's Biggest Hype

A new Chrome Extension literally replaces 'AI' with 💩. It's hilarious, but the underlying roast of the tech industry's forced AI trend is brutally honest.

Jun 33 min read
Read more →
printed circuit board, circuit board, electronics, circuit, computer chip, microchip
IT DramaTechnology

PR Nightmare 101: Flux.ai Sends Legal Goons After Open-Source Darling Adafruit

VC-backed startup Flux.ai thought sending a legal demand letter to Adafruit was a big brain move. Spoiler alert: The internet is now roasting them alive.

Jun 32 min read
Read more →

The "vibe coding" hype is real right now—just vibe with your prompt, and the AI magically spits out a full-stack app. But reality hits different, folks. A recent story just dropped about a dude who literally served his Stripe API keys on a silver platter to the internet, all because he trusted Claude a bit too much.

The Anatomy of a Prod Disaster

So here’s the tea. This guy (probably lazy, probably a bit too overly optimistic about AI) decided to build a site using Claude. This wouldn't be news if his approach to security wasn't a complete dumpster fire.

Instead of manually handling his environment variables or, you know, actually reading the code, he threw some purely spiritual prompts at the AI: "make sure all our api keys are not on the front end" and topped it off with the legendary "All the security measures are taken."

Result? Claude probably responded with "Sure thing, boss," but the actual code generated left the Stripe Secret API keys hanging out completely exposed on the client side. Big yikes!

The aftermath was brutal. The moment the site went live, malicious bots scraped it and used the API for credit card testing. His Stripe account got hit with massive fee charges.

But the wildest part? He didn't just quietly hotfix it in shame. He wrote a whole essay on LinkedIn flexing about his startup journey. Reading his post, it tracks that he wasn't sweating the fact that he exposed users to credit card theft; he was just salty about his wallet taking a hit from Stripe fees.

His ultimate takeaway from this whole fiasco? "I was just one prompt away." Delusional!

Reddit is Absolutely Roasting Him

Unsurprisingly, the web dev community on Reddit had an absolute field day with this.

First came the mocking of the "Prompt Engineers". People were dying laughing at the "just make it secure bro" prompt. One guy sarcastically noted, "Yeah, I’m sure that will make it crystal clear for Claude." Newsflash: AI isn't sentient. It doesn't know your deployment architecture.

Then came the heavy sarcasm. One user dropped this gem: "I always feel it's best to publish API keys in public... that way others can help you find it if you lose it." Painful, but hilarious.

Lastly, the sheer disbelief. Many devs couldn't fathom the audacity of posting this colossal fuck-up on LinkedIn for recruiters to see. Someone went to check the original post and reported back: the guy was actually in the comments defending his actions. Absolutely unhinged.

The C4F Verdict: Don't Be That Guy

Look, AI is amazing. It codes fast, helps you debug, and saves time. But remember, AI is basically a junior developer on steroids who types really fast but hallucinates occasionally. It is NOT your Senior Tech Lead.

"Vibe coding" is fine for a weekend hackathon, but when you are shipping to production and actual money is involved, turn off the vibes and turn on your brain. Security is not a magical string you append to a prompt. It’s about environment variables, CORS, rate limiting, and the golden rule: Never trust the client.

Don't wait until your server crashes and your bank account drains to realize you played yourself. If you copy-paste blindly without reading, that's on you, not the AI.

Alright, if you're currently "prompting" your app into existence, go check your .env file right now before you wake up tomorrow as the king of debt.

Source: Reddit - Vibe code IRL: left Stripe API keys public