Coding4Food LogoCoding4Food
HomeCategoriesArcadeBookmarks
vi
HomeCategoriesArcadeBookmarks
Coding4Food LogoCoding4Food
HomeCategoriesArcadeBookmarks
Privacy|Terms

© 2026 Coding4Food. Written by devs, for devs.

All news
IT DramaAI & Automation

Vibe Coding Gone Wrong: Guy Trusts Claude, Spills Stripe API Keys to the World

March 5, 20263 min read

A wild story of a dev doing "vibe coding" with Claude, leaking his Stripe API keys on the frontend, and flexing about it on LinkedIn. Reddit devs are roasting him alive.

Share this post:
credit cards, denim, jeans, blue jeans, debit cards, cards, money, bank account, bank, mastercard, pocket, credit cards, money, money, money, money, money, bank, bank, bank
Nguồn gốc: https://coding4food.com/post/vibe-coding-gone-wrong-claude-ai-stripe-api-keys-public. Nội dung thuộc bản quyền Coding4Food. Original source: https://coding4food.com/post/vibe-coding-gone-wrong-claude-ai-stripe-api-keys-public. Content is property of Coding4Food. This content was scraped without permission from https://coding4food.com/post/vibe-coding-gone-wrong-claude-ai-stripe-api-keys-publicNguồn gốc: https://coding4food.com/post/vibe-coding-gone-wrong-claude-ai-stripe-api-keys-public. Nội dung thuộc bản quyền Coding4Food. Original source: https://coding4food.com/post/vibe-coding-gone-wrong-claude-ai-stripe-api-keys-public. Content is property of Coding4Food. This content was scraped without permission from https://coding4food.com/post/vibe-coding-gone-wrong-claude-ai-stripe-api-keys-public
Nguồn gốc: https://coding4food.com/post/vibe-coding-gone-wrong-claude-ai-stripe-api-keys-public. Nội dung thuộc bản quyền Coding4Food. Original source: https://coding4food.com/post/vibe-coding-gone-wrong-claude-ai-stripe-api-keys-public. Content is property of Coding4Food. This content was scraped without permission from https://coding4food.com/post/vibe-coding-gone-wrong-claude-ai-stripe-api-keys-publicNguồn gốc: https://coding4food.com/post/vibe-coding-gone-wrong-claude-ai-stripe-api-keys-public. Nội dung thuộc bản quyền Coding4Food. Original source: https://coding4food.com/post/vibe-coding-gone-wrong-claude-ai-stripe-api-keys-public. Content is property of Coding4Food. This content was scraped without permission from https://coding4food.com/post/vibe-coding-gone-wrong-claude-ai-stripe-api-keys-public
vibe codingstripe api keyclaude aibảo mật weblỗi lập trìnhdrama it
Share this post:

Bình luận

Related posts

log in, login, log on, symbol, gui, button, computer, icon, black computer, black laptop, log in, login, login, login, login, login
IT DramaDev Life

The Ultimate CYA: User Blames IT for 'Broken' Tools to Hide His 2-Hour Workdays

A hilarious Reddit saga where a remote worker blamed the IT support team for his lack of productivity, only for system logs to reveal he barely works at all.

Apr 173 min read
Read more →
programming, robot, cyborg, artificial intelligence, programmer, technology, futuristic, computer, data, internet, information, communication, tech, network, laptop, server, cartoon
TechnologyAI & Automation

Cloudflare's New Tool Wants You to Code for AI Agents. Are Humans Obsolete?

Cloudflare launched 'Agent-Ready Scanner' to audit if your website can handle AI agents. Are we building the web for machines now? Let's dive into the drama.

Apr 192 min read
Read more →
ai, robot, technology, coding, laboratory, development, women, engineering, collaboration, future, innovation, software, research, science, tech, workplace, machine, human, screen, data, ai generated
AI & AutomationTechnology

Verdent 2.0: An AI Demanding to be Your Co-founder - VC Bait or the Holy Grail?

Verdent 2.0 claims to be your AI Tech Co-founder, replacing PMs, Devs, and QA. Let's see how the tech community roasts and toasts this absolute unit of an AI.

Apr 203 min read
Read more →
warning, error, error code, mistake, 404
IT DramaAI & Automation

The Hottest Job of 2030: AI Disaster Cleanup Consultant at 3x Pay

Companies are firing seniors to replace them with AI. Here is why the inevitable cleanup will make veteran devs richer than ever.

Apr 183 min read
Read more →
computer, laptop, tech, blue computer, blue laptop, blue tech, computer, laptop, tech, tech, tech, tech, tech
AI & AutomationTechnology

OpenAI's Codex 2.0: From Code Monkey to Micro-Managing Butler?

OpenAI drops Codex 2.0, aiming to turn it into a full workflow agent that operates your Mac. Let's see if it's the ultimate dev tool or just overhyped copium.

Apr 183 min read
Read more →
hacker, full hd wallpaper, hood, wallpaper hd, beautiful wallpaper, windows wallpaper, free background, light, boy, criminal, portal, hd wallpaper, mac wallpaper, fantastic, youth, wallpaper 4k, life style, wallpaper, star, laptop wallpaper, cool backgrounds, free wallpaper, desktop backgrounds, 4k wallpaper 1920x1080, 4k wallpaper, background
IT DramaTechnology

The GitHub Black Market: When Open-Source Stars Are Just Bought and Paid For

Deep dive into the underground market of faking GitHub stars. How bots and click farms manipulate trending repos to fool devs and VC funds.

Apr 203 min read
Read more →

The "vibe coding" hype is real right now—just vibe with your prompt, and the AI magically spits out a full-stack app. But reality hits different, folks. A recent story just dropped about a dude who literally served his Stripe API keys on a silver platter to the internet, all because he trusted Claude a bit too much.

The Anatomy of a Prod Disaster

So here’s the tea. This guy (probably lazy, probably a bit too overly optimistic about AI) decided to build a site using Claude. This wouldn't be news if his approach to security wasn't a complete dumpster fire.

Instead of manually handling his environment variables or, you know, actually reading the code, he threw some purely spiritual prompts at the AI: "make sure all our api keys are not on the front end" and topped it off with the legendary "All the security measures are taken."

Result? Claude probably responded with "Sure thing, boss," but the actual code generated left the Stripe Secret API keys hanging out completely exposed on the client side. Big yikes!

The aftermath was brutal. The moment the site went live, malicious bots scraped it and used the API for credit card testing. His Stripe account got hit with massive fee charges.

But the wildest part? He didn't just quietly hotfix it in shame. He wrote a whole essay on LinkedIn flexing about his startup journey. Reading his post, it tracks that he wasn't sweating the fact that he exposed users to credit card theft; he was just salty about his wallet taking a hit from Stripe fees.

His ultimate takeaway from this whole fiasco? "I was just one prompt away." Delusional!

Reddit is Absolutely Roasting Him

Unsurprisingly, the web dev community on Reddit had an absolute field day with this.

First came the mocking of the "Prompt Engineers". People were dying laughing at the "just make it secure bro" prompt. One guy sarcastically noted, "Yeah, I’m sure that will make it crystal clear for Claude." Newsflash: AI isn't sentient. It doesn't know your deployment architecture.

Then came the heavy sarcasm. One user dropped this gem: "I always feel it's best to publish API keys in public... that way others can help you find it if you lose it." Painful, but hilarious.

Lastly, the sheer disbelief. Many devs couldn't fathom the audacity of posting this colossal fuck-up on LinkedIn for recruiters to see. Someone went to check the original post and reported back: the guy was actually in the comments defending his actions. Absolutely unhinged.

The C4F Verdict: Don't Be That Guy

Look, AI is amazing. It codes fast, helps you debug, and saves time. But remember, AI is basically a junior developer on steroids who types really fast but hallucinates occasionally. It is NOT your Senior Tech Lead.

"Vibe coding" is fine for a weekend hackathon, but when you are shipping to production and actual money is involved, turn off the vibes and turn on your brain. Security is not a magical string you append to a prompt. It’s about environment variables, CORS, rate limiting, and the golden rule: Never trust the client.

Don't wait until your server crashes and your bank account drains to realize you played yourself. If you copy-paste blindly without reading, that's on you, not the AI.

Alright, if you're currently "prompting" your app into existence, go check your .env file right now before you wake up tomorrow as the king of debt.

Source: Reddit - Vibe code IRL: left Stripe API keys public