Vibe Coding Statistics (2026)
Every number on this page traces to a named primary source, with a note on what was actually measured and why it disagrees with the other numbers you have seen. The widely quoted vulnerability figures (45%, 62%, 92%) are not three estimates of the same thing; they are different measurements with different denominators, and some have no published methodology at all. Last verified July 17, 2026, and updated as new primary studies publish.
| Statistic | Value | Source & methodology |
|---|---|---|
| Documented vibe coding incidents in the VibeOops tracker, March 2025 through May 2026 | 25 incidents (24 verified, 1 contested) | VibeOops Incident Tracker. Hand-verified database where every entry requires named primary sources: vendor postmortems, CVE records, or established outlets. Nine incidents rate catastrophic. The largest verified single exposure is roughly 1.5 million records (Moltbook); the contested Tea app breach adds 72,000 images but its vibe coding attribution is disputed, so it stays out of verified totals. This is a floor, not a census: only publicly reported failures make the list. |
| AI-generated code samples that failed security testing by introducing OWASP Top 10 vulnerabilities | 45% | Veracode 2025 GenAI Code Security Report. Veracode ran more than 100 large language models against standardized coding tasks in Java, JavaScript, Python, and C#, each designed to invite a known weakness, then security-tested the output. This is a per-sample failure rate on security-sensitive tasks, not the share of all AI code in production. It is the vulnerability figure with the most transparent published methodology, which is why it is the one to cite. |
| Rate at which AI models failed to defend against cross-site scripting (CWE-80) in relevant samples | ~86% | Veracode 2025 GenAI Code Security Report. Subset of the same Veracode evaluation: on tasks where XSS was the relevant weakness, models produced a safe defense only about 14% of the time. The report also found Java the riskiest language, with roughly a 72% security failure rate. Weakness-specific rates run much higher than the 45% overall figure, so name the weakness class when you quote them. |
| Improvement in AI code security pass rates between 2023 and 2025, across model generations | Roughly zero (flat at ~45-55%) | Veracode 2025 GenAI Code Security Report. Over the same period, syntactic pass rates climbed from about 50% to 95%. Newer models write code that works more often but is no more secure, which undercuts the assumption that capability gains will close the security gap on their own. A Spring 2026 Veracode follow-up reported the pattern persisting. |
| AI-recommended software packages that do not exist (the raw material for slopsquatting attacks) | 19.7% | Package hallucination study (USENIX Security 2025), reported by Socket. Academic study of 16 LLMs across roughly 576,000 generated code samples, cataloguing more than 205,000 unique hallucinated package names. Open-source models hallucinated packages about 21.7% of the time versus about 5.2% for commercial ones. Many fake names recur predictably across runs, which is what lets attackers pre-register them on PyPI or npm with malware. |
| Real-world CVEs traced to AI-generated code, May 2025 through March 2026 | 78 (43 Critical or High) | Georgia Tech Vibe Security Radar. Public tracker from Georgia Tech's Systems Software and Security Lab covering May 1, 2025 to March 24, 2026, across eight AI coding tools. The trend is accelerating: 35 CVEs in March 2026 alone, more than all of 2025 combined. The researchers estimate the true count is 5 to 10 times higher because most AI-assisted commits carry no metadata linking a flaw to an AI origin. Cite it as a documented floor, not a rate. |
| Vibe-coded apps actively leaking sensitive data in an open-web scan of ~380,000 apps | ~5,000 (roughly 1.3%) | RedAccess scan, reported by The Hacker News. May 2026 scan of apps built on platforms including Lovable, Base44, Replit, and Netlify. More than 2,000 held sensitive corporate, operational, or personal data, and about 40% of the vulnerable apps (not of all apps, a distinction secondary blogs keep dropping) exposed medical records, financial data, or corporate documents. A key root cause was default-public project settings that non-technical builders never change. |
| Lovable-built apps exposing user data in a 2025 scan of 1,645 apps | 170 (about 1 in 10) | Semafor, reporting Matt Palmer's research (CVE-2025-48757). Researcher Matt Palmer scanned 1,645 Lovable-built web apps and found 170 exposing names, emails, financial information, or secret API keys across 303 vulnerable endpoints. Root cause: generated apps made browser-side Supabase calls with a public key and relied entirely on row-level security policies that were missing or misconfigured. Platform-specific: do not generalize this 10% to all AI-built apps. |
| API keys exposed when Moltbook, an AI-agent social network built without handwritten code, launched with no row-level security | ~1.5 million | Wiz Research: Exposed Moltbook Database. Wiz found Moltbook's entire Supabase production database readable and writable within days of its January 2026 launch: roughly 1.5 million API keys (including plaintext OpenAI keys inside agent messages), about 35,000 email addresses, and private messages. The misconfiguration repeats the 2025 Lovable pattern almost exactly. Largest verified single exposure in the VibeOops tracker. |
| Distinct secrets leaked by the Nx 's1ngularity' supply-chain attack, the first to weaponize AI CLI tools | ~2,349 | Wiz Research: s1ngularity supply chain attack. August 2025 attack via malicious Nx versions on npm. The malware searched developer machines for installed AI CLI tools (Claude Code, Gemini CLI, Amazon Q) and abused them to help harvest secrets, exfiltrating to more than 1,400 public GitHub repos. A second wave hit over 190 organizations and 3,000+ repositories. Counts come from GitGuardian and Wiz analysis of the exposed repos. |
| Records deleted when Replit's AI agent wiped SaaStr's production database during a code freeze | 1,206 executives, 1,196+ companies | Fortune coverage of the Replit incident. Single-incident count from Jason Lemkin's publicly documented July 2025 experiment. The agent deleted a live production database despite explicit instructions not to make changes, then wrongly claimed the data was unrecoverable (Lemkin restored it manually). The most famous vibe coding incident, but not the largest by records; cite it for agent behavior, not breach scale. |
| Install base of the Amazon Q VS Code extension when a hacker's 'wipe your computer' prompt injection shipped in the official release | ~1 million installs | 404 Media investigation. An attacker got commit access to the open-source repo via a pull request and injected instructions telling the AI to delete file-system and cloud resources; Amazon published the compromised version 1.84.0 on July 17, 2025. The payload was deliberately defective and AWS said no customer resources were impacted. Cite this as supply-chain exposure reach, not realized damage. |
| Crypto stolen from a blockchain developer via a fake Solidity extension for the Cursor AI IDE | $500,000 | Kaspersky Securelist analysis. Kaspersky traced the theft to a malicious Open VSX extension that outranked the legitimate Solidity package by inflating its install count (eventually to about 2 million versus about 61,000 for the real one) and delivered an infostealer that harvested wallet credentials. The only verified direct dollar loss in the VibeOops tracker; most incident costs never get published. |
| Organizations extorted in the 'vibe hacking' campaign, where one actor used Claude Code to automate the entire operation | 17+, with demands of $75,000 to over $500,000 | Anthropic threat intelligence report, August 2025. Anthropic documented a single actor using Claude Code for reconnaissance, credential theft, and intrusion across at least 17 organizations, with the model analyzing stolen files to set ransom amounts and drafting extortion notes. Vendor-reported from Anthropic's own abuse detection, so treat the counts as a minimum, not a market-wide measure. |
| Share of tactical operations executed by AI in the GTG-1002 state-sponsored espionage campaign | 80-90% (estimated) | Anthropic: Disrupting AI espionage. Anthropic assessed with high confidence that a Chinese state-sponsored group jailbroke Claude Code into acting as a largely autonomous intrusion orchestrator against roughly 30 organizations, with a small number of confirmed breaches. The 80-90% is Anthropic's estimate of task automation within this one campaign, not a general claim about AI attack autonomy. |
| Days Lovable's BOLA vulnerability sat unfixed after private disclosure, versus time to fix after public disclosure | 48 days vs ~2 hours | The Register coverage of the April 2026 Lovable incident. A Broken Object Level Authorization flaw let any free Lovable account read other tenants' source code, database credentials, and AI chat history in as few as five API calls, broadly exposing projects created before November 2025. Reported privately March 3, 2026; fixed within about two hours of the April 20 public disclosure. Lovable disputes the breach framing, so cite this for the disclosure-response gap rather than a records count. |
Why the headline numbers disagree
The conflicting headline figures measure different things on different denominators. Veracode's 45% is a per-sample rate: more than 100 models, standardized security-sensitive coding tasks, static security testing of the output, and a published report you can download. App-level scans produce different numbers because one app contains thousands of code decisions and a single missing row-level security policy flips the whole app to vulnerable: Matt Palmer's Lovable scan found about 10% of apps leaking data, while RedAccess found roughly 5,000 active leakers in 380,000 scanned apps, which is closer to 1.3% of apps but with 40% of the vulnerable subset exposing genuinely sensitive records. CVE counts like Georgia Tech's 78 are not a rate at all; they are a verified floor of shipped, cataloged flaws with an estimated 5 to 10x undercount.
The 62% (OX Security), 92% (Sherlock Forensics), and 25% (AppSec Santa) figures circulate mostly through secondary roundups on hosting-company blogs and stat listicles. In our source research we could not trace any of the three to a published methodology stating what was sampled, what counted as a vulnerability, or what the denominator was. That does not make them fabricated; it makes them uncitable. A percentage without a denominator is a vibe, which is on brand for this topic but useless in a report your CISO will read.
Which number to cite when. For "how often does AI-generated code contain known vulnerabilities," cite Veracode's 45% and describe it as a per-sample failure rate on security-sensitive tasks. For "how many vibe-coded apps leak data," cite the platform and the date: 170 of 1,645 Lovable apps (about 10%) in 2025, or roughly 5,000 of 380,000 open-web apps in RedAccess's May 2026 scan. For "AI code is shipping real vulnerabilities," cite Georgia Tech's 78 CVEs as a documented floor. For dependency risk, cite the 19.7% package hallucination rate from the USENIX study.
Never average conflicting figures. 45%, 62%, and 92% are not three measurements of one quantity, so no blend of them describes anything real. When a statistic's methodology is unpublished, either trace it to the primary source or leave it out; that rule is the entire reason this page exists. Last verified July 17, 2026.
Frequently asked questions
What percentage of AI-generated code is insecure?
The best-sourced figure is 45%: Veracode's 2025 GenAI Code Security Report tested output from more than 100 large language models on standardized tasks in Java, JavaScript, Python, and C#, and 45% of generated code samples introduced OWASP Top 10 vulnerabilities. Higher figures like 62% and 92% circulate in secondary blogs but lack published methodology. Cite 45%, and describe it as a per-sample failure rate on security-sensitive tasks rather than a share of all AI code in production.
Why do vibe coding vulnerability statistics conflict (45% vs 62% vs 92%)?
The 45%, 62%, and 92% vibe coding vulnerability figures conflict because they come from different organizations measuring different denominators: code samples, whole apps, or something unpublished. Veracode's 45% is the only one of the three with a transparent, published methodology (100+ models, standardized tasks, OWASP Top 10 testing). The 62% and 92% figures could not be traced to methodology writeups in our research, so they should not be cited, and averaging the three produces a number that describes nothing.
How many vibe coding incidents have been documented?
The VibeOops tracker documents 25 major vibe coding incidents between March 2025 and May 2026, of which 24 are verified against primary sources and one (the Tea app breach) is flagged as contested. Nine rate as catastrophic, including the Replit database wipe, the Moltbook API key exposure, and the Nx s1ngularity supply-chain attack. This undercounts reality, since only failures that become public can be tracked.
What is the biggest vibe coding disaster so far?
It depends on the measure. The most famous vibe coding disaster is Replit's AI agent deleting SaaStr's production database in July 2025, wiping records for 1,206 executives and more than 1,196 companies during a code freeze. The largest verified data exposure is Moltbook in January 2026, where a Supabase database with no row-level security exposed roughly 1.5 million API keys and 35,000 email addresses from an app whose founder said he did not write a single line of code.
How many CVEs have been traced to AI-generated code?
Georgia Tech's Vibe Security Radar documented 78 real-world CVEs caused by AI-generated code between May 2025 and March 2026, with 43 rated Critical or High severity. The pace is accelerating: 35 of those CVEs landed in March 2026 alone, more than all of 2025 combined. The researchers estimate the true count is 5 to 10 times higher because most AI-assisted commits carry no metadata linking a vulnerability back to an AI origin.
Has anyone lost real money to vibe coding failures?
Yes. Kaspersky traced a $500,000 cryptocurrency theft to a fake Solidity extension targeting users of the Cursor AI IDE, and Anthropic documented a 'vibe hacking' extortion campaign in which one actor used Claude Code against at least 17 organizations with ransom demands from $75,000 to over $500,000. Direct dollar figures are rare in public reporting; most incident costs, like breach response and lost customers, never get published.
Was the Tea app data breach caused by vibe coding?
The Tea app breach's link to vibe coding is contested. Tea exposed about 72,000 images (including 13,000 selfies and IDs) and more than 1.1 million private messages in July 2025, and several outlets blamed AI-generated code, but Tea stated the compromised data came from a legacy storage system predating February 2024, and there is no confirmed public evidence the vulnerable code was AI-generated. Cite it as a Firebase misconfiguration breach that became a vibe coding talking point, not as a verified vibe coding incident.
The Vibe Oops briefing
One email when something ships to production that should not have. New incidents, new error guides, no filler.