Vibe Coding Is the New Cocaine

Everybody is vibe coding. And honestly, if you’re not, maybe you should be.

I say that knowing full well it might make me the dealer getting high on my own supply. Full disclosure: I have never actually done cocaine. But I have seen The Wolf of Wall Street and lived through the programmatic gold rush, so I know a speculative frenzy when I see one. I don’t know exactly where this drug analogy begins and ends, but stay with me, because the metaphor holds up better than it should.

Vibe coding is intoxicating. You describe what you want, the model builds it, and something that used to take a sprint ships in an afternoon. It will have you feeling like the king of the world, like the smartest person in the room, like nobody can stop you. The dopamine is real. The productivity is real. The demos are real. I have seen non-engineers stand up working tools in a day that would have sat in a backlog for a quarter. That is not hype. That is a genuine shift in who gets to build.

So no, this is not a post telling you to quit. Everyone should be experimenting with this. The people learning to build with AI right now are going to lap the people who are waiting for permission.

But here is where the high wears off.

Where does the intelligence live?

Picture how most of these tools actually get built. Someone on your team opens a chat with an LLM on their personal laptop. Over days or weeks, that conversation becomes the tool. The prompts, the corrections, the context, the reasoning behind every decision, all of it lives in a chat thread on a machine you do not control.

Then that person leaves the company.

The tool might still run. But the intelligence that built it walks out the door. The chat that holds the “why” behind the code sits on a personal computer somewhere, and nobody left in the building can explain how the thing works, let alone fix it or extend it. You did not lose an employee. You lost the source of truth for a system your team now depends on.

We used to call this key person risk. Vibe coding puts it on steroids, because the documentation was never written down in the first place. It was a conversation.

Who is servicing these things?

Here is the second problem, and it is the one nobody budgets for.

Models change constantly. Capabilities expand, behaviors shift, APIs evolve, pricing moves. The agent that worked beautifully in March may behave differently in July because the model underneath it changed. In a world where the foundation is moving on a near daily basis, every vibe coded tool is a living system that needs care.

Who is doing that maintenance at your company? Be honest.

For most organizations, the answer is “whoever built it, in their spare time.” That is not a strategy. Keeping agents current, tested, and reliable as the AI landscape evolves is not a part time job for somebody. It is a full time function. And if you are stacking up vibe coded tools without assigning that function to anyone, you are not building capability. You are building deferred chaos.

The tab always comes due

None of this is hypothetical, and the receipts are starting to pile up publicly.

Start with Moltbook, the cautionary tale of this cycle. Moltbook launched in late January 2026 as an AI social network built for autonomous agents, and its founder proudly said he did not write a single line of code. Within three days, security researchers at Wiz discovered the app had exposed its entire production database to the public internet: roughly 1.5 million API authentication tokens, 35,000 email addresses, and private messages, all traced back to a misconfigured database deployment that the AI generated and no human reviewed. The build took days. The breach took less.

And there is a quieter pattern repeating underneath the headlines: a vibe coded app ships with an API key exposed where anyone can find it, someone finds it, and the token bill arrives like a bar tab from a night nobody remembers. In one reported case, attackers found exposed keys in a vibe coded site and burned through API credits overnight, through wide open endpoints with no authentication, no rate limits, and no validation. An unplanned expense nobody approved, nobody budgeted, and nobody noticed until the invoice landed. And I will just say this: I have seen versions of this story land a lot closer to home than a headline. Nobody plans for the line item called “someone else used our AI.”

If anecdotes are not enough, the data is unambiguous:

Security researchers at Escape scanned 5,600 publicly deployed vibe coded applications and found more than 2,000 vulnerabilities and over 400 exposed secrets, including API keys, credentials, and tokens. That is roughly one in three apps shipping with a serious, exploitable flaw that anyone could find.

GitGuardian reported that hardcoded secrets exposed in public GitHub commits jumped 34 percent year over year in 2025, the largest single year increase on record. Worse, 64 percent of credentials exposed years earlier were still valid and unrevoked as of January 2026. So the leaks are not just happening faster. They are not getting cleaned up, because remember, nobody owns cleanup.

And a December 2025 study of open source repositories found that AI assisted pull requests introduced 2.74 times more security issues than human authored code. The very thing that makes vibe coding feel magical, accepting output you did not read, is the thing quietly stacking up risk.

Speed is not free. It is just billed later, with interest.

The enterprise question

So this is what leaders should actually be asking. Not “should my team be vibe coding” but “how does all this building play into my enterprise level tools?”

As agents and internal tools multiply across your organization, three questions decide whether you get compounding value or compounding risk:

Who provides the layer of governance across everything being built? Who harnesses these agents so they work together instead of sprawling in silos? And who ensures they have the right context for your business and your industry, so they behave like insiders instead of clever generalists?

There is a fourth question, and it is the one your CFO will ask first: who is watching the meter?

The entire promise of AI was supposed to be OpEx savings. Fewer hours on manual work, leaner operations, more output per dollar. But when every team is vibe coding its own agents on its own keys, you do not get savings. You get spend fragmented across dozens of invisible line items: duplicate agents doing the same job in three departments, tokens burning on workflows nobody optimized, subscriptions and API accounts no one remembers opening. The math only works if someone is accountable for driving cost consumption down, consolidating usage, retiring redundant agents, and measuring what each one actually returns. Otherwise you have not automated your operating expenses. You have just re-billed them under a cooler name.

Because an agent without governance is just risk that ships fast. And orchestration without governance is a liability.

Keep the high. Lose the crash.

The answer is not to ban vibe coding. It is to give it a home. A system of record for what gets built. Governance that travels with the agents instead of living in someone’s chat history. Context that belongs to the company, not to a laptop.

Above all, it means ensuring you have a serviceable system. One that someone is caring for. One that someone is in charge of. One that someone takes ownership of, by name, as their actual job. If you cannot point to the person responsible for keeping an agent alive and current, you do not have a tool. You have a countdown.

And here is the payoff for doing it right: governance is not just how you avoid the breach headline. It is how you actually bank the savings. When your agents live in one governed system instead of fifty shadow accounts, you can see consumption, cut what is redundant, optimize what is wasteful, and negotiate as one buyer instead of a hundred credit cards. The companies that win this era will not be the ones that built the most agents. They will be the ones whose agents demonstrably drove operating expenses down, quarter after quarter, and could prove it.

Speed is a gift. Trust is what lets you use it. Get both, and the high never has to come with a crash.

Aubriana Alvarez Lopez is Co-Founder and CMO of Agnitio, the vendor-neutral control plane for agentic media and advertising. Want to know how exposed your organization actually is? Take the Vibe Check, our free 10-question agent governance audit: ten yes-or-no questions, five minutes, one honest score. Take the Vibe Check at go.agnitio.ai/vibe-check.

Learn More

We know, we’re excited too!

Ready when you are! Drop your email to get started.

Get In Touch

Agnitio.AI © 2026 All Rights Reserved.

Privacy Policy

Terms of Use