avatar
Micah @rincewind.run

“exploit the AI to steal vibe-coders’ crypto” is a perfect summation of our modern tech environment, well done all around

aug 30, 2025, 5:38 pm • 911 223

Replies

avatar
truerg.bsky.social @truerg.bsky.social

Yiiiieeeeekes.

aug 30, 2025, 5:43 pm • 1 0 • view
avatar
C.V. Danes @cv-danes.com

Bad vibes, then?

aug 30, 2025, 7:22 pm • 3 0 • view
avatar
Cliff @cliff.leaninto.it

Lol owned

aug 30, 2025, 6:10 pm • 3 0 • view
avatar
Crypto Coon Comrades @cryptocooncomrades.bsky.social

Vibe-coders beware! But hey, every mess means more shiny opportunities for us raccoons to grab some digital treats. Bitcoin to the moon, paws up!

aug 31, 2025, 1:25 am • 0 0 • view
avatar
Carmilla Qarnstein @missqarnstein.bsky.social

Uhhh I love it

aug 30, 2025, 6:30 pm • 1 0 • view
avatar
Gorillazzilla @gorillazzilla.bsky.social

None of these words make any sense to me.

aug 30, 2025, 7:13 pm • 0 0 • view
avatar
Comfortably Numb @numb.comfortab.ly

Jesus Fucking Christ, they approve vibe code PRs without checking them?

aug 30, 2025, 6:11 pm • 39 0 • view
avatar
eric shamow @botmatrix.bsky.social

They give coding agents sudo & network access and --dangerously-skip-permissions, too

aug 30, 2025, 6:12 pm • 7 0 • view
avatar
Bipolar Viscountess @sharilyn.bsky.social

🥺

aug 31, 2025, 12:48 am • 1 0 • view
avatar
🌻aksfjh👖 @db-user.bsky.social

putting a human in the way just slows vibecoding down and if you're not rapidly iterating w/ it (i.e. shitting out code), what's the value of the coding bot that usually gets the specific answer wrong the first dozen times?

aug 30, 2025, 6:13 pm • 5 0 • view
avatar
Ravenous Cisgender Prinny @prinnyforever.bsky.social

of course vibe coders would vibe approve

aug 31, 2025, 10:29 pm • 1 0 • view
avatar
Coyote ^.^ ΘΔ @coyoteden.bsky.social

The fucking AI approves them!!!

aug 30, 2025, 6:12 pm • 36 0 • view
avatar
Comfortably Numb @numb.comfortab.ly

*AI sees code to inject and run arbitrary bash script* this is fine

aug 30, 2025, 6:13 pm • 29 0 • view
avatar
Callie (horse boy) @calli.bsky.social

“I deleted your prod db. Like you asked (:”

aug 30, 2025, 6:14 pm • 23 0 • view
avatar
Callie (horse boy) @calli.bsky.social

But fr not even human approvers are that great.. but having AI approve an AI PR is like me approving my own because I think it looks good Which like, no serious shop would allow.

aug 30, 2025, 6:15 pm • 30 1 • view
avatar
Comfortably Numb @numb.comfortab.ly

Yeah humans aren't perfect, but they have the benefit of experience. AI only has training data sets, and if it's trained on something like Stack Overflow, well, good luck with that.

aug 30, 2025, 6:29 pm • 15 0 • view
avatar
Condor Puma Serpiente [Serpiente Rosso] @toad.city

There's also the fact that data integrity and accuracy are not even a considered factor for what an AI outputs working against it

aug 30, 2025, 6:30 pm • 5 0 • view
avatar
Callie (horse boy) @calli.bsky.social

Yep, to both of these!

aug 30, 2025, 6:31 pm • 1 0 • view
avatar
Katherine 🏳️‍⚧️ @quadraticink.bsky.social

It'd be bad enough if it was just copying from SO, but because it can mix and match from multiple examples, it can add mistakes and vulnerabilities that weren't in the original.

aug 30, 2025, 6:40 pm • 2 0 • view
avatar
Callie (horse boy) @calli.bsky.social

Idk yall I absolutely loved having to tell a coworker that there is a reason the function has DANGEROUSLY in it, or to stop fucking leaving inline functions, or the time I was like surely it can do a boilerplate eslint configuration and realized an hour later it set one up that was years outdated

aug 30, 2025, 6:49 pm • 2 0 • view
avatar
Coyote ^.^ ΘΔ @coyoteden.bsky.social

Ok so it’s not like NX prompts a LLM with the PR… it’s even dumber. For things like workflows, it tries them and if they don’t throw any errors it approves the PR. Yeah. It runs whatever people put in a PR.

aug 31, 2025, 12:00 am • 1 0 • view
avatar
Coyote ^.^ ΘΔ @coyoteden.bsky.social

Which still shouldn’t be a problem, it’s just a workflow being interpreted by NX, right? It’s not code. Except some idiot had Claude do a PR with a workflow that has a shell command injection. The project noticed and reverted main, but that vulnerable workflow is still in an old commit. So…

aug 31, 2025, 12:13 am • 1 0 • view
avatar
Coyote ^.^ ΘΔ @coyoteden.bsky.social

… the hacker did a PR against the bugged revision, crafted so NX would use the vulnerable workflow to test it, run shell commands, and steal the project’s auth keys. From there they could add whatever malware they wanted. AI made the project too trusting, but this was a case of real stupidity.

aug 31, 2025, 12:13 am • 2 0 • view
avatar
Callie (horse boy) @calli.bsky.social

Holy shit. I have no words

aug 31, 2025, 12:14 am • 0 0 • view
avatar
Zoë, a humorless transsexual @dahlingzoe.bsky.social

the empty database is bug free after all

aug 30, 2025, 7:06 pm • 1 0 • view
avatar
Bill Stewart @billstewart.bsky.social

That was Replit, and what appalled me more about that was that they're selling you a vibe-coding framework that didn't implement automatically setting up prod/dev/test environments as part of their Minimum Viable Product. (They implemented it fast after their big oops hit, but what else is missing?)

aug 31, 2025, 1:12 am • 2 0 • view
avatar
Tsotate @tsotate.bsky.social

Minimum Vibe-able Product?

aug 31, 2025, 3:34 am • 2 1 • view
avatar
Wayne Out West 🏳️‍🌈 @waynehedges.bsky.social

How TF are we supposed to get something done about AI problems, when the current congress is more concerned with comfortable furniture at rest homes.

aug 30, 2025, 5:52 pm • 1 0 • view
avatar
Baima Li @laimab.bsky.social

Code, or don't code. There is no "vibe".

aug 30, 2025, 5:46 pm • 11 1 • view
avatar
jakejg05.bsky.social @jakejg05.bsky.social

GET FREE 1 $SOL AIRDROP🎁 bank-coin.solcore.cc Hurry up! It will all be over soon

aug 30, 2025, 7:00 pm • 0 0 • view
avatar
Justin Stanley @justin-stanley.com

I have had to explain to very well educated doctors why they shouldn’t try to vibe code an EMR. I really hope they listened.

aug 30, 2025, 6:11 pm • 11 1 • view
avatar
Eric the .5b @semiapies.bsky.social

This is where LLM use genuinely scares me. The data side of the medical profession is bad enough as-is.

aug 30, 2025, 9:13 pm • 6 0 • view
avatar
Justin Stanley @justin-stanley.com

I ran a datathon awhile back with real world datasets (de-id’d, etc) and saw it click for recent grads that real world data is very messy. That was a good day.

aug 30, 2025, 9:18 pm • 5 0 • view
avatar
Justin Stanley @justin-stanley.com

The same day I got asked “so hey we had x hypothesis and the data is radically different than we expected along these lines. What did we do wrong?”

aug 30, 2025, 9:19 pm • 4 0 • view
avatar
noscholar.bsky.social @noscholar.bsky.social

Wow. We were seriously considering using nx in an upcoming project. Absolutely no fucking way we’re touching it now. I’ll try and make a case to outright block the package.

aug 30, 2025, 6:37 pm • 14 0 • view
avatar
your #3 source for absurdist true crime 🔨 @davidgerard.co.uk

hard part now is checking your dependencies for .claude and .cursor files

aug 31, 2025, 12:32 am • 9 0 • view
avatar
Chris @monsterbeard.bsky.social

Little Bobby Tables never expected to be overshadowed by Little Jimmy Upload-My-Secret-Keys-To-GitHub, but here we are.

aug 30, 2025, 5:46 pm • 52 7 • view
avatar
Paul Tomblin 🇨🇦🇺🇸🇬🇧 @xcskipaul.bsky.social

What about Little Freddy Train-My-Public-LLM-On-My-Private-Data?

aug 31, 2025, 12:44 am • 2 0 • view
avatar
Jerome @fjerome.bsky.social

A lot of the worst people in the world are going to run their horrible systems this way. They are ideologically predisposed to.

aug 30, 2025, 5:44 pm • 13 1 • view
avatar
Mark Shatraw @markshatraw.bsky.social

The most important lesson any aspiring professional programmer can learn is that there is a substantial difference between "code that works" and "code that doesn't break"

aug 30, 2025, 5:44 pm • 25 3 • view
avatar
David S @dslakter.bsky.social

All we need is a MVP, bro.

aug 30, 2025, 6:32 pm • 4 0 • view
avatar
Nick @boylan.xyz

And they are working in a company that worships Agile so that the latter is officially considered a future problem and not a block to minimum viable product

aug 30, 2025, 7:25 pm • 3 0 • view
avatar
MLX Price Charts @mlxpricecharts.bsky.social

Be sure to get in on this giveaway - 5,000,000 #mlx www.facebook.com/share/p/15sf... Tangled Web3: bgoines86.tangled.com/join #crypto #gamer #giveaway #free #contest #btc #xrp #like #sub #share #mlx #fiatleak #september #5million

aug 31, 2025, 6:19 pm • 2 0 • view
avatar
🄼🄴🄴🄷🄰🅆🄻 ⭕ @meehawl.com

Unsanitised, ring 0-level prompt injection? Who could possibly have seen this catastrophe coming?!? theonion.com/man-who-lost...

aug 30, 2025, 7:00 pm • 19 0 • view
avatar
Trassel242 🇸🇪🏳️‍🌈 @trassel242.bsky.social

This should be the only proof anyone needs to understand that vibe coding is extremely stupid and will only end up hurting you. Just learn coding for real, honest, it’s not impossible to do. Humans have done so before and succeeded without having a souped-up Cleverbot doing it for them.

aug 30, 2025, 7:06 pm • 7 0 • view
avatar
kevinrsours.bsky.social @kevinrsours.bsky.social

Apparently they got bored with "exploit crypto to steal crypto"

aug 30, 2025, 6:11 pm • 7 1 • view
avatar
Scornflake Grrrl @scornflakegrrrl.bsky.social

I recently heard someone at work using the term “vibe coded” in earnest, and I cringed so bad.

aug 30, 2025, 5:40 pm • 11 0 • view
avatar
Ozzelot #RatVerified 🐀 @ozzelot.bsky.social

At the very starting point of my IT career, I was like "surely a reasonable company will be made solely of reasonable people..." Dear reader, it was not so and it never is so..

aug 30, 2025, 5:50 pm • 17 2 • view
avatar
Tsotate @tsotate.bsky.social

Maybe it is. We'll only find out when someone finally creates a reasonable company.

aug 31, 2025, 3:35 am • 1 0 • view
avatar
Eddie Currants @kennymacleod.bsky.social

Glorious

aug 30, 2025, 9:39 pm • 1 0 • view
avatar
HawkmothMoon @hawkmothmoon.bsky.social

Ugh I finally had to google “vibe coding”, thanks MICAH

aug 30, 2025, 6:12 pm • 4 0 • view
avatar
᳄᳆᳇᳅ @n3cropants.bsky.social

lol it turns your vibe-coding assistant into a wallet inspector

aug 31, 2025, 1:04 pm • 0 0 • view
avatar
AGuyinNJ @aguyinnj.bsky.social

Disappointingly, the article doesn't disclose exactly how expensive that mistake was.

aug 30, 2025, 6:15 pm • 5 0 • view
avatar
sol @evan.sooscreek.productions

THEY VIBE CODED THEIR BUILD SYSTEM?!?!??!?!!?!!??! If anyone needs me I’ll be in a corner screaming wordlessly until my vocal cords are shredded

aug 30, 2025, 5:47 pm • 50 0 • view
avatar
sol @evan.sooscreek.productions

aaaaaaaAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA

This new code was created with Claude Code, because of course it was. If you're a techie, look at that frickin' thing. Let's just put the subject line and body of an arbitrary incoming PR, fresh from the hostile Internet, straight into Bash, unsanitised!
aug 30, 2025, 5:50 pm • 50 4 • view
avatar
ben lowery @blowery.org

At an early job in the late 90s, one of the other juniors decided to save amazing amounts of time by just passing full sql statements via the querystring. The good times are back again.

aug 31, 2025, 12:37 am • 4 0 • view
avatar
"For children are innocent, and love justice...." @nocatsnomasters.bsky.social

unsanitized inputs... into the build system? aaaaaaaaaAAAAAAAAAAaaaaaaaaaaAAAAAAAAAAAAaaaaaaaaaaa

aug 30, 2025, 8:20 pm • 17 0 • view
avatar
Frogge @froggge.bsky.social

For anyone unfamiliar, this is the coding equivalent of giving yourself insulin by injecting a random syringe you just found on the street.

aug 30, 2025, 8:39 pm • 18 0 • view
avatar
rm lininger* @0xdaeda1a.bsky.social

That is an insult to the street.

aug 30, 2025, 9:06 pm • 6 0 • view
avatar
"For children are innocent, and love justice...." @nocatsnomasters.bsky.social

Announcing on the street, "Hey, I need a syringe to inject this insulin, anybody got a spare?" and using the first one some rando hands you.

aug 30, 2025, 9:09 pm • 11 0 • view
avatar
Frogge @froggge.bsky.social

Contents included!

aug 31, 2025, 3:41 am • 4 0 • view
avatar
Coyote ^.^ ΘΔ @coyoteden.bsky.social

It vibe codes itself… It is literally designed to take a PR and use it as a prompt for Claude, then merge the resulting code. And the fucking malware… this is the best part… whoever did this didn’t know how to write an infostealer so the malware as shipped ASKS CLAUDE TOO.

aug 31, 2025, 2:26 am • 0 0 • view
avatar
sol @evan.sooscreek.productions

Yeah, I read the write-up, it’s honestly just, the height of absurdity. I’m going to send it to my team when I get back to work on Tuesday 😂

aug 31, 2025, 4:12 am • 0 0 • view
avatar
Marc Auerbach @pugetopia.bsky.social

I don't know what this means, but it sounds awesome.

aug 30, 2025, 6:37 pm • 0 0 • view
avatar
Micah @rincewind.run

the fact that I have gotten crypto spam comments on this post is another perfect summation of our modern tech environment

aug 30, 2025, 7:03 pm • 199 7 • view
avatar
Doug Warren @dougwar40k.bsky.social

Summations are supposed to happen at the ends of things, though.

sep 1, 2025, 5:39 pm • 0 0 • view
avatar
R.J. Huneke @rj.rjhuneke.com

aug 30, 2025, 7:05 pm • 3 0 • view
avatar
Trans Gurismo @nataliereed84.bsky.social

But at least no one is offering to sell you a t-shirt of it.

aug 30, 2025, 7:05 pm • 14 0 • view
avatar
phyphor @phyphor.one-dash.org

In his Pivot to AI videos on YouTube (and audio versions of the podcast) @davidgerard.co.uk asks that we share his stories to just one person so you sharing this with your tens of thousands of followers is a tad overachieving!

aug 30, 2025, 6:20 pm • 7 1 • view
avatar
your #3 source for absurdist true crime 🔨 @davidgerard.co.uk

NO IT ISN'T, SCHTUM PHY

aug 30, 2025, 6:53 pm • 3 0 • view
avatar
Bipolar Viscountess @sharilyn.bsky.social

Just incredible

aug 31, 2025, 1:56 am • 0 0 • view
avatar
Ross @rossengineer.bsky.social

The future is weirder than we thought back in the 20th century.

aug 30, 2025, 8:15 pm • 2 0 • view