Short answer: Vibe coding is building software by describing what you want in plain language to an AI coding tool, running what it generates, and fixing what breaks, without reading or writing most of the code yourself. Andrej Karpathy coined the term on X on February 2, 2025. It's great for prototypes and throwaway tools, risky for anything touching real user data or money unless someone who understands the code reviews it.
If you've scrolled tech Twitter, LinkedIn, or Discord in the past year, you've seen the phrase everywhere: "I vibe coded this app in a weekend." Some people use it like a badge of honor. Others use it as an insult, shorthand for sloppy, insecure software nobody actually understands. Both camps are talking about the same thing. They just disagree on whether it's good.
This post is the plain-English version. Where the term came from, what it actually means, how it's different from "AI-assisted engineering" (a phrase people often use interchangeably but shouldn't), where it shines, where it quietly wrecks things, and how you, a Filipino beginner with a laptop and curiosity, can start doing it responsibly this week.
Who coined "vibe coding," and what did they actually say?
Andrej Karpathy, former Tesla AI director and OpenAI founding member, posted on X on February 2, 2025: "There's a new kind of coding I call 'vibe coding', where you fully give in to the vibes, embrace exponentials, and forget that the code even exists." He described his own workflow as talking to Cursor's Composer (with Claude models under the hood), sometimes even using voice-to-text, and just accepting what came back: "I just see stuff, say stuff, run stuff, and copy-paste stuff, and it mostly works."
That's the whole origin story. It wasn't a manifesto or a framework. It was a throwaway tweet describing a way of working that a lot of developers immediately recognized in themselves. On November 6, 2025, Collins Dictionary named "vibe coding" its Word of the Year, citing it as evidence of how AI is reshaping software development, and by 2026 it had become the default term for "building with AI without deeply reading the code."
What vibe coding actually is (and isn't)
Vibe coding is not just "using AI to help you code." Every developer who autocompletes with Copilot or asks ChatGPT to explain a regex is using AI assistance, but they're still reading, understanding, and owning every line before it ships. That's AI-assisted engineering.
Vibe coding is specifically the mode where you stop verifying. You describe the outcome, the AI writes the implementation, you run it, and if it looks right, you move on. Karpathy's own phrase, "forget that the code even exists," is the key. The code becomes a means to an end, not a thing you're accountable for line by line.
| Vibe coding | AI-assisted engineering | |
|---|---|---|
| Who reads the generated code | Rarely, or only when something breaks | Almost always, before merging |
| Best for | Prototypes, internal tools, one-off scripts, landing pages | Production systems, anything with real users or data |
| Risk profile | High if shipped as-is | Managed, because a human still owns correctness |
| Mental model | "Does it work when I click around?" | "Do I understand why it works?" |
| Typical user | Beginner, founder testing an idea, hobbyist | Professional engineer using AI as a force multiplier |
Neither one is "better" in the abstract. They're suited to different jobs, and the mistake is using vibe coding's speed for a job that needed engineering's rigor.
The typical vibe coding loop
Almost everyone who vibe codes ends up in some version of this cycle:
- Prompt. Describe what you want in natural language, such as "make a landing page for my tutoring service with a signup form that emails me," inside a tool like Cursor, Claude Code, v0, Lovable, or Replit Agent.
- Run. Execute the generated code, usually with one click or command, and see what actually renders or happens.
- Read (a little). Skim the output, the UI, maybe the error message. Most vibe coders read outcomes, not implementations.
- Fix. If something's broken or off, you don't debug the code yourself. You describe the symptom back to the AI ("the button doesn't submit the form") and let it patch itself.
Repeat until it works well enough. The loop is fast, which is exactly why it's addictive and exactly why it's dangerous when the stakes go up. Speed hides the fact that nobody in the loop necessarily understands what got built.
Where vibe coding genuinely works
- Prototypes and MVPs. Testing whether an idea resonates before you invest real engineering time. If it flops, you lost a weekend, not months.
- Internal tools. A script that reformats a spreadsheet for your team, a Slack bot that pings you when a form is submitted, a dashboard only three people will ever see.
- Landing pages and marketing sites. Static or mostly-static pages with no sensitive data flowing through them are close to the ideal vibe coding target.
- Learning by building. For a total beginner, vibe coding something that runs is more motivating than reading a textbook chapter on syntax. It's how a lot of our own AI Builder Cohort members get their first working app.
- Hackathons and sprints. Events like our own Ship Happens! 48-hour build sprint are built for exactly this speed-over-polish tradeoff.
Where it breaks, and why "it works on my machine" isn't enough
The moment real user data, payments, or authentication enter the picture, the risk profile changes completely. This isn't hypothetical. In a documented 2026 incident, security journalists reported that a broken-access-control flaw in Lovable's API let anyone with a free account pull other users' profiles, source code, and database credentials in as few as five API calls. Projects created before November 2025 were affected. One confirmed case involved a Danish nonprofit, Connected Women in AI, whose exposed records included names, job titles, LinkedIn profiles, and Stripe customer IDs tied to individuals at Accenture Denmark and Copenhagen Business School. Separately, and more broadly, employees at companies including Nvidia, Microsoft, Uber, and Spotify reportedly had Lovable accounts tied to projects on the affected platform, which is a sign of how widely used the platform was, not a confirmed breach of those companies' own data. The flaw was reported on March 3, 2026, and stayed unpatched on existing projects for 48 days before wider disclosure. Separately, a May 2026 scan by security firm RedAccess of roughly 380,000 apps built on vibe-coding platforms found about 5,000 leaking sensitive data, including medical records and financial information, mostly traced back to missing or misconfigured backend access controls; we're citing this scan via a secondary summary of RedAccess's findings, not RedAccess's own original report, so treat the exact figures as reported-through-an-intermediary rather than primary-source-verified.
A few real categories of risk that show up again and again in vibe-coded apps, based on incidents like these:
- Exposed API keys and secrets. AI tools will happily hardcode a key into client-side code or commit it straight into a public repo if you don't tell them not to, because the model doesn't inherently know which values are secret.
- Missing database access rules. Supabase's own documentation states plainly that a table in an exposed schema without row-level security enabled is readable and writable by any role that has been granted access to it, and it explicitly instructs developers to enable row-level security on every table in an exposed schema. An AI coding tool generating a table via raw SQL or a migration has no built-in reason to add that protection unless it's told to, which is exactly the kind of gap behind the Lovable incident above.
- No input validation. Forms that trust whatever the user (or an attacker) sends, because nobody asked the AI to sanitize or validate it.
- Silent scale failure. Code that works fine for the ten people who tested it and quietly falls over at a hundred concurrent users, because nobody load-tested it or thought about database indexes.
- Unreviewed dependencies. AI tools sometimes pull in packages that are outdated, abandoned, or outright malicious, and a vibe coder who never opens
package.jsonnever notices.
None of these are hypothetical edge cases. They're the predictable result of removing the "someone understands this" step from software that used to require it.
How to vibe code responsibly
You don't have to choose between "move fast" and "be safe." A few habits close most of the gap:
- Match the tool to the stakes. Vibe code the landing page. Do not vibe code the payment flow without review.
- Ask the AI to explain security-sensitive parts. Before shipping anything with a login, a database, or a form, literally prompt: "explain what could go wrong here from a security standpoint" and read the answer.
- Never let secrets live in code you didn't write yourself. Use environment variables, and ask the AI explicitly to keep keys out of anything that goes into a public repo or ships to the browser.
- Turn on access rules by default. If you're using Supabase, Firebase, or similar, treat "did I lock down my database" as a non-negotiable checklist item before launch, not an optional polish step. Our AI engineer survival guide to Supabase and MCP walks through this in detail.
- Get a second pair of eyes before anything public. Even a non-technical friend clicking around can catch obvious holes; a developer friend reviewing the security-sensitive bits catches the rest.
- Know when to graduate to real engineering. If your side project starts making money, storing real people's data, or gets enough traffic to matter, that's the signal to either learn the underlying skills or bring in someone who already has them.
How Filipino beginners can start this week
You don't need a computer science degree, a paid course, or expensive hardware to try this. Here's a realistic starting point:
- Pick a free tool. Claude Code, Cursor, or Lovable all have usable free tiers. Start with whichever one your friends already use, so you have someone to ask when you're stuck.
- Build something you actually want. Not a to-do app tutorial. Something for your own life. A tracker for your sari-sari store's inventory, a simple site for your tita's small business, a personal portfolio.
- Join our free 7-day challenge. Ship Your First Project is built exactly for this: a structured week that gets you from zero to a live, shipped project, vibe coding included.
- Read the code out loud at least once. Even if you don't fully understand it, the act of reading what the AI wrote, instead of only running it, starts building the instinct you'll need later.
- Find a community. Our Discord has people at every stage, from total beginners to working AI engineers, who will tell you honestly if something you built has a hole in it. That feedback loop is worth more than any tutorial.
Vibe coding isn't a shortcut around learning to build software. It's a genuinely new way of building it: faster, more accessible, and forgiving of not knowing syntax by heart. Used well, it's how a lot of Filipinos are shipping their first real projects in 2026. Used carelessly, it's how side projects turn into cautionary tales. The difference isn't the tool. It's whether you know which mode you're in.
Frequently asked questions
Who invented the term "vibe coding"?
Andrej Karpathy, former Tesla AI director and an OpenAI founding member, coined it in a post on X on February 2, 2025, describing a workflow where he prompted an AI coding assistant and accepted its output without closely reading the code.
Is vibe coding the same as AI-assisted coding?
No. AI-assisted coding is any use of AI to help write software, and the developer still reviews and understands the code before shipping it. Vibe coding specifically means skipping that review step and trusting the AI's output based on whether it appears to work.
Can beginners with zero coding experience vibe code?
Yes, that's a big part of why the term spread. Tools like Lovable, v0, and Claude Code let someone describe an app in plain English and get a working result, which is why vibe coding has become a common entry point for non-programmers in the Philippines and everywhere else.
Is vibe coding safe for real businesses?
Only with review. Vibe coding is fine for prototypes, internal tools, and low-stakes projects. Anything touching customer data, payments, or authentication needs a human who understands the code, or at minimum a security-focused review, before it goes live.
What tools do people use for vibe coding?
Common tools in 2026 include Cursor, Claude Code, v0 by Vercel, Lovable, Replit Agent, and Bolt. Our comparison of Cursor, Claude Code, v0, and Lovable breaks down which one fits which situation.
What's the difference between vibe coding and agentic coding?
Vibe coding is conversational and stays in the loop with you: you prompt, the AI generates, you glance at the result, and you steer the next prompt, often without reading the implementation closely. Agentic coding refers to AI agents working more autonomously toward a goal, planning out subtasks, writing and running code, testing it, and iterating with less step-by-step human steering. In practice the two overlap a lot, since many "vibe coding" tools in 2026 also have agent modes, but the key difference is how much a human is actively steering each individual step.
Will vibe coding replace software engineers?
Not based on what's happened so far. It's changed what beginners and non-engineers can build alone, and it's sped up how professional engineers work, but the risk categories above (security, scale, data integrity) are exactly the areas where experienced engineering judgment still matters most.
Sources
- Andrej Karpathy on X, February 2, 2025, the original "vibe coding" post.
- Collins' Word of the Year 2025: AI meets authenticity as society shifts, Collins Dictionary, November 6, 2025.
- Vibe coding, Wikipedia, definition, timeline, and documented security incidents.
- Lovable security crisis: 48 days of exposed projects, closed bug reports, and the structural failure of vibe coding security, The Next Web, 2026.
- A scan of 380,000 vibe-coded apps found 5,000 leaking sensitive data, RedAccess study summary, May 2026.
- Row Level Security, Supabase Docs, on tables in an exposed schema without RLS being readable and writable by any role with a grant on them, and Supabase's own instruction to enable RLS on every such table.
- Vibe Coding vs. Agentic Coding: Fundamentals and Practical Implications of Agentic AI, arXiv.
- Our AI engineer survival guide to Supabase and MCP