Illustration: a laptop with code flying out as fireworks that turn into a dumpster fire, a chill surfer dude shrugging beside it, flat vector, warm reds/oranges
Vibe coding β the practice of describing software to an AI and letting it write the code while you, in the immortal words of the movement's founders, "forget the code even exists" β was supposed to democratize software. And to be fair, it did something remarkable: it let millions of people build things that work on the demo. The problem, as the growing pile of vibe coding disasters attests, is that software doesn't live on the demo. It lives in production, at 3 a.m., when the database is on fire and the logs are in a language nobody speaks.
The vibe coding promise: "just describe what you want." The vibe coding reality: you still need to know what you want, how computers work, and what can go wrong β you just also have to debug code you didn't write, in patterns you don't recognize, at 2x the normal confusion.
The Disaster Gallery
The vibe coding disasters are not hypothetical. They've been arriving steadily:
The security hole you can't see. Non-programmers shipping AI-generated backends routinely deploy with hardcoded API keys, no authentication, SQL injection vulnerabilities, and exposed admin panels. One widely-shared case: a founder's vibe-coded SaaS had its entire user database downloadable from an unprotected endpoint. The code "worked." It also worked for everyone else. It's prompt injection's quieter sibling: not an attacker exploiting the model, just the model exploiting your trust.
The bill that ate the startup. AI-written code is famously indifferent to efficiency. Infinite loops in serverless functions. N+1 queries that turn a $20 database into a $20,000 invoice. Unbounded retries against paid APIs. Traditional engineers learn cost-awareness through scars; the model has no scars, and neither does the person who prompted "make it work."
The bug nobody can fix. This is the signature vibe coding disaster. The app breaks. The user pastes the error into the AI. The AI rewrites the function. The app breaks differently. Repeat until the codebase is a geological formation β layers of AI-generated sediment, each fixing the last one's mistakes, none of it understood by anyone. Developers call this "code I didn't write." Vibe coders call it "my app." Same thing, different denial.
The AI hallucinations pipeline. Remember confidently wrong AI? Now imagine it with commit access. Vibe-coded projects regularly import nonexistent packages, call APIs that don't exist, and implement algorithms that sound right but compute wrong. The code reads beautifully. It just doesn't do anything. Reviewing it requires the expertise the whole movement claimed you didn't need.
Vibe coding is pair programming where your pair has read all of GitHub and understood none of it.
Why Vibe Coding Feels So Good (And Fails So Predictably)
The seduction is real and worth taking seriously. The first hour of vibe coding is magic: an idea becomes a working prototype before your coffee cools. For mockups, internal tools, and "is this idea even viable" experiments, it's genuinely a superpower. The 0-to-1 has never been faster.
The failure is structural, and it has a name: the expertise inversion. The easier the tool makes it to produce code, the more expertise you need to evaluate the code. Writing was never the bottleneck in software; knowing what's correct was. Vibe coding automates the typing and leaves the thinking β then tells you the thinking is optional. It is not optional. It was never optional.
This is the same dynamic as AI slop: when generation becomes free, judgment becomes the scarce resource, and the market hasn't priced judgment in yet. Every vibe-coded production system is a bet that nothing will go wrong. Some bets pay off. The disasters are the ones that didn't.
There's also a quieter, meaner failure: the learning trap. Junior developers who learn to code through the AI often never build the mental models β how the event loop works, what a race condition is, why the database is slow. They can produce; they can't diagnose. The industry is minting a generation of developers who can summon code but can't interrogate it. That's fine until the pager goes off.
The Honest Middle Ground
Vibe coding isn't going away, and it shouldn't β the productivity gains for experienced developers are real. A senior engineer with an AI pair programmer is genuinely 2-5x faster at the boring parts. The disaster stories almost all share one trait: no experienced human in the loop. The fix was never "don't use AI." The fix is the oldest rule in engineering:
1. Read the diff. Every line the AI writes goes past human eyes before it merges. No exceptions for "it looked fine." 2. Tests are non-negotiable. If you can't write a test for it, you don't understand it, and neither does the model. 3. Keep the blast radius small. Vibe-coded prototypes stay in staging. Production gets the boring, reviewed, understood version. 4. Know when to stop vibing. CRUD app? Vibe away. Payment processing, auth, crypto, medical? Hire the engineer. Some code has a blast radius measured in lawsuits.
The mature version of this movement won't be called vibe coding. It'll be called "software engineering, with really good autocomplete" β which, if you've been reading this publication, you know is our entire thesis. Spicy autocomplete is a fantastic intern and a terrible architect. Ship fast if you want. Just make sure someone on the team knows where the fire extinguisher is.
Enjoyed this? Get the next one first.
The Spicy Dispatch: one email a week, zero slop, unsubscribe anytime.
One email a week. Zero slop. Unsubscribe anytime.