Skip to content
All posts

Vibe CodingAI CodingApp Development

What Is Vibe Coding? Meaning, Origin and Real Risks

Robin Faraj

Vibe coding is building software by describing what you want to an AI model in plain language, running whatever it produces, and steering by the result instead of reading the code. Andrej Karpathy coined the term in February 2025 for exactly that: accept the AI's changes, paste back the errors, and "forget that the code even exists."

That is the strict meaning. In everyday use the term has stretched to cover almost any software built with AI help, which is why people argue about whether it is "real coding". Both meanings are useful, and they lead to very different results once an app has real users, real data and someone's money in it.

This guide covers where the term came from, what it means now, how the loop works in practice, where it fails, and how to vibe code something that survives contact with the public.

Where the term came from

On February 2, 2025, Andrej Karpathy, a founding member of OpenAI and former director of AI at Tesla, posted this on X (original post):

There's a new kind of coding I call "vibe coding", where you fully give in to the vibes, embrace exponentials, and forget that the code even exists. It's possible because the LLMs (e.g. Cursor Composer w Sonnet) are getting too good. Also I just talk to Composer with SuperWhisper so I barely even touch the keyboard. I ask for the dumbest things like "decrease the padding on the sidebar by half" because I'm too lazy to find it. I "Accept All" always, I don't read the diffs anymore. When I get error messages I just copy paste them in with no comment, usually that fixes it. The code grows beyond my usual comprehension, I'd have to really read through it for a while. Sometimes the LLMs can't fix a bug so I just work around it or ask for random changes until it goes away. It's not too bad for throwaway weekend projects, but still quite amusing. I'm building a project or webapp, but it's not really coding - I just see stuff, say stuff, run stuff, and copy paste stuff, and it mostly works.

Read it again and notice how specific it is. He does not read the diffs. He pastes errors back without comment. He works around bugs the model cannot fix. And he scopes it himself: "not too bad for throwaway weekend projects." Karpathy is a very experienced programmer. This was someone who could read every line choosing not to, for fun, on projects he could throw away.

Simon Willison's blog post quoting Andrej Karpathy's original vibe coding post in full, with "forget that the code even exists" and "throwaway weekend projects" in bold

Simon Willison quoting Karpathy's post in full in March 2025, with his own emphasis on the two phrases that define it. Source

A year later, Karpathy called it "a shower of thoughts throwaway tweet that I just fired off without thinking", which somehow "minted a fitting name at the right moment for something that a lot of people were feeling at the same time."

What vibe coding means now

The term escaped its definition within weeks. By March 2025, Simon Willison was already warning that people were applying "vibe coding" to all forms of code written with AI assistance, and he pinned his own meaning down as "building software with an LLM without reviewing the code it writes."

The general public went with the broad meaning anyway. In November 2025, Collins named "vibe coding" its word of the year for 2025, describing it as software development that turns natural language into computer code using AI. Collins lexicographers pick the word by tracking usage in the 24-billion-word Collins Corpus, and "vibe coding" beat a shortlist that included "clanker", a slang insult for AI and robots.

Infosecurity Magazine reporting that Collins Dictionary Word of the Year 2025 is vibe coding, described as using large language models to turn natural language prompts into computer code

Infosecurity Magazine on the Collins pick, November 2025: the dictionary sense is "AI turns your prompts into code", with nothing about whether you read it. Source

So when someone asks what vibe coding means today, there are two honest answers:

  • The narrow meaning (Karpathy, Willison): you let the AI write the code and you do not review it. You judge the app only by whether it seems to work.
  • The broad meaning (Collins, most of the internet): any software made by prompting an AI in plain language, whether or not anyone reads the output.

Karpathy himself has since drawn a line between the two. In the same anniversary post he wrote that programming via LLM agents "is increasingly becoming a default workflow for professionals, except with more oversight and scrutiny," and that his favorite name for that careful version is "agentic engineering": you orchestrate agents that write the code, and you act as the oversight.

How vibe coding works in practice

Strip away the tools and every vibe coding session is the same four-step loop.

  1. Describe. You tell the AI what you want in plain words. "A habit tracker with a streak counter and a reminder at 8pm." Later, much smaller asks: "make the button bigger", "the list is empty after I log in".
  2. Run. The tool writes or edits files and you run the result: a browser preview in Lovable or Bolt, a simulator or your own phone for a mobile app, a dev server for Cursor or Claude Code.
  3. React. You look at what happened. If it looks right, you move on. If there is an error, you paste the error back. If it looks wrong, you describe what is wrong.
  4. Repeat. Until the thing on the screen matches the thing in your head.

What is missing from that loop is the part of traditional programming where someone reads the code, decides whether it is correct, and understands why. In pure vibe coding the only test is "does it look like it works?" That is a fine test for a layout and a bad test for things you cannot see: who can read which database rows, whether a payment was actually verified, what happens when two people use the app at once.

Is vibe coding real coding?

It depends on which meaning you use, and the distinction matters more than the label.

Traditional codingVibe coding (strict)AI-assisted engineering
Who writes the codeYouThe AIMostly the AI
Who reads the codeYou and reviewersNobodyYou, or tests and checks you trust
How you know it worksTests, review, running itIt looks right on screenTests, review, running it
Speed to a first demoSlowestFastestFast
Good forAnything, if you have the timePrototypes, personal tools, throwaway projectsApps with users, data and payments

Willison's test is the clearest one we know. His golden rule:

Simon Willison's golden rule: he won't commit any code to his repository if he couldn't explain exactly what it does to somebody else

Willison's line between vibe coding and software development: if you reviewed it, tested it and can explain it, the LLM is "immaterial". Source

By that standard, vibe coding in the strict sense is not real coding, and its inventor said as much ("it's not really coding"). AI-assisted engineering is. The tools are identical. The difference is whether a human, or a test suite a human trusts, checks the output before it reaches users.

Professional developers mostly sit on the engineering side. In the 2025 Stack Overflow Developer Survey, 72.2% of respondents said vibe coding is not part of their professional work and another 5.3% said so emphatically, even though most of them use AI tools.

Where vibe coding works

The honest list is longer than critics admit.

  • Prototypes and demos. Getting an idea onto a screen in an afternoon, to show a co-founder or test whether anyone cares, is where vibe coding is unbeatable.
  • Personal tools. A script that renames your photos, a dashboard only you use. If it breaks, the only person affected is you.
  • Learning by doing. Seeing a working version of something, then asking the AI why it works, is a good way into programming.
  • Throwaway projects. Exactly what Karpathy described. Weekend experiments you will delete.

The common thread: low stakes, one user, no sensitive data, nothing that charges money.

Where it breaks

The problems start when a vibe coded app gets users. They cluster in three places.

Security

AI models write code that runs long before they write code that is safe. Veracode tested more than 100 large language models on security-relevant coding tasks in Java, Python, C# and JavaScript for its 2025 GenAI Code Security Report.

Veracode's 2025 GenAI Code Security Report: 45% of code samples failed security tests and introduced OWASP Top 10 security vulnerabilities into the code

Veracode's headline finding, July 2025. The same report found security pass rates stayed flat as models got better at writing code that compiles. Source

In the same report, the models failed to defend against cross-site scripting in 86% of relevant samples, and security performance "remained flat, regardless of model size or training sophistication." Newer models write cleaner code. They do not write noticeably safer code.

The real-world version of this is usually a database left open. In 2025, a researcher disclosed CVE-2025-48757: Lovable-generated projects could ship with insufficient row-level security on their Supabase database, letting anyone read and sometimes write data such as user details, API keys and payment status (write-up). Lovable disputes the CVE on the grounds that each customer is responsible for protecting their own app's data, and that dispute is the point: someone has to check those policies, and in a pure vibe coding loop nobody does, because an open database looks exactly like a working one.

Maintainability

Karpathy named this one himself: "The code grows beyond my usual comprehension." That is fine for a weekend. It is a problem in month three, when a change in one place breaks something in another and neither you nor the AI can explain why. The most common complaint in the Stack Overflow survey, from 66% of developers, was "AI solutions that are almost right, but not quite." Almost-right code in a codebase nobody understands is how projects stall at 80% done.

There is also no guarantee the loop is faster. METR's 2025 randomized study found experienced open-source developers took 19% longer with AI tools while believing they were faster. METR has since said that number is out of date and its newer data is unreliable in both directions, so treat it as a warning about self-perception rather than a verdict on AI.

Production

A demo has one user who forgives everything. A real app has to handle sign-in for strangers, deleting accounts, payments that are verified on a server instead of trusted from the device, push notifications, crash reporting, and for mobile, Apple and Google's review rules. None of that shows up in the "does it look right" loop until a reviewer, a user or an attacker finds it. Our guide on publishing to the App Store covers the review side.

The tools, in one paragraph

Vibe coding tools come in two shapes. Browser builders like Lovable, Bolt and Replit host everything for you and are the fastest way to a web prototype. Coding agents like Cursor, Claude Code and Codex work on a real codebase on your machine, which is what you want once the code needs to be yours, tested and shipped to the app stores. We compare them in the best vibe coding tools, and Codex vs Claude Code goes deeper on the two agents.

How to vibe code something that survives real users

You can keep the speed of vibe coding and lose most of its failure modes. The trick is to stop asking the AI to invent the hard parts, and give it a codebase where those parts already exist, are tested, and come with written instructions.

First, start from a codebase with structure. An agent starting from nothing makes a hundred architectural decisions you never see, and makes them differently each session. An agent starting from a codebase with one convention per problem follows the conventions it finds.

Second, give the agent tests it can run. Tests turn "it looks right" into "it is right." If the agent can run one command and see what broke, it fixes its own mistakes before you ever see them.

Third, write instructions for the agent. Agent instruction files (skills, CLAUDE.md, AGENTS.md) tell the agent where code goes, which components exist and what not to touch. Without them, every session starts from guesswork.

Fourth, keep the dangerous parts out of the vibe loop. Auth, database permissions, payments and secrets should already be correct before you start prompting for features, so your prompts can be about your app.

This is the reason we built NativeExpress the way we did. It is a React Native and Expo starter for iOS and Android, built to be finished by a coding agent:

  • Sign-in with Google, Apple and email is finished, with row-level security on every record a user owns in your own Supabase project.
  • RevenueCat purchases with entitlement checked on the server, failing closed without the server key, so a modified app cannot unlock your paid tier.
  • AI features run on Supabase Edge Functions, so your provider key never leaves the server.
  • Jest and React Native Testing Library tests sit beside the code, Maestro flows cover the screens, and yarn ci runs twelve checks in one command.
  • Agent skills ship with the clone: setup, design and conventions skills, a PRODUCT.md brief they read, a .agents/skills mirror for Cursor, Codex and other agents, and store-assets and submit skills for Claude Code.

Your agent still writes most of the code. You make the decisions, sign in to services when asked and test on your phone. The difference is that the parts most likely to be vibe coded badly are already done.

For the first time, I felt like I was actually going to make it to the App Store with my idea.
Ilya LibinShipped his first app

For the step-by-step version, from first prompt to a build on your phone, read how to vibe code an app. If you are still choosing between a browser builder and a real codebase, best AI app builders and can Lovable make mobile apps? cover that decision.

FAQ

What is vibe coding and why is it bad?

Vibe coding is building software by prompting an AI and accepting its output without reviewing the code. It is not bad in itself; it is great for prototypes and personal tools. It goes wrong when an unreviewed app handles real users, data or money, because AI-generated code often has security flaws (45% of samples in Veracode's 2025 tests) that look fine on screen.

Is vibe coding a real job?

Not as a defined job category. Official labor statistics do not track "vibe coder" as an occupation, and roles that mention vibe coding are usually software, product or design jobs that expect you to work with AI tools. The skills that get people hired are the engineering ones around it: knowing what to ask for, reviewing output and testing it.

Is vibe coding just coding with AI?

In the original sense, no. Karpathy's vibe coding specifically means not reading the code and judging only by results. In everyday use, and in Collins' word of the year definition, the term has broadened to cover most AI-assisted coding, which is why the distinction between vibe coding and AI-assisted engineering (reviewed, tested, understood) is worth keeping.

How much do vibe coders make?

There is no reliable salary data for "vibe coder", because it is not a recognized occupation with tracked pay. The closest official benchmark is software developers, whose median annual wage was $135,980 in May 2025 according to the US Bureau of Labor Statistics. People who vibe code their own apps earn whatever the app earns; our guide on how to make money with an app covers that side.