Polako Finance logo
← Back to articles

Why you shouldn't vibe-code payments on your website

Why you shouldn't vibe-code payments on your website

A website that takes real money should be built by a professional, not by AI from a description. Sites built with AI and no developer get hacked within days of launch, sometimes within hours.

Vibe coding means building a website by simply describing to AI what you need, without knowing how to code. With Claude, Cursor or Lovable you can build a store over a weekend, and it will work. But AI often leaves the database, keys or payment check wide open, and bots find this before the owner does.

Real hacks and leaks

In every one of these cases the site worked fine, and the hole was found by outsiders - researchers or attackers.

When Where What happened
2026 Apps on Supabase UpGuard found 16,326 databases anyone could read without a password. Supabase is often used in sites built with AI. Confirmed leaks include a platform in India - data on 65,000 people with passport details, a valet parking service in the US - over 100,000 customers, and an immigration service in Canada - passwords stored in plain text.
March-April 2026 Projects on Lovable For 48 days, anyone with a free account could open other people’s projects on Lovable: source code and database credentials. One organization leaked names, job titles and LinkedIn profiles of its employees.
January 2026 Moltbook A social network for AI agents whose founder said he hadn’t written a single line of code. Wiz researchers found an open database within minutes: 1.5 million access keys and over 35,000 emails.
March 2025 EnrichLead A service built in Cursor without a single line of hand-written code. Two days after the launch post, attackers moved in: they bypassed the subscription paywall, burned through API key limits and filled the database with junk. About a week later the service shut down.

How fast they get hacked

Bots find an exposed key or database in minutes, not days. In March-April 2026, researchers left keys to a test database in different places and timed how long it took attackers to show up.

Where the key was When the bots arrived
Public code on GitHub in under a minute
Site code visible in the browser within a few minutes
Developer forums (Stack Overflow, Pastebin) within 30-60 minutes
Published code library (npm) within 2-3 hours

All the bots behaved the same way: they looked at how the database was structured, found the user tables, downloaded them and tried to change the data. In a similar experiment by Comparitech, a key to an Amazon cloud server posted on GitHub was abused within a minute.

Being a little-known store doesn’t protect you: bots scan everything. According to Thales (Imperva), in 2026 bots made up 53% of web traffic, and 40% of all traffic came from malicious bots.

How exactly AI-built stores get hacked

When a site takes payments, a hack hits your money directly. Here is what attackers usually do:

  • Buy for 1 dinar. If the browser calculates the order total, the price can be changed before payment.
  • Mark an order as paid without paying. If the store doesn’t check that the payment confirmation really came from the bank, it can be faked.
  • Steal the payment system key. AI often leaves it right in the site code. With a stolen Stripe key, for example, you can issue refunds on payments from the last 180 days.
  • Download the customer database. Names, phone numbers, addresses and order history end up with strangers.
  • Plant a script on the payment page. It quietly copies everything the customer types.

An owner who doesn’t write code can’t check any of these. They find out about the problem when the money or data is already gone.

What to do: leave payments to professionals

A website that takes real money should be built and checked by a professional developer.

AI code usually works, but that doesn’t mean it’s secure. In a Carnegie Mellon study, AI agents solved 61% of tasks correctly, but only 10.5% of the solutions were secure. Only someone who understands development can tell the difference.

  • Use proven platforms. Tilda and WooCommerce power millions of sites, and dedicated teams look after their security. Hackers know this: in a campaign uncovered in September 2026, they deliberately avoided big platforms like WooCommerce and went after stores running custom code.
  • Don’t vibe-code payments. Payment processing, account login and the order database should be built by a specialist, not by AI from a description.
  • Keep AI for everything else. Copy, product descriptions, images, design - mistakes there don’t cost money.
  • If your site is already built with AI, show it to a developer before real payments start.

How Polako Finance protects payments on your site

Three of the five attack methods above target payments directly. You can hand this part to professionals right away - that’s what Polako Finance does.

  • We connect you to the bank. No need to ask AI to write payments from scratch.
  • Secret keys never reach your site. They’re stored on our side, so they can’t be stolen from your site’s code.
  • Customers enter card details on the bank’s page, not yours. Card data doesn’t pass through your site and isn’t stored there.
  • Payments are confirmed by the payment system. Every response is verified with a digital signature, so a fake “paid” won’t get through.
  • We check your site before launch. First automatically, then manually. Then the payment system runs its own test payments, and finally we check everything with a real payment and a refund.
  • All payments are visible in your dashboard. If something goes wrong, unusual transactions are easy to spot.

You don’t need to rebuild your site: you can connect even with a one-page site. There’s a ready-made module for Tilda, and an API for other sites.

Your customer database and admin panel are the site’s responsibility. That’s why the best setup is a store on a proven platform with payments through Polako Finance.

See how checkout looks for customers in our demo store. Want to find out how well payments on your site are protected?

Sources

Ready to connect online payments?

Tell us about your project and we'll respond within one business day.

Get in touch