Series-B SaaS (pattern case) · 2025 · cost index 4/5

Vibe-coded auth middleware nobody could explain

Sev-1 incident; emergency rewrite; weeks of audit and customer trust repair

What happened

A weekend demo shipped AI-generated auth middleware to production without a thorough diff review. The incident revealed session edge cases and permission holes nobody could attribute to a human author. Slack archaeology replaced code ownership; the prompt history was the closest thing to a design doc.

Failure mode

Generation speed treated as shipping readiness. Review capacity did not scale with PR volume. Tests asserted happy paths the model also invented. Accountability evaporated when the outage page asked who signed off.

Lesson

Copilot is not a committer of record. Size review like on-call, require humans on the hook for security-sensitive paths, and treat vibe-shipped diffs as prototypes until proven otherwise.

Sources

  • Industry pattern — AI-generated prod incidents (anonymized)
  • OWASP — LLM application security guidance
  • Engineering postmortems — ownership of generated code

Related tech

← All cases

© 2026 Fadstack · Shane Code

Opinionated history · not a ranking