惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

奇客Solidot–传递最新科技情报
奇客Solidot–传递最新科技情报
博客园_首页
大猫的无限游戏
大猫的无限游戏
让小产品的独立变现更简单 - ezindie.com
让小产品的独立变现更简单 - ezindie.com
Apple Machine Learning Research
Apple Machine Learning Research
B
Blog
B
Blog RSS Feed
Cyber Security Advisories - MS-ISAC
Cyber Security Advisories - MS-ISAC
P
Proofpoint News Feed
MyScale Blog
MyScale Blog
Engineering at Meta
Engineering at Meta
量子位
H
Hackread – Cybersecurity News, Data Breaches, AI and More
T
Tailwind CSS Blog
Stack Overflow Blog
Stack Overflow Blog
N
Netflix TechBlog - Medium
T
The Blog of Author Tim Ferriss
U
Unit 42
aimingoo的专栏
aimingoo的专栏
博客园 - 叶小钗
博客园 - 【当耐特】
云风的 BLOG
云风的 BLOG
博客园 - Franky
博客园 - 聂微东

Aikido Security's Blog

GlassWorm goes native: New Zig dropper infects every IDE on your machine Aikido Attack finds multiple 0-days in Hoppscotch The cybersecurity doomerism around Mythos doesn't match what we see on the ground axios compromised on npm: maintainer account hijacked, RAT deployed Popular telnyx package compromised on PyPI by TeamPCP Aikido × Lovable: Vibe, Fix, Ship CanisterWorm Gets Teeth: TeamPCP's Kubernetes Wiper Targets Iran TeamPCP deploys CanisterWorm on NPM following Trivy compromise Security testing is validating software that no longer exists Aikido Recognized by Frost & Sullivan with the 2026 Customer Value Leadership Award in ASPM GlassWorm Hides a RAT Inside a Malicious Chrome Extension fast-draft Open VSX Extension Compromised by BlokTrooper Glassworm Strikes Popular React Native Phone Number Packages Glassworm Is Back: A New Wave of Invisible Unicode Attacks Hits Hundreds of Repositories How Security Teams Fight Back Against AI-Powered Hackers Introducing Betterleaks, an open source secrets scanner by the author of Gitleaks Trump’s 2026 cybersecurity strategy: From compliance to consequence How does AI pentesting work with compliance? What continuous pentesting actually requires Rare Not Random: Using Token Efficiency for Secrets Scanning Persistent XSS/RCE using WebSockets in Storybook’s dev server Why Determinism Is Still a Necessity in Security WAF vs. RASP vs. ADR Introducing Aikido Infinite: A new model of self-securing software How Aikido secures AI pentesting agents by design Astro Full-Read SSRF via Host Header Injection How to Get Your Board to Care About Security (Before a Breach Forces the Issue) What is Slopsquatting? The AI Package Hallucination Attack Already Happening SvelteSpill: A Cache Deception Bug in SvelteKit + Vercel Top 6 Wiz Code Alternatives
Coinbase's layoffs signal a dangerous move into a vibe-co...
2026-05-08 · via Aikido Security's Blog

While roasting tech CEOs isn’t my usual job (that falls more into Madeline Lawrence’s territory), Coinbase CEO Brian Armstrong’s recent tweet about layoffs and AI is so out of pocket that I had to write something. In short, the CEO announced that he’s firing 14% of the workforce to rebuild Coinbase to “be lean, fast, and AI-native,” which apparently involves everyone at the company shipping AI-generated code, including “non-technical teams.” 

Armstrong must have thought this was as good a time as any to make more cuts, perhaps because it seems in vogue (see: Microsoft, Amazon, and soon PayPal). No one is shocked, since Coinbase laid off staff in 2022, 2023, and even earlier this year.  But this time is different, and not in a good way. Armstrong latches onto the whole “AI is here, we’re in a down market, time to be more efficient” spiel that everyone else is using, and doubles down on the rhetoric.

Among the laundry list of problems with the tweet (including the tweet being written by AI itself), one of the biggest concerns is the implications of what this means for Coinbase’s security posture. 

A financial exchange isn't a place to vibe-code

We’re in the midst of a new generation of AI vibe code founders. But Coinbase isn’t some niche SaaS product. It’s a large financial exchange. 

"If I was managing one of the largest crypto exchanges in the world, managing assets on behalf of sovereigns and institutions, I would not be letting my technical staff vibecode... idk, but that's just me." — @Crypto_Mags

In his long tweet, Armstrong said, “The biggest risk now is not taking action. We are adjusting early and deliberately to rebuild Coinbase to be lean, fast, and AI-native. We need to return to the speed and focus of our startup founding, with AI at our core.” This reads like pandering to shareholders. The biggest risk to users is losing their money or personal data in a cybersecurity attack. 

Coinbase customers already know what a breach looks like. The 2025 breach exposed personal data on 70,000 users and drained hundreds of millions from victims through follow-on phishing attacks, with Coinbase itself absorbing $180-400M in remediation costs.

“This is crazy ->

> Non-technical teams are now shipping production code

As a software engineer and a customer of Coinbase I find this deeply concerning” — @mikeneder

The stakes of getting security right at a crypto exchange are high, and we expect more from our financial institutions than we do from other companies. We want them to be mature, which sometimes necessitates being slow and deliberate, instead of being an AI-powered startup. Imagine Wells Fargo or HSBC announcing that they’re going to act like a startup and make the bank tellers write code.

Vibe coding doesn’t create secure code

Instead of leaving coding to the experts, Armstrong shared in his tweet that “Non-technical teams are now shipping production code, and many of our workflows are being automated.” 

Non-technical teams shipping production code is so unhinged.

While non-technical people can prompt Claude Code to produce something that looks functional, they don’t have the training to understand the security implications of how a given piece of code works. It’s not their job to know, and frankly, people in non-engineering roles have other jobs they were hired to do. 

Vibe-code code will get better over time, but it’s not production-ready yet. According to our research at Aikido, 1 in 5 organizations last year reported an incident that was caused by AI-generated code.  One thing that vibe-code advocates seem to forget is that the hard part of software development has never been individual lines of code. AIs don’t always capture the big picture when they write, like how different components come together, and the result is that more vulnerabilities make it into the code.

Simply prompting AI to “do security better” doesn’t fix this. When left to their own devices, AIs tend to make less secure code over time. According to research, LLMs writing code are optimizing functional completeness, performance, maintainability, and security, with security as a soft prompt. Over multiple iterations, the model gradually drifts away from the security spec because it's trying to satisfy the other three objectives. 

People tend to assume the opposite. Studies show that people tend to overestimate AI’s ability to write secure code, and as a result, developers with coding assistance write less secure code than those without access. Given reality, then, AI-generated code needs more oversight, not less. Non-technical people, and even junior engineers, are not equipped to do this.

“This tells me that tech is being run so incompetently at Coinbase that:

- They're effectively letting random employees push code. The unknown unknowns and totally unnecessary risk is off the charts.

- They can't imagine a way to put those people to work building value.” —@DragonStacker

With the layoffs, Armstrong also throws organization and leadership out the window. “Leaders will own much more, with as many as 15+ direct reports... Managers should be like player-coaches, getting their hands dirty alongside their teams.” So now MORE people are creating code, and the senior staff have more responsibilities than ever. Who is supposed to be reviewing all this code? Seriously.

Setting aside the "is anyone looking at the PM’s code being thrown into prod" question, there are the operational concerns that don’t seem to be addressed in Armstrong’s tweet. Nothing he said explains how piles of vibe-coded features are supposed to run effectively in production (and it doesn’t scale by adding more AI).

What's the rollback plan when something breaks or causes a security incident at 2 a.m., and the code was written by a PM and an AI agent? Who's on call? This PM is certainly not being asked to debug code they didn't really write, in a system they don't really understand. Definitely not the AI agent. Perhaps it was an engineer who was fired for not writing enough AI code? Godspeed to the surviving DevOps and security teams.

Six-panel pixel art comic titled "Overreliance on LLMs" by Schematical.com. A bearded reviewer asks a developer in a backwards cap about their pull request. Panel 1: "I have a few questions about your last pull request." Panel 2: "What does this code on lines 172 to 210 do?" The developer answers, "It makes our application work." Panel 3: The reviewer presses, "Sure but what specifically does it do?" The developer replies, "I told it to validate the form data." Panel 4: The reviewer, surprised: "You told it?" The developer backpedals, "I mean it validates the form data." Panel 5: "Can you explain further?" The developer says, "Sure... one sec." Panel 6: A computer screen shows the developer secretly prompting an LLM site: "What do you do when you use an LLM to write code that you don't understand and someone asks you about it?"

Credit: Schematical.com

An AI-first, human-last strategy

In his announcement, Armstrong states a “plan” of how to become AI-native: “To get there, we are not just reducing headcount and cutting costs, we’re fundamentally changing how we operate: rebuilding Coinbase as an intelligence, with humans around the edge aligning it.”

I don’t know what “Coinbase as an intelligence” means, and it doesn’t quite get explained (is my crypto custodian app sentient?). But what is clear is that the CEO is treating humans as secondary.

The correct response to agentic AI is not to fire the engineers and ship code as fast as possible. It’s recognizing that agentic AI has made cybersecurity more important than ever. The people making decisions to replace experts with AI clearly are not getting their hands dirty writing production-quality code daily (vibe-coded personal productivity apps don’t count).

I’ll likely be moving my Bitcoin out of Coinbase soon. 

"The people who survived this layoff just got assigned 15 direct reports, mandatory IC work, and managing a fleet of AI agents. honestly getting laid off might be the better deal here." — @siddsax