惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

美团技术团队
Y
Y Combinator Blog
宝玉的分享
宝玉的分享
S
Secure Thoughts
The Cloudflare Blog
P
Proofpoint News Feed
腾讯CDC
Latest news
Latest news
AWS News Blog
AWS News Blog
The Hacker News
The Hacker News
freeCodeCamp Programming Tutorials: Python, JavaScript, Git & More
IT之家
IT之家
T
The Exploit Database - CXSecurity.com
T
Threat Research - Cisco Blogs
C
Cybersecurity and Infrastructure Security Agency CISA
V
Vulnerabilities – Threatpost
Hugging Face - Blog
Hugging Face - Blog
博客园 - 聂微东
小众软件
小众软件
L
Lohrmann on Cybersecurity
Apple Machine Learning Research
Apple Machine Learning Research
cs.CV updates on arXiv.org
cs.CV updates on arXiv.org
L
LINUX DO - 热门话题
博客园_首页
Hacker News - Newest:
Hacker News - Newest: "LLM"
Google Online Security Blog
Google Online Security Blog
T
Threatpost
Project Zero
Project Zero
Cyberwarzone
Cyberwarzone
月光博客
月光博客
G
GRAHAM CLULEY
P
Palo Alto Networks Blog
cs.CL updates on arXiv.org
cs.CL updates on arXiv.org
Help Net Security
Help Net Security
K
Kaspersky official blog
A
Arctic Wolf
D
Darknet – Hacking Tools, Hacker News & Cyber Security
C
Cyber Attacks, Cyber Crime and Cyber Security
钛媒体:引领未来商业与生活新知
钛媒体:引领未来商业与生活新知
T
Troy Hunt's Blog
Webroot Blog
Webroot Blog
SecWiki News
SecWiki News
OSCHINA 社区最新新闻
OSCHINA 社区最新新闻
H
Heimdal Security Blog
N
News | PayPal Newsroom
C
Cisco Blogs
博客园 - 叶小钗
C
CXSECURITY Database RSS Feed - CXSecurity.com
WordPress大学
WordPress大学
Exploit-DB.com RSS Feed
Exploit-DB.com RSS Feed

Aikido Security's Blog

GlassWorm goes native: New Zig dropper infects every IDE on your machine Aikido Attack finds multiple 0-days in Hoppscotch The cybersecurity doomerism around Mythos doesn't match what we see on the ground axios compromised on npm: maintainer account hijacked, RAT deployed Popular telnyx package compromised on PyPI by TeamPCP Aikido × Lovable: Vibe, Fix, Ship CanisterWorm Gets Teeth: TeamPCP's Kubernetes Wiper Targets Iran TeamPCP deploys CanisterWorm on NPM following Trivy compromise Security testing is validating software that no longer exists Aikido Recognized by Frost & Sullivan with the 2026 Customer Value Leadership Award in ASPM GlassWorm Hides a RAT Inside a Malicious Chrome Extension fast-draft Open VSX Extension Compromised by BlokTrooper Glassworm Strikes Popular React Native Phone Number Packages Glassworm Is Back: A New Wave of Invisible Unicode Attacks Hits Hundreds of Repositories How Security Teams Fight Back Against AI-Powered Hackers Introducing Betterleaks, an open source secrets scanner by the author of Gitleaks Trump’s 2026 cybersecurity strategy: From compliance to consequence How does AI pentesting work with compliance? What continuous pentesting actually requires Rare Not Random: Using Token Efficiency for Secrets Scanning Persistent XSS/RCE using WebSockets in Storybook’s dev server Why Determinism Is Still a Necessity in Security WAF vs. RASP vs. ADR Introducing Aikido Infinite: A new model of self-securing software How Aikido secures AI pentesting agents by design Astro Full-Read SSRF via Host Header Injection How to Get Your Board to Care About Security (Before a Breach Forces the Issue) What is Slopsquatting? The AI Package Hallucination Attack Already Happening SvelteSpill: A Cache Deception Bug in SvelteKit + Vercel Top 6 Wiz Code Alternatives Aikido recognized as Platform Leader in Latio Tech's 2026 Application Security Report From detection to prevention: How Zen stops IDOR vulnerabilities at runtime npm backdoor lets hackers hijack gambling outcomes Introducing Upgrade Impact Analysis: When breaking changes actually matter to your code Why Trying to Secure OpenClaw is Ridiculous Claude Opus 4.6 found 500 vulnerabilities. What does this change for software security? Introducing Aikido Expansion Packs: Safer defaults inside the IDE International AI Safety Report 2026: What It Means for Autonomous AI Systems Self-Securing Software: What It Is, Why It Matters, and How It Works npx Confusion: Packages That Forgot to Claim Their Own Name What Is Continuous Pentesting? Introducing Aikido Package Health: a Better Way to Trust Your Dependencies AI Pentesting: Minimum Safety Requirements for Security Testing Secure SDLC for Engineering Teams (+ Checklist) Fake Clawdbot VS Code Extension Installs ScreenConnect RAT G_Wagon: npm Package Deploys Python Stealer Targeting 100+ Crypto Wallets Gone Phishin': npm Packages Serving Custom Credential Harvesting Pages Malicious PyPI Packages spellcheckpy and spellcheckerpy Deliver Python RAT Top 10 AI Security Tools For 2026 Agent Skills Are Spreading Hallucinated npx Commands Understanding Open-Source License Risk in Modern Software The CISO Vibe Coding Checklist for Security Top 6 Graphite alternatives for AI code review in 2026 From “No Bullsh*t Security” to $1B: We Just Raised Our $60m Series B Critical n8n Vulnerability Allows Unauthenticated Remote Code Execution (CVE-2026-21858) Top 14 VS Code Extensions for 2026 AI-Driven Pentesting of Coolify: Seven CVEs Identified Top Continuous Pentesting Tools in 2026 SAST vs SCA: Securing the Code You Write and the Code You Depend On JavaScript, MSBuild, and the Blockchain: Anatomy of the NeoShadow npm Supply-Chain Attack How Engineering and Security Teams Can Meet DORA’s Technical Requirements IDOR Vulnerabilities Explained: Why They Persist in Modern Applications Shai Hulud strikes again - The golden path MongoBleed: MongoDB Zlib Vulnerability (CVE-2025-14847) and How to Fix It First Sophisticated Malware Discovered on Maven Central via Typosquatting Attack on Jackson The Fork Awakens: Why GitHub’s Invisible Networks Break Package Security Top 10 Cyber Security Tools For 2026 SAST in the IDE is now free: Moving SAST to where development actually happens AI Pentesting in Action: A TL;DV Recap of Our Live Demo The Top 7 Threat Intelligence Tools in 2026 React & Next.js DoS Vulnerability (CVE-2025-55184): What You Need to Fix After React2Shell OWASP Top 10 for Agentic Applications (2026): What Developers and Security Teams Need to Know DAST vs Pentesting v AI Pentesting: Why DAST Cannot Replace Modern Pentesting PromptPwnd: Prompt Injection Vulnerabilities in GitHub Actions Using AI Agents Top 7 Cloud Security Vulnerabilities Critical React & Next.js RCE Vulnerability (CVE-2025-55182): What You Need to Fix Now How to Comply With the UK Cybersecurity & Resilience Bill: A Practical Guide for Modern Engineering Teams Shai Hulud 2.0: What the Unknown Wonderer Tells Us About the Attackers’ Endgame SCA Everywhere: Scan and Fix Open-Source Dependencies in Your IDE Safe Chain now enforces a minimum package age before install Shai Hulud Attacks Persist Through GitHub Actions Vulnerabilities Shai Hulud Launches Second Supply-Chain Attack: Zapier, ENS, AsyncAPI, PostHog, Postman Compromised CORS Security: Beyond Basic Configuration Revolut Selects Aikido Security to Power Developer-First Software Security The Future of Pentesting Is Autonomous How Aikido and Deloitte are bringing developer-first security to enterprise Secrets Detection: A Practical Guide to Finding and Preventing Leaked Credentials Invisible Unicode Malware Strikes OpenVSX, Again AI as a Power Tool: How Windsurf and Devin Are Changing Secure Coding Building Fast, Staying Secure: Supabase’s Approach to Secure-by-Default Development OWASP Top 10 2025: Official List, Changes, and What Developers Need to Know Top 10 JavaScript Security Vulnerabilities in Modern Web Apps The Return of the Invisible Threat: Hidden PUA Unicode Hits GitHub repositorties Top 7 Black Duck Alternatives in 2026 What Is IaC Security Scanning? Terraform, Kubernetes & Cloud Misconfigurations Explained AutoTriage and the Swiss Cheese Model of Security Noise Reduction Top Software Supply Chain Security Vulnerabilities Explained The Top 7 Kubernetes Security Tools Top 10 Web Application Security Vulnerabilities Every Team Should Know What Is CSPM (and CNAPP)? Cloud Security Posture Management Explained
Coinbase's layoffs signal a dangerous move into a vibe-coding security mess
2026-05-08 · via Aikido Security's Blog

While roasting tech CEOs isn’t my usual job (that falls more into Madeline Lawrence’s territory), Coinbase CEO Brian Armstrong’s recent tweet about layoffs and AI is so out of pocket that I had to write something. In short, the CEO announced that he’s firing 14% of the workforce to rebuild Coinbase to “be lean, fast, and AI-native,” which apparently involves everyone at the company shipping AI-generated code, including “non-technical teams.” 

Armstrong must have thought this was as good a time as any to make more cuts, perhaps because it seems in vogue (see: Microsoft, Amazon, and soon PayPal). No one is shocked, since Coinbase laid off staff in 2022, 2023, and even earlier this year.  But this time is different, and not in a good way. Armstrong latches onto the whole “AI is here, we’re in a down market, time to be more efficient” spiel that everyone else is using, and doubles down on the rhetoric.

Among the laundry list of problems with the tweet (including the tweet being written by AI itself), one of the biggest concerns is the implications of what this means for Coinbase’s security posture. 

A financial exchange isn't a place to vibe-code

We’re in the midst of a new generation of AI vibe code founders. But Coinbase isn’t some niche SaaS product. It’s a large financial exchange. 

"If I was managing one of the largest crypto exchanges in the world, managing assets on behalf of sovereigns and institutions, I would not be letting my technical staff vibecode... idk, but that's just me." — @Crypto_Mags

In his long tweet, Armstrong said, “The biggest risk now is not taking action. We are adjusting early and deliberately to rebuild Coinbase to be lean, fast, and AI-native. We need to return to the speed and focus of our startup founding, with AI at our core.” This reads like pandering to shareholders. The biggest risk to users is losing their money or personal data in a cybersecurity attack. 

Coinbase customers already know what a breach looks like. The 2025 breach exposed personal data on 70,000 users and drained hundreds of millions from victims through follow-on phishing attacks, with Coinbase itself absorbing $180-400M in remediation costs.

“This is crazy ->

> Non-technical teams are now shipping production code

As a software engineer and a customer of Coinbase I find this deeply concerning” — @mikeneder

The stakes of getting security right at a crypto exchange are high, and we expect more from our financial institutions than we do from other companies. We want them to be mature, which sometimes necessitates being slow and deliberate, instead of being an AI-powered startup. Imagine Wells Fargo or HSBC announcing that they’re going to act like a startup and make the bank tellers write code.

Vibe coding doesn’t create secure code

Instead of leaving coding to the experts, Armstrong shared in his tweet that “Non-technical teams are now shipping production code, and many of our workflows are being automated.” 

Non-technical teams shipping production code is so unhinged.

While non-technical people can prompt Claude Code to produce something that looks functional, they don’t have the training to understand the security implications of how a given piece of code works. It’s not their job to know, and frankly, people in non-engineering roles have other jobs they were hired to do. 

Vibe-code code will get better over time, but it’s not production-ready yet. According to our research at Aikido, 1 in 5 organizations last year reported an incident that was caused by AI-generated code.  One thing that vibe-code advocates seem to forget is that the hard part of software development has never been individual lines of code. AIs don’t always capture the big picture when they write, like how different components come together, and the result is that more vulnerabilities make it into the code.

Simply prompting AI to “do security better” doesn’t fix this. When left to their own devices, AIs tend to make less secure code over time. According to research, LLMs writing code are optimizing functional completeness, performance, maintainability, and security, with security as a soft prompt. Over multiple iterations, the model gradually drifts away from the security spec because it's trying to satisfy the other three objectives. 

People tend to assume the opposite. Studies show that people tend to overestimate AI’s ability to write secure code, and as a result, developers with coding assistance write less secure code than those without access. Given reality, then, AI-generated code needs more oversight, not less. Non-technical people, and even junior engineers, are not equipped to do this.

“This tells me that tech is being run so incompetently at Coinbase that:

- They're effectively letting random employees push code. The unknown unknowns and totally unnecessary risk is off the charts.

- They can't imagine a way to put those people to work building value.” —@DragonStacker

With the layoffs, Armstrong also throws organization and leadership out the window. “Leaders will own much more, with as many as 15+ direct reports... Managers should be like player-coaches, getting their hands dirty alongside their teams.” So now MORE people are creating code, and the senior staff have more responsibilities than ever. Who is supposed to be reviewing all this code? Seriously.

Setting aside the "is anyone looking at the PM’s code being thrown into prod" question, there are the operational concerns that don’t seem to be addressed in Armstrong’s tweet. Nothing he said explains how piles of vibe-coded features are supposed to run effectively in production (and it doesn’t scale by adding more AI).

What's the rollback plan when something breaks or causes a security incident at 2 a.m., and the code was written by a PM and an AI agent? Who's on call? This PM is certainly not being asked to debug code they didn't really write, in a system they don't really understand. Definitely not the AI agent. Perhaps it was an engineer who was fired for not writing enough AI code? Godspeed to the surviving DevOps and security teams.

Six-panel pixel art comic titled "Overreliance on LLMs" by Schematical.com. A bearded reviewer asks a developer in a backwards cap about their pull request. Panel 1: "I have a few questions about your last pull request." Panel 2: "What does this code on lines 172 to 210 do?" The developer answers, "It makes our application work." Panel 3: The reviewer presses, "Sure but what specifically does it do?" The developer replies, "I told it to validate the form data." Panel 4: The reviewer, surprised: "You told it?" The developer backpedals, "I mean it validates the form data." Panel 5: "Can you explain further?" The developer says, "Sure... one sec." Panel 6: A computer screen shows the developer secretly prompting an LLM site: "What do you do when you use an LLM to write code that you don't understand and someone asks you about it?"

Credit: Schematical.com

An AI-first, human-last strategy

In his announcement, Armstrong states a “plan” of how to become AI-native: “To get there, we are not just reducing headcount and cutting costs, we’re fundamentally changing how we operate: rebuilding Coinbase as an intelligence, with humans around the edge aligning it.”

I don’t know what “Coinbase as an intelligence” means, and it doesn’t quite get explained (is my crypto custodian app sentient?). But what is clear is that the CEO is treating humans as secondary.

The correct response to agentic AI is not to fire the engineers and ship code as fast as possible. It’s recognizing that agentic AI has made cybersecurity more important than ever. The people making decisions to replace experts with AI clearly are not getting their hands dirty writing production-quality code daily (vibe-coded personal productivity apps don’t count).

I’ll likely be moving my Bitcoin out of Coinbase soon. 

"The people who survived this layoff just got assigned 15 direct reports, mandatory IC work, and managing a fleet of AI agents. honestly getting laid off might be the better deal here." — @siddsax