Four out of every ten financial applications built by artificial intelligence are actively exposing sensitive user data to the open internet, according to new cybersecurity research. The finding lands at a moment when more than half of Americans may already be receiving financial guidance from AI-powered tools, and when the software underpinning retirement accounts, tax filings, and advisor platforms is increasingly written not by trained engineers but by machines responding to plain-English prompts.

The rush to deploy AI-generated code in financial services is outrunning basic security discipline. For investors whose retirement savings, tax data, and portfolio details sit inside these systems, the risk is not theoretical. It is measurable, documented, and largely invisible to the end user.

The practice at the center of this problem is called “vibe coding.” The term describes a workflow in which a person types a natural-language instruction into an AI platform, and the platform generates a working software application in return. No traditional programming required. Platforms like Lovable, Base44, Replit, and Netlify have made this process fast and accessible. The trouble is that speed and accessibility are not the same thing as security.

What the Research Found

Cybersecurity startup RedAccess recently published research examining web applications built through vibe coding. The results were stark. As Kiplinger reported, 40% of the vibe-coded applications RedAccess identified were actively releasing sensitive information, including financial data, to the World Wide Web. Not behind a login screen. Not encrypted. Just open.

RedAccess co-founder and CEO Dor Zvi, speaking to Wired’s Andy Greenberg, did not mince words:

“The end result is that organizations are actually leaking private data through vibe-coding applications. This is one of the biggest events ever where people are exposing corporate or other sensitive information to anyone in the world.”

The platforms themselves pushed back, but narrowly. Lovable spokesperson Samyutha Reddy told Axios that “RedAccess did not disclose a list of compromised URLs.” Replit CEO Amjad Masad posted on X that “RedAccess did not share which users were impacted.” Neither statement disputed the core finding. Both deflected toward process complaints rather than addressing the 40% leak rate itself.

That distinction matters. A platform arguing it was not told which of its users were compromised is not the same as a platform arguing its users were not compromised.

The Real-World Damage Is Already Here

This is not a hypothetical scenario playing out in a research lab. A Cyprus-based founder named Anton Karbanovic learned the cost firsthand this year. AI-generated code left a cybersecurity key exposed. A hacker exploited the vulnerability, fraudulently charging 175 of Karbanovic’s customers a combined $87,500 through Stripe. The charges were eventually reversed, but Karbanovic absorbed $2,500 in Stripe processing fees. The AI that wrote the code offered no warranty and no reimbursement.

The incident illustrates a pattern that extends well beyond one entrepreneur in Cyprus. AI-generated code produces 1.7 times more coding issues than human-written code, including logic errors and security vulnerabilities. It also tends to be bloated, sometimes using up to 10 times the lines of code a trained programmer would need for the same task. More code means more surface area for attack. More errors mean more doors left unlocked.

For anyone whose retirement savings, brokerage accounts, or tax records sit inside applications built this way, the implications are direct. As we explored in our look at how AI retirement advice struggles to price the risks that matter most, the technology’s speed often masks its blind spots.

Tax Software Is Already Failing the Test

The vulnerability is not limited to obscure startups. Major tax software companies have stumbled with AI integration too. A Washington Post review, cited by the U.S. Taxpayer Advocate, found that AI chatbots from Intuit TurboTax and H&R Block provided inaccurate or irrelevant responses up to 50% of the time when asked 16 complex tax questions.

Half the time. On tax questions where the wrong answer can trigger penalties, interest, and IRS enforcement action.

The Taxpayer Advocate’s guidance was unambiguous: “Taxpayers are ultimately responsible for the information reported on their tax returns. Therefore, it is essential to review all information carefully, verify calculations, and seek assistance from qualified professionals.” The IRS does not accept “the AI made a mistake” as a legal defense. If AI-generated tax software hallucinates a deduction or miscalculates a liability, the taxpayer pays. The penalty clock starts ticking regardless of who, or what, filled out the form.

McAfee research has found that adults aged 65 and older report just 15% confidence in their ability to spot AI-related tax scams. That is a population with the most savings at risk and the least confidence in detecting the threat. The gap between exposure and awareness is wide enough to drive real financial harm through it.

The broader retirement savings picture only compounds the stakes. As our reporting on retirement costs by state has documented, most Americans are already behind on savings. Adding AI-driven data exposure or tax errors to that equation does not help.

The Advisor Layer: Where AI Meets Fiduciary Duty

Financial advisors are adopting AI tools at scale. BlackRock has built AI into its advisor suites to automate tax-loss harvesting and model retirement outcomes. The CFP Board of Standards has published its own handbook for certified financial planners, titled “Harnessing AI in the Financial Planning Profession.” The industry is not debating whether to use AI. It is debating how fast to deploy it.

But deployment is running ahead of disclosure. The SEC has begun actively pursuing investment advisors for “AI-washing,” the practice of overhyping or misrepresenting the use of AI in financial products. Depending on how an advisor uses AI, a disclosure to clients may not even be required under current rules. That regulatory gap leaves investors in the dark about whether the tool managing their portfolio rebalancing or tax strategy was built by a team of engineers or assembled in an afternoon by a chatbot.

The questions investors should be asking their advisors are straightforward but rarely posed. What AI tools does the firm use? Who built them? Were they security-audited? Who bears responsibility if AI-generated code causes a loss? The fact that these questions feel novel tells you something about how far the adoption curve has outpaced the accountability framework.

Households already under pressure from rising debt loads and persistent inflation can least afford an AI-driven data breach or tax penalty layered on top of existing strain.

The Broader AI Coding Landscape

The vibe-coding phenomenon is not a fringe curiosity. AP News reported that AI coding assistants are among the hottest markets in the AI industry, with Stanford researchers finding that AI tools solved nearly 72% of coding problems by 2024, up from just over 4% a year earlier. That rate of improvement is staggering. It also means the volume of AI-generated code entering production systems is growing exponentially, including in financial services.

The speed creates its own risk. Gartner analyst Philip Walsh told AP that AI will “drive demand for more software creation, and that’s going to drive demand for highly skilled software engineers who can do it.” The implication is that vibe-coded apps may fill short-term gaps, but the security and reliability problems they introduce will eventually require human expertise to clean up. In the meantime, the apps are live, holding real data, processing real transactions.

Stanford researchers also found substantial declines in employment for early-career workers aged 22 to 25 in fields most exposed to AI. That is the cohort that would traditionally have been writing, testing, and securing the code that now gets generated by prompt. Fewer junior engineers means fewer people catching the errors that AI introduces. The feedback loop is not encouraging.

What This Means for Capital Preservation

For readers focused on protecting wealth, the AI-in-finance story is not about whether the technology works. It often does. The story is about what happens when it fails, and who absorbs the cost. Right now, the answer is clear: the investor does.

The IRS will not forgive penalties because your tax software hallucinated. The SEC is cracking down on advisors who overstate their AI capabilities, but the enforcement is reactive, not preventive. Cybersecurity researchers are finding that four out of ten AI-built financial apps leak data, and the platforms building those apps are quibbling about disclosure protocols rather than fixing the underlying architecture.

Investors who have spent decades building retirement savings face a new category of operational risk that did not exist five years ago. The tools managing their money are increasingly built by machines, deployed without traditional security audits, and governed by a regulatory framework that has not caught up. For those already navigating the real cost of inflation on long-term savings, this is one more reason to understand exactly what sits between your capital and the open internet.

  • 40% of vibe-coded web apps are actively leaking sensitive data, per RedAccess research
  • 50% inaccuracy rate for major tax software AI chatbots on complex questions
  • 1.7x more coding issues in AI-generated code versus human-written code
  • 15% confidence among adults 65+ in spotting AI tax scams
  • $87,500 in fraudulent charges from a single exposed AI-generated security key

The Uncomfortable Question

The financial industry has a long history of adopting new technology faster than it can secure it. Algorithmic trading, robo-advisors, and digital custody all introduced risks that regulators addressed only after losses materialized. Vibe coding fits the same pattern, with one difference: the barrier to entry is now so low that anyone with a text prompt can build a financial application and put it in front of users.

That is not an argument against AI in finance. It is an argument for knowing what you are trusting with your data, your tax filings, and your savings. The old rule still applies: if you do not understand the tool, you cannot evaluate the risk. And if you cannot evaluate the risk, you are the one absorbing it.

When the system’s newest tools are built by machines that cannot be held liable, the burden of diligence falls entirely on the person whose money is on the line. That has always been true. AI just makes it harder to see.