AI built your app in a day. Hackers can break it in two.
A founder bragged online that his app was 100 percent AI-coded, zero hand-written lines. Within 48 hours it was hacked. Within a week it was gone. That story went viral, but the uncomfortable part is that the research says it was not bad luck.
Veracode's GenAI Code Security Report tested more than 100 AI models on 80 real coding tasks. The code usually works. But when there is a secure way and an insecure way to do something, the AI picks the insecure one:
The five repairs (one afternoon, total)
Each repair below is a plain-English explanation, a copy-paste prompt for your AI coding tool, and a way to check it actually worked. Do them in order.
Get your login token out of the browser's junk drawer
AI code loves storing your login token in localStorage, where any script on the page can steal it. It belongs in a secure cookie that scripts cannot touch (OWASP's guidance).
Find every place this app stores auth tokens or session data in localStorage or sessionStorage. Move them to HttpOnly, Secure, SameSite cookies, and update everything that breaks.
Check: open DevTools → Application → Local Storage. If you can see your token there, so can an attacker.
Never trust a check that runs in the browser
"Members only" screens, paywalls, and admin checks that live in the browser are cardboard doors: free tools remove them in seconds. Every check must be repeated on the server, where attackers cannot reach. This exact hole is what killed the 48-hour founder.
List every permission, payment, or role check in this app that happens only in the frontend. For each one, add the same check server-side, and make the server the source of truth.
Check: log out, then try calling one of your protected API routes directly. If it answers with data, the door is cardboard.
Stop letting bots guess passwords forever
Without rate limiting, a bot can try passwords on your login form all night, every night. Limit attempts and lock out after too many failures.
Add rate limiting to login and signup: max 5 attempts per account per 15 minutes, with exponential backoff, and return 429 without revealing whether the email exists.
Check: deliberately type a wrong password six times in a row. By the last attempt you should be blocked, not politely told "wrong password" again.
Turn on two-factor authentication
Microsoft's large-scale study of real account attacks found multi-factor authentication blocks over 99 percent of automated account takeovers. It is the single highest-value switch you can flip.
Add optional two-factor authentication using time-based one-time codes (TOTP), with recovery codes, and prompt users to enable it after signup.
Check: turn it on for your own account, log out, and log back in. If you get in without the six-digit code, it is not actually enforced.
Reject passwords that already leaked
Over a billion real passwords are floating around from old breaches, and bots try those first. The free Have I Been Pwned database lets your app reject them at signup without the password ever leaving your server, and checking leaked passwords is a NIST standard, not paranoia.
At signup and password change, check the password against the Have I Been Pwned range API (k-anonymity) and reject any password that appears in known breaches, with a friendly error message.
Check: try to sign up with the password password123. It should be refused. If it sails through, the check is not wired up.
Before you share your app link anywhere: run all five checks above, once, yourself. Ten minutes. The founders who skip this are the ones who become cautionary reels.
One more door worth checking, and it is not code you wrote. If you install skills into your AI tools — the folders other people publish to teach an assistant a new job — a quarter of those carry a security hole of their own, and there is now a free NVIDIA scanner that reads one before you install it: scan any AI skill before you install it.
Questions people actually ask
Can't I just prompt the AI to 'make it secure'?
Vague security prompts barely help. What works is naming the specific weakness (like the five in this memo) and then testing afterward. Prompts fix most of it, but only if you verify.
My app is small. Would anyone really attack it?
Attacks are automated. Bots scan everything with a login form, no matter how small. You are not being targeted personally; you are being swept, which is worse, because it happens on day one.
I already shipped. Is it too late?
No. All five repairs can be added to a live app in an afternoon. Start with the browser-check repair (number 2), because it is the one that kills apps fastest.
Do these repairs require a security background?
No. Each one is a copy-paste prompt plus a simple check you can do yourself. If you can use an AI coding tool, you can apply all five.
Want this built for you?
We write these memos because we build this stuff every day. If you want it working in your business instead of sitting on your reading list, that is literally our job.