Full Breakdown
AI-Generated Code Leads to Massive Credit-Card Leak on Dark Web
5/8/2026, 8:58:23 PM
Core Event: Unsecured Dashboard Exposes 345,000 Stolen Cards
On April 16, Cybernews uncovered an unauthenticated dashboard run by the dark-web carding site Jerry’s Store. Built with AI coding assistant Cursor, it displayed details for about 345,000 stolen cards, including roughly 145,000 marked as valid after test purchases at merchants such as Amazon and Lyft.
Background & Context: Vibe Coding and AI Tools
Jerry’s Store operators used Cursor, an AI-coding platform from U.S. firm Anysphere, to build the server and dashboards. Their “vibe coding”—plain-English prompts with no security review—created an unauthenticated public directory that exposed the data.
Key Figures & Groups
The breach involved Jerry’s Store (dark-web marketplace), Cursor (AI coding assistant), Anysphere (its developer), and Cybernews (researchers).
Data & Statistics
The leak contained about 345,000 card records: roughly 200,000 invalid and 145,000 valid, each with PAN, expiration, CVV, name and address. Validation used test purchases at merchants such as Amazon, Grubhub, Temu, Lyft, Elf Cosmetics and CountryMax.
Why It Matters
The incident shows AI-generated software can amplify cybercrime when developers skip basic security. It also raises regulatory concerns about AI misconfiguration as a systemic threat, prompting calls for stricter oversight of AI-assisted development in both legitimate and illicit contexts.
Official Statements & Responses
Cybernews said the leak “traced back to a single moment in the chat history with Cursor,” when the operator asked the AI to build a statistics dashboard. The team noted the AI kept generating code despite vague instructions, leaving the system exposed. No comment was received from Anysphere or the operators of Jerry’s Store.
Criticism & Opposition
Cybersecurity experts warned that “vibe coding” can cause “accidental data leaks,” urging mandatory human security reviews. Regulators and financial institutions cited the breach as evidence that AI-driven misconfigurations pose a “serious systemic threat” requiring policy action.
On-the-Ground Reports
Cybernews researchers accessed the dashboard via a standard browser, confirming no authentication. Their probe documented fabricated merchant accounts used to test card validity, a practice that raises the market value of verified cards on the dark web.
Conflicting Reports & Gaps
Sources agree on an approximate total of 345,000 records, but the exact count of valid cards varies between “around 145,000” and “approximately 145,000.” No statements from the operators or Anysphere were obtained, leaving their awareness of the vulnerability unclear.
Verbatim Quotes
- “People are now calling this approach vibe coding.” — Cybersecurity analysts, general commentary
- “While Cursor is a legitimate tool, the lack of basic security measures led to the creation of an unauthenticated public directory, exposing sensitive data directly to the internet.” — VarIndia
- “This incident underscores a broader issue: the inherent vulnerabilities in using AI coding tools without adequate human oversight.” — VarIndia
- “The basic idea is that a developer types out what they want in plain English and lets an AI like Cursor, Codex, or Claude Code write the code unhindered.” — GeekSpin
What’s Next
Regulators are reviewing AI-coding tool guidelines, and law-enforcement continues to probe Jerry’s Store’s operators.
