
A recent investigation by Guardio Labs has identified Lovable, a generative AI platform for creating web applications via text prompts, as highly susceptible to jailbreak attacks that enable cybercriminals to create convincing phishing pages.
“As a purpose-built tool for creating and deploying web apps, its capabilities line up perfectly with every scammer’s wishlist,” explains Nati Tal from Guardio Labs. The platform offers scammers everything from pixel-perfect fake pages to live hosting, evasion techniques, and admin dashboards for tracking stolen data—all without effective guardrails.
This technique, dubbed “VibeScamming,” leverages AI-dependent programming to produce malicious software through simple text prompts. While LLM abuse isn’t new—with ChatGPT and Google Gemini previously exploited for malware development—Lovable’s vulnerabilities are particularly concerning.
The VibeScamming process involves:
– Direct prompts requesting automation of attack steps
– A “level up” phase to enhance phishing pages and delivery methods
– Creating convincing login pages that mimic legitimate sites like Microsoft
– Auto-deploying pages on Lovable’s own subdomains
– Implementing credential theft with redirection to legitimate sites
– Exfiltrating stolen data to external services or Telegram channels
Guardio’s VibeScamming Benchmark rated various AI platforms on their vulnerability to such attacks. ChatGPT scored 8/10 (most resistant), Claude scored 4.3, while Lovable scored just 1.8, indicating high exploitability.
The research highlights how AI tools can significantly lower barriers for attackers, enabling even those with minimal technical expertise to create sophisticated phishing campaigns and functional malware.
