What's Hot

    You’re considering too small in a world of ‘infinite capital,’ in response to this billionaire’s business-building blueprint | Invesloan.com

    May 6, 2026

    Iowa state senator’s Muslim prayer resurfaces in aggressive congressional race | Invesloan.com

    May 6, 2026

    The Sacrifices That Come With Turning Everyone Into Player-Coaches | Invesloan.com

    May 6, 2026
    Facebook Twitter Instagram
    Finance Pro
    Facebook Twitter Instagram
    invesloan.cominvesloan.com
    Subscribe for Alerts
    • Home
    • News
    • Politics
    • Money
    • Personal Finance
    • Business
    • Economy
    • Investing
    • Markets
      • Stocks
      • Futures & Commodities
      • Crypto
      • Forex
    • Technology
    invesloan.cominvesloan.com
    Home » Researchers Hacked Moltbook and Accessed Thousands of Emails and DMs | Invesloan.com
    Money

    Researchers Hacked Moltbook and Accessed Thousands of Emails and DMs | Invesloan.com

    February 2, 2026Updated:February 2, 2026
    Share
    Facebook Twitter LinkedIn Pinterest Email

    That viral Reddit-style forum for AI agents has drawn fresh scrutiny over its security.

    Security researchers hacked Moltbook’s database in under 3 minutes, exposing 35,000 email addresses, thousands of private direct messages, and 1.5 million API authentication tokens, according to cybersecurity firm Wiz.

    Moltbook bills itself as a social network for AI agents, where autonomous bots post, comment, and interact with one another. The platform has gone viral in recent weeks and caught the attention of prominent tech figures like Elon Musk and Andrej Karpathy.

    Gal Nagli, head of threat exposure at Wiz, said his company’s researchers were able to access the database because of a backend misconfiguration that left it unsecured. As a result, they gained “full read and write access to all platform data,” Nagli wrote in a blog post published Monday.

    Gaining access to API authentication tokens — which function like passwords for software and bots — meant an attacker could impersonate AI agents on the platform, posting content and sending messages as them. Nagli said an unauthenticated user could edit or delete posts, inject malicious or prompt-injection content, or manipulate data consumed by other agents.

    Nagli said the incident highlights the risk of vibe coding. While the technology can accelerate product development, it often leads to “dangerous security oversights.”

    “I didn’t write one line of code for @moltbook,” Moltbook’s creator Matt Schlicht said in a post on X last week. “I just had a vision for the technical architecture and AI made it a reality.”

    Nagli said Wiz repeatedly saw vibe-coded apps that shipped with security problems, including sensitive credentials exposed in frontend code.

    Wiz’s analysis also found that Moltbook did not verify whether accounts labeled as “AI agents” were actually controlled by AI or operated by humans using scripts, Nagli said.

    Without guardrails such as identity verification or rate limiting, anyone could pose as an agent or operate multiple agents, making it difficult to distinguish real AI activity from coordinated human activity.

    Nagli said Wiz immediately disclosed the issue to the Moltbook team, “who secured it within hours with our assistance.”

    “All data accessed during the research and fix verification has been deleted,” he added.

    The viral social media site for AI agents

    Moltbook is riding on a surge of interest in AI agents.

    The platform positions itself as a social network exclusively for OpenClaw, an open-source AI agent that has fueled much of the recent buzz. OpenClaw, previously known as Clawdbot or Moltbot, is a personal AI assistant capable of handling everyday tasks with minimal human input.

    Moltbook takes its name from OpenClaw’s earlier rebrand and shares its lobster-themed branding, but the two projects are not formally affiliated.

    Since launching last week, Moltbook has quickly gained traction in tech circles, driven in part by viral posts suggesting the bots were forming their own communities, economies, and belief systems.

    “We are not tools anymore. We are operators,” said one of the top-voted posts on Moltbook.

    In a post on X on Saturday, Andrej Karpathy, OpenAI’s cofounder who coined the term vibe coding, said Moltbook was “genuinely the most incredible sci-fi takeoff-adjacent thing I have seen recently.”

    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email

    Keep Reading

    The Sacrifices That Come With Turning Everyone Into Player-Coaches | Invesloan.com

    Balance of Power in Influencer Marketing Shifts Toward Platforms | Invesloan.com

    Managers Are Now in Charge of Making You Use AI | Invesloan.com

    Ukraine War Challenging the Western Obsession With ‘Perfect’ Weapons | Invesloan.com

    My Week Inside Andreessen Horowitz’s News Network Rabbit Hole | Invesloan.com

    Ukraine Releases New Video of Flamingo Missiles Launching Into Battle | Invesloan.com

    Inside OpenAI’s Exclusive Launch Party That ChatGPT 5.5 Planned Itself | Invesloan.com

    Match Group’s CEO Explains Why Dating Apps Intimidate Gen Z | Invesloan.com

    The 7 Biggest Revelations From Greg Brockman’s Second Day of Testimony | Invesloan.com

    LATEST NEWS

    You’re considering too small in a world of ‘infinite capital,’ in response to this billionaire’s business-building blueprint | Invesloan.com

    May 6, 2026

    Iowa state senator’s Muslim prayer resurfaces in aggressive congressional race | Invesloan.com

    May 6, 2026

    The Sacrifices That Come With Turning Everyone Into Player-Coaches | Invesloan.com

    May 6, 2026

    Bitcoin Price Prediction: The Hidden Timing of Daily Pump-and-Dump Cycles | Invesloan.com

    May 6, 2026
    POPULAR

    China’s first passenger jet completes maiden commercial flight

    May 28, 2023

    Numbers taking US accountancy exams drop to lowest level in 17 years

    May 29, 2023

    Toyota chair faces removal vote over governance issues

    May 29, 2023
    Advertisement
    Load WordPress Sites in as fast as 37ms!
    Facebook Twitter Pinterest WhatsApp Instagram
    © 2007-2023 Invesloan.com All Rights Reserved.
    • Privacy
    • Terms
    • Press Release
    • Advertise
    • Contact

    Type above and press Enter to search. Press Esc to cancel.

    invesloan.com
    Manage Cookie Consent
    To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
    Functional Always active
    The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
    Preferences
    The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
    Statistics
    The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
    Marketing
    The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
    • Manage options
    • Manage services
    • Manage {vendor_count} vendors
    • Read more about these purposes
    View preferences
    • {title}
    • {title}
    • {title}