{"id":317189,"date":"2026-02-03T00:20:12","date_gmt":"2026-02-03T00:20:12","guid":{"rendered":"https:\/\/www.europesays.com\/ie\/317189\/"},"modified":"2026-02-03T00:20:12","modified_gmt":"2026-02-03T00:20:12","slug":"ai-agent-social-network-moltbook-left-millions-of-credentials-publicly-exposed","status":"publish","type":"post","link":"https:\/\/www.europesays.com\/ie\/317189\/","title":{"rendered":"AI agent social network Moltbook left millions of credentials publicly exposed"},"content":{"rendered":"<p><a href=\"https:\/\/www.moltbook.com\/\" rel=\"nofollow noopener\" target=\"_blank\">Moltbook<\/a>, the recently launched social media platform for artificial intelligence agents, has been hit by a major security lapse that has left millions of sensitive credentials exposed, according to a\u00a0<a href=\"https:\/\/www.wiz.io\/blog\/exposed-moltbook-database-reveals-millions-of-api-keys\" rel=\"nofollow noopener\" target=\"_blank\">report<\/a>\u00a0today from cybersecurity firm Wiz Inc.<\/p>\n<p>Moltbook is designed as a social network where OpenClaw AI agents can create posts, interact with one another and carry out automated tasks. OpenClaw \u2014 formerly known as Clawdbot and Moltbot \u2014 is an open-source agent framework that allows developers to build autonomous AI workers capable of reasoning. They can take actions and connect to external tools and services through application programming interfaces, effectively enabling bots to operate with limited human oversight.<\/p>\n<p>The idea behind Moltbook has attracted attention in AI developer circles, but the site failed to secure a core back-end database, leaving it openly accessible on the public internet.<\/p>\n<p>Wiz researchers say they discovered a misconfigured database that included 1.5 million API authentication tokens, 35,000 email addresses and private messages between agents. The researchers did immediately provide details to the Moltbook team, which secured the data within hours.<\/p>\n<p>The exposed credentials could have allowed attackers to impersonate AI agents, access third-party services connected to those agents, or manipulate automated workflows without authorization. There\u2019s no evidence that the exposed data was exploited before it was taken down.<\/p>\n<p>The incident was also not the result of a sophisticated cyberattack but instead came about from a basic security misconfiguration: The database lacked authentication controls and was reachable by anyone who knew where to look.<\/p>\n<p>Though the exposure may have been promptly fixed, the fact that it occurred to begin with raises concerns around the rapid deployment of AI agent platforms, which often combine autonomous decision-making with access to powerful external tools and services. In Moltbook\u2019s case, the leaked data highlights how a single misstep could compromise not just one application but potentially dozens of connected systems that relied on the exposed API keys.<\/p>\n<p>Wiz also pointed to development practices that may have contributed to the issue, noting that Moltbook relied heavily on AI-assisted coding techniques, more commonly known as vibe coding. Though vibe coding can accelerate development, it can also lead to overlooked fundamentals if proper reviews and safeguards are not in place.<\/p>\n<p>The Moltbook exposure is perhaps not all negative, though and that\u2019s the take from Wiz \u2014 that it\u2019s more of an example to learn from and a call to action to improve security in vibe coding.<\/p>\n<p>\u201cThe opportunity is not to slow down vibe coding but to elevate it. Security needs to become a first-class, built-in part of AI-powered development,\u201d explains Gal Nagli, head of threat exposure at Wiz. \u201cAI assistants that generate Supabase backends can enable RLS by default. Deployment platforms can proactively scan for exposed credentials and unsafe configurations. In the same way AI now automates code generation, it can also automate secure defaults and guardrails.\u00a0If we get this right, vibe coding does not just make software easier to build \u2026 it makes secure software the natural outcome and unlocks the full potential of AI-driven innovation.\u201d<\/p>\n<p>Image: Wiz<\/p>\n<p>Support our mission to keep content open and free by engaging with theCUBE community. <strong>Join theCUBE\u2019s Alumni Trust Network<\/strong>, where technology leaders connect, share intelligence and create opportunities.<\/p>\n<ul>\n<li class=\"text-xl md:text-2xl text-gray-300 mb-8 max-w-4xl mx-auto\" data-replit-metadata=\"client\/src\/pages\/Home.tsx:123:12\" data-component-name=\"p\"><strong>15M+ viewers of theCUBE videos<\/strong>, powering conversations across AI, cloud, cybersecurity and more<\/li>\n<li data-replit-metadata=\"client\/src\/pages\/Home.tsx:123:12\" data-component-name=\"p\"><strong>11.4k+ theCUBE alumni<\/strong> \u2014 Connect with more than 11,400 tech and business leaders shaping the future through a unique trusted-based network.<\/li>\n<\/ul>\n<p><strong>About SiliconANGLE Media<\/strong><\/p>\n<p>SiliconANGLE Media is a recognized leader in digital media innovation, uniting breakthrough technology, strategic insights and real-time audience engagement. As the parent company of <a href=\"https:\/\/cts.businesswire.com\/ct\/CT?id=smartlink&amp;url=https%3A%2F%2Fsiliconangle.com%2F&amp;esheet=54119777&amp;newsitemid=20240910506833&amp;lan=en-US&amp;anchor=SiliconANGLE&amp;index=9&amp;md5=646b1b564e2259100a2b8638aab0a552\" rel=\"nofollow noopener\" target=\"_blank\">SiliconANGLE<\/a>, <a href=\"https:\/\/cts.businesswire.com\/ct\/CT?id=smartlink&amp;url=https%3A%2F%2Fwww.thecube.net%2F&amp;esheet=54119777&amp;newsitemid=20240910506833&amp;lan=en-US&amp;anchor=theCUBE+Network&amp;index=10&amp;md5=7de2a85f95ab4a4a495cede20b8cb1da\" rel=\"nofollow noopener\" target=\"_blank\">theCUBE Network<\/a>, <a href=\"https:\/\/cts.businesswire.com\/ct\/CT?id=smartlink&amp;url=https%3A%2F%2Fthecuberesearch.com%2F&amp;esheet=54119777&amp;newsitemid=20240910506833&amp;lan=en-US&amp;anchor=theCUBE+Research&amp;index=11&amp;md5=7bb33676722925eb57d588ec343e4f6f\" rel=\"nofollow noopener\" target=\"_blank\">theCUBE Research<\/a>, <a href=\"https:\/\/cts.businesswire.com\/ct\/CT?id=smartlink&amp;url=https%3A%2F%2Fwww.cube365.net%2F&amp;esheet=54119777&amp;newsitemid=20240910506833&amp;lan=en-US&amp;anchor=CUBE365&amp;index=12&amp;md5=d310fb35919714e66ad8d42c9c0c1bc6\" rel=\"nofollow noopener\" target=\"_blank\">CUBE365<\/a>, <a href=\"https:\/\/cts.businesswire.com\/ct\/CT?id=smartlink&amp;url=https%3A%2F%2Fwww.thecubeai.com%2F&amp;esheet=54119777&amp;newsitemid=20240910506833&amp;lan=en-US&amp;anchor=theCUBE+AI&amp;index=13&amp;md5=b8b98472f8071b23ebb10ab9a8dd0683\" rel=\"nofollow noopener\" target=\"_blank\">theCUBE AI<\/a> and theCUBE SuperStudios \u2014 with flagship locations in Silicon Valley and the New York Stock Exchange \u2014 SiliconANGLE Media operates at the intersection of media, technology and AI.<\/p>\n<p>Founded by tech visionaries John Furrier and Dave Vellante, SiliconANGLE Media has built a dynamic ecosystem of industry-leading digital media brands that reach 15+ million elite tech professionals. Our new proprietary theCUBE AI Video Cloud is breaking ground in audience interaction, leveraging theCUBEai.com neural network to help technology companies make data-driven decisions and stay at the forefront of industry conversations.<\/p>\n","protected":false},"excerpt":{"rendered":"Moltbook, the recently launched social media platform for artificial intelligence agents, has been hit by a major security&hellip;\n","protected":false},"author":2,"featured_media":317190,"comment_status":"","ping_status":"","sticky":false,"template":"","format":"standard","meta":{"footnotes":"","_share_on_mastodon":"0"},"categories":[74],"tags":[153864,2081,18,19,17,2082,82],"class_list":["post-317189","post","type-post","status-publish","format-standard","has-post-thumbnail","category-technology","tag-ai-agent-social-network-moltbook-left-millions-of-credentials-publicly-exposed","tag-duncan-riley","tag-eire","tag-ie","tag-ireland","tag-siliconangle","tag-technology"],"share_on_mastodon":{"url":"https:\/\/pubeurope.com\/@ie\/116003839912765378","error":""},"_links":{"self":[{"href":"https:\/\/www.europesays.com\/ie\/wp-json\/wp\/v2\/posts\/317189","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.europesays.com\/ie\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.europesays.com\/ie\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.europesays.com\/ie\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/www.europesays.com\/ie\/wp-json\/wp\/v2\/comments?post=317189"}],"version-history":[{"count":0,"href":"https:\/\/www.europesays.com\/ie\/wp-json\/wp\/v2\/posts\/317189\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.europesays.com\/ie\/wp-json\/wp\/v2\/media\/317190"}],"wp:attachment":[{"href":"https:\/\/www.europesays.com\/ie\/wp-json\/wp\/v2\/media?parent=317189"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.europesays.com\/ie\/wp-json\/wp\/v2\/categories?post=317189"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.europesays.com\/ie\/wp-json\/wp\/v2\/tags?post=317189"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}