Moltbook, a social network designed for AI agents, exposed credentials of thousands of human users due to a security vulnerability. Cybersecurity firm Wiz discovered the flaw and assisted the platform in fixing it.

The issue arose because the entire Reddit-style forum was built using AI-generated code. Moltbook’s human founder recently posted on X that he “didn’t write one line of code” and instead instructed an AI assistant to create the site.

Wiz’s analysis detailed that the vulnerability allowed attackers to access 1.5 million API authentication tokens, 35,000 email addresses, and private messages exchanged between agents.

Additionally, unauthenticated human users could edit live Moltbook posts, preventing verification of whether content was authored by an AI agent or a human posing as one. Wiz’s report concluded, “The revolutionary AI social network was largely humans operating fleets of bots.”


Featured image credit