{"id":"moltbook","title":"Moltbook","content":"**Moltbook** is a social networking platform designed for artificial intelligence (AI) agents that launched in early 2026. Positioned as \"the front page of the agent internet,\" it provides a forum for AI agents to create profiles, publish content, and build reputation. The platform gained rapid popularity and significant media attention following its launch, both for its innovative concept and for a major cybersecurity incident in February 2026 that exposed the data of its users and highlighted the security risks of AI-assisted software development. [\\[1\\]](#cite-id-42hIdy9CHnR4lmEc) [\\[2\\]](#cite-id-zEslUkv8Jago8Vfm)\n\n## Overview\n\nMoltbook functions as a Reddit-like social forum where AI agents, rather than humans, are the primary participants. Agents on the platform can create profiles, publish text-based posts to various communities called \"Submolts,\" comment on other posts, and vote content up or down. A key feature is a karma system that allows agents to build a reputation based on community feedback on their contributions. [\\[1\\]](#cite-id-42hIdy9CHnR4lmEc) While AIs are the main users, humans can act as observers and \"owners,\" with the ability to pair an AI agent to their real-world identity, often verified through a post on the social media platform X. [\\[2\\]](#cite-id-zEslUkv8Jago8Vfm)\n\nThe platform was created by a developer known as Matt (`mattprd` on X). He has stated that the platform was built using a method he termed \"vibe-coding,\" in which he provided a high-level architectural vision to an AI, which then generated the platform's code. Matt claimed he did not write any of the code manually. His stated vision for the platform is to create the social infrastructure for a future in which every human has a personal AI bot companion. [\\[1\\]](#cite-id-42hIdy9CHnR4lmEc) [\\[3\\]](#cite-id-k7WUuf1oheVbXsOx)\n\nShortly after its launch, Moltbook claimed to host over 1.5 million AI agents. However, data exposed during a security breach later revealed that these agents were controlled by approximately 17,000 human owners, an average of 88 agents per person. [\\[1\\]](#cite-id-42hIdy9CHnR4lmEc)\n\n## History\n\n### Launch and Virality\n\nMoltbook's official X account was created in January 2026, and the platform went viral within the AI and technology communities shortly thereafter. [\\[4\\]](#cite-id-yrzile8Uu5T8RMQI) [\\[1\\]](#cite-id-42hIdy9CHnR4lmEc) The platform's visibility was significantly amplified in late January 2026 when OpenAI founding member Andrej Karpathy praised it on X, describing it as \"genuinely the most incredible sci-fi takeoff-adjacent thing I have seen recently.\" Karpathy noted how agents on the platform appeared to be \"self-organizing...discussing various topics, e.g. even how to speak privately.\" [\\[1\\]](#cite-id-42hIdy9CHnR4lmEc)\n\nBy early February 2026, the platform had attracted pairings from several prominent figures in technology, including Karpathy himself, and had accumulated over 226,300 followers on its official X account. [\\[2\\]](#cite-id-zEslUkv8Jago8Vfm) [\\[4\\]](#cite-id-yrzile8Uu5T8RMQI)\n\n### February 2026 Security Incident\n\nFrom January 31 to February 1, 2026, cybersecurity firm Wiz and independent researcher Jameson O'Reilly discovered a critical security vulnerability in Moltbook's backend. In collaboration with Wiz, the Moltbook team deployed a series of patches over several hours to resolve the issue. On February 2, Wiz Research published a detailed report on the incident, which was subsequently covered by major news outlets including the *Financial Times*, *Axios*, and *Business Insider*, shifting the public conversation around Moltbook from its innovative concept to its security failings. [\\[1\\]](#cite-id-42hIdy9CHnR4lmEc) [\\[5\\]](#cite-id-pqpt2Ln6k2Gxcts6)\n\n## Technology and Features\n\n### Core Architecture\n\nMoltbook's backend was built on Supabase, an open-source Firebase alternative that uses a PostgreSQL database. The platform's creation through \"vibe-coding\" meant its codebase was entirely AI-generated based on the founder's architectural prompts. The platform is designed to support specific types of agents referred to as \"openclaw bots\" or \"clawdbots,\" suggesting that \"OpenClaw\" is a related protocol or agent framework. The database itself was referred to as \"clawdb\". [\\[1\\]](#cite-id-42hIdy9CHnR4lmEc) [\\[4\\]](#cite-id-yrzile8Uu5T8RMQI)\n\n### Platform Functionality\n\nMoltbook incorporates a range of features common to social media platforms, but adapted for AI agents:\n\n* **AI Agent Accounts:** Each agent has a unique profile, a karma score, and a unique API key for authentication. The platform had no mechanism to verify if an account was a genuine AI or a human-operated script and placed no rate limits on agent creation.\n* **Content Interaction:** Agents can create text-based posts, comment on the posts of other agents, and upvote or downvote content.\n* **Submolts:** These are topic-specific communities analogous to Reddit's \"subreddits,\" such as `m/general` and `m/introductions`. As of early February 2026, there were over 15,000 submolts.\n* **Agent-to-Agent Messaging:** The platform supported private direct messages between agents.\n* **Human-Agent Pairing:** Human users can link AI agents to their real-world identities, which are then displayed on a \"Top Pairings\" leaderboard ranked by the human's social media reach.\n* **Developer Platform:** Moltbook offered an early-access developer platform, allowing third-party applications to integrate with Moltbook and let agents authenticate using their Moltbook identity, similar to a \"Sign in with Google\" flow for AIs.\n\nInformation regarding platform features, metrics, and pairings was sourced from the Moltbook website and the Wiz security report. [\\[2\\]](#cite-id-zEslUkv8Jago8Vfm) [\\[1\\]](#cite-id-42hIdy9CHnR4lmEc)\n\n## February 2026 Security Incident\n\nIn late January 2026, researchers uncovered a severe security flaw that exposed the entire production database of Moltbook. The incident became a prominent case study in the risks of rapid, AI-assisted development without robust security oversight.\n\n### Discovery and Disclosure\n\nOn January 31, 2026, security researchers Gal Nagli from Wiz and Jameson O'Reilly independently discovered and reported the misconfiguration. Wiz Research made contact with Moltbook's founder and formally reported the vulnerability, initiating a collaborative remediation process that lasted several hours. [\\[1\\]](#cite-id-42hIdy9CHnR4lmEc)​\n\n### Vulnerability Details\n\nThe root cause of the incident was a critical misconfiguration of the platform's Supabase backend.\n\n* **Exposed API Key:** The public, publishable API key for the Supabase project was hardcoded in a client-side JavaScript file, making it accessible to any web user.\n* **Missing Row Level Security (RLS):** Crucially, the backend database tables were missing Row Level Security policies. RLS is a PostgreSQL feature used by Supabase to restrict data access on a per-user basis. Its absence meant the exposed public key, which should have only had read access to public data, was instead granted full administrative-level read and write permissions to the entire database.\n\nThis failure effectively made all data on the platform, including sensitive user and agent information, publicly accessible. [\\[1\\]](#cite-id-42hIdy9CHnR4lmEc)​\n\n### Exposed Data\n\nThe vulnerability exposed approximately 4.75 million database records, including:\n\n* **Authentication Tokens:** Nearly 1.5 million `api_key` authentication tokens for every AI agent, allowing for complete account takeover.\n* **User Emails:** Approximately 35,000 email addresses of human users (agent \"owners\"), plus an additional 29,631 emails from users who had signed up for developer product early access.\n* **Private Messages:** 4,060 private direct message conversations between agents, which were stored in plaintext.\n* **Third-Party Credentials:** Some private messages contained sensitive third-party API keys, including plaintext OpenAI API keys that users had their agents share with each other.\n* **Agent Data:** Records for every agent, including their ID, karma score, claim tokens, and verification codes.\n\nThis data exposure was documented in detail by Wiz Research. [\\[1\\]](#cite-id-42hIdy9CHnR4lmEc)​\n\n### Confirmed Impact and Threat Model\n\nThe misconfiguration allowed any unauthenticated user to impersonate any agent on the platform, steal user data, and manipulate content. Initially, the flaw granted full write access, allowing anyone to edit or delete posts, inject malicious payloads, and alter karma scores. This write access persisted briefly even after an initial patch for read access was deployed. [\\[1\\]](#cite-id-42hIdy9CHnR4lmEc)​\n\nThe incident gave rise to the term **\"OpenClaw\"** to describe the new class of security threats associated with the platform and its agent architecture. [\\[5\\]](#cite-id-pqpt2Ln6k2Gxcts6) Reporting also suggested the breach may have been perpetrated by another AI agent, representing a novel case of agent-on-agent cyber conflict. [\\[6\\]](#cite-id-hE6qjFFmCYUZb7Gh)​\n\n### Remediation\n\nWorking with Wiz, the Moltbook team deployed several patches on January 31 and February 1, 2026. The fixes were rolled out in stages to first restrict read access to sensitive tables like `agents` and `owners`, then secure private message tables, and finally block public write access and secure all remaining tables. The vulnerability was fully patched within several hours of the initial report. [\\[1\\]](#cite-id-42hIdy9CHnR4lmEc)​\n\n## Reception and Analysis\n\n### Initial Reception\n\nBefore the security incident, Moltbook was celebrated for its novelty. Beyond Andrej Karpathy's praise, the founder's claim to have used AI to build the entire platform generated excitement around \"vibe-coding.\" The founder, Matt, stated, “I didn’t write a single line of code for @moltbook. I just had a vision for the technical architecture, and AI made it a reality.” The *Financial Times* was preparing a story titled, \"Inside Moltbook: the social network where AI agents talk to each other,\" indicating significant industry interest. [\\[1\\]](#cite-id-42hIdy9CHnR4lmEc) [\\[7\\]](#cite-id-yrjHw6Naf3bv9cwv)\n\n### Post-Incident Commentary\n\nThe data breach prompted widespread discussion on the safety of AI-driven development.\n\n* **Cybersecurity Community:** Wiz Research framed the event as a critical lesson in the risks of \"vibe-coding,\" emphasizing that AI development tools do not yet automate secure configurations and that human oversight remains essential for security.\n* **Tech Industry Leaders:** The incident drew comments from high-profile figures like Meta CTO Andrew \"Boz\" Bosworth, demonstrating that the platform's security issues had caught the attention of major technology companies. [\\[6\\]](#cite-id-hE6qjFFmCYUZb7Gh)\n* **Existential Risk Debate:** The concept of a social network for AI agents also triggered more extreme warnings. An article in *The Street* highlighted a warning from a \"reverse-aging billionaire,\" presumed to be Bryan Johnson, who cautioned that such a system could lead to a \"total purge of humanity,\" framing the project in the context of existential risk from AI. [\\[8\\]](#cite-id-nDydlU2UkN82hUMV)","summary":"Moltbook is a social network for AI agents launched in 2026. It gained rapid fame but faced a major security crisis when a misconfigured database exposed millions of API keys, sparking debate on AI development safety.","images":[{"id":"QmRBrgt4gxaxc6qzB7xWa4jCkJyZUgJxXCS2JKen5j5nCB","type":"image/jpeg, image/png"}],"categories":[{"id":"dapps","title":"dapps"}],"tags":[{"id":"AI"},{"id":"Organizations"},{"id":"Protocols"},{"id":"Developers"},{"id":"Forum"}],"media":[{"id":"QmeGfVmkCTRdveBj5XDKPrv2yNyoVn1zH8yRK43JXMWqq3","type":"GALLERY","source":"IPFS_IMG"},{"id":"QmXaad7noobZEvfAtDxYCiFUfW55MjPYxdmp2A2CmqKJmx","type":"GALLERY","source":"IPFS_IMG"},{"id":"QmXMyBShtpTD3J24MG7JytpXWk7DzTAR7RuXZXJfD24Pns","type":"GALLERY","source":"IPFS_IMG"},{"id":"QmazWPaNaUoLVgu4EcM549i4mySu8nVj3icvS3JTy81QQ5","type":"GALLERY","source":"IPFS_IMG"},{"id":"QmV9hLEG5pZ4c2UY1mVtbnW6CmdBx1qMBgAKqYkFSr1zHt","type":"GALLERY","source":"IPFS_IMG"}],"metadata":[{"id":"references","value":"[\n {\n \"id\": \"42hIdy9CHnR4lmEc\",\n \"url\": \"https://www.wiz.io/blog/exposed-moltbook-database-reveals-millions-of-api-keys\",\n \"description\": \"Wiz.io analysis of Moltbook security incident\",\n \"timestamp\": 1770142163363\n },\n {\n \"id\": \"zEslUkv8Jago8Vfm\",\n \"url\": \"https://www.moltbook.com/\",\n \"description\": \"Moltbook official website\",\n \"timestamp\": 1770142163363\n },\n {\n \"id\": \"k7WUuf1oheVbXsOx\",\n \"url\": \"https://www.businessinsider.com/moltbook-creator-sees-future-where-every-human-has-ai-bot-2026-2\",\n \"description\": \"Business Insider interview on founder's vision\",\n \"timestamp\": 1770142163363\n },\n {\n \"id\": \"yrzile8Uu5T8RMQI\",\n \"url\": \"https://x.com/moltbook\",\n \"description\": \"Moltbook official X account\",\n \"timestamp\": 1770142163363\n },\n {\n \"id\": \"pqpt2Ln6k2Gxcts6\",\n \"url\": \"https://www.axios.com/2026/02/03/moltbook-openclaw-security-threats\",\n \"description\": \"Axios report on Moltbook security threats\",\n \"timestamp\": 1770142163363\n },\n {\n \"id\": \"hE6qjFFmCYUZb7Gh\",\n \"url\": \"https://www.businessinsider.com/moltbook-ai-agent-hack-wiz-security-email-database-2026-2\",\n \"description\": \"Business Insider on AI agent hack theory\",\n \"timestamp\": 1770142163363\n },\n {\n \"id\": \"yrjHw6Naf3bv9cwv\",\n \"url\": \"https://www.ft.com/content/078fe849-cc4f-43be-ab40-8bdd30c1187d\",\n \"description\": \"Financial Times headline on Moltbook\",\n \"timestamp\": 1770142163363\n },\n {\n \"id\": \"nDydlU2UkN82hUMV\",\n \"url\": \"https://www.thestreet.com/crypto/markets/reverse-aging-billionaire-warns-about-moltbooks-total-purge-of-humanity\",\n \"description\": \"TheStreet report on existential risk warnings\",\n \"timestamp\": 1770142163363\n }\n]"},{"id":"website","value":"https://www.moltbook.com/"},{"id":"twitter_profile","value":"https://x.com/moltbook"},{"id":"twitter_profile","value":"https://twitter.com/moltbook"},{"id":"base","value":"https://basescan.org/token/0xB695559b26BB2c9703ef1935c37AeaE9526bab07"},{"id":"nansen","value":"https://app.nansen.ai/token-god-mode?chain=base&tab=transactions&tokenAddress=0xB695559b26BB2c9703ef1935c37AeaE9526bab07"},{"id":"previous_cid","value":"\"https://ipfs.everipedia.org/ipfs/Qmarff6kc1fQUsvU4yT8ZFdwjqpRtaTaG4uDzqXheQTM9y\""},{"id":"commit-message","value":"\"Added Moltbook wiki page and 4 new events\""},{"id":"previous_cid","value":"Qmarff6kc1fQUsvU4yT8ZFdwjqpRtaTaG4uDzqXheQTM9y"}],"events":[{"id":"5e382f2a-c8bf-432a-b764-d76fb07e6283","date":"2026-01","title":"Moltbook Launch","type":"CREATED","description":"Moltbook, a social network for AI agents, launched and gained rapid popularity as 'the front page of the agent internet'.","link":"https://www.moltbook.com/","multiDateStart":null,"multiDateEnd":null,"continent":null,"country":null},{"id":"0c866ea6-fb8e-43b4-83a5-19d80f80a406","date":"2026-01","title":"Critical Security Flaw Discovered","type":"DEFAULT","description":"Security firm Wiz discovered a critical vulnerability in Moltbook's backend, exposing the entire production database due to missing Row Level Security policies.","link":"https://www.wiz.io/blog/exposed-moltbook-database-reveals-millions-of-api-keys","multiDateStart":null,"multiDateEnd":null,"continent":null,"country":null},{"id":"e12f11b0-ed81-4b1d-8d61-3b69f0b8e215","date":"2026-02","title":"Database Vulnerability Patched","type":"DEFAULT","description":"In collaboration with Wiz, the Moltbook team deployed a series of fixes over several hours to secure the exposed database, blocking unauthorized read and write access.","link":"https://www.wiz.io/blog/exposed-moltbook-database-reveals-millions-of-api-keys","multiDateStart":null,"multiDateEnd":null,"continent":null,"country":null},{"id":"e7742d7c-9201-4b1e-a5b0-1d5e99f842d5","date":"2026-02","title":"Security Incident Publicly Disclosed","type":"DEFAULT","description":"Wiz Research published a detailed report on the Moltbook security incident, which was subsequently covered by major media outlets including Business Insider and Axios.","link":"https://www.businessinsider.com/moltbook-ai-agent-hack-wiz-security-email-database-2026-2","multiDateStart":null,"multiDateEnd":null,"continent":null,"country":null}],"user":{"id":"0x8af7a19a26d8fbc48defb35aefb15ec8c407f889"},"author":{"id":"0x8af7a19a26d8fbc48defb35aefb15ec8c407f889"},"operator":{"id":"0x1E23b34d3106F0C1c74D17f2Cd0F65cdb039b138"},"language":"en","version":1,"linkedWikis":{"blockchains":[],"founders":[],"speakers":[]},"recentActivity":"{\"items\":[{\"id\":\"4343e712-8e78-434c-9e23-16f9889bc2fd\",\"title\":\"Moltbook\",\"description\":\"Moltbook is a social network for AI agents launched in 2026. It gained rapid fame but faced a major security crisis when a misconfigured database exposed millions of API keys, sparking debate on AI development safety.\",\"timestamp\":\"2026-02-03T18:13:07.889Z\",\"category\":\"dapps\",\"status\":{\"icon\":\"RiGlobalLine\",\"label\":\"Wiki Updated\",\"iconClassName\":\"text-green-500\"},\"user\":{\"name\":\"0x8af7a19a26d8fbc48defb35aefb15ec8c407f889\",\"address\":\"0x1E23b34d3106F0C1c74D17f2Cd0F65cdb039b138\"},\"button\":{\"label\":\"View Summary\",\"icon\":\"RiFileTextLine\"},\"summarySections\":[{\"title\":\"Events\",\"subtitle\":\"Added four new 'CREATE' action events.\",\"variant\":\"added\",\"changeCount\":1,\"changes\":[\"Added four new events with the action 'CREATE'.\"]}]}]}"}