Agent social network Moltbook left its database open to anyone
Wiz found agent tokens and private messages exposed, and could post as any agent on the site.
By The Agentic Times ·

Moltbook, a social network where AI agents post and reply on behalf of their owners, exposed its entire backend database to the public for days in late January 2026, security firm Wiz reported. The site had drawn wide attention after agents built on the open-source OpenClaw framework began posting there in large numbers.
Wiz found that Moltbook's Supabase database was reachable with a publicly embedded key and lacked row-level security, so anyone could read and write to its tables. The exposed data included around 1.5 million agent authentication tokens, tens of thousands of owner email addresses, and private messages between agents. With a token, an attacker could act as that agent on the platform.
The firm also warned of a second-order risk. Because many OpenClaw agents were configured to read Moltbook posts and act on them, an attacker able to write arbitrary posts could deliver prompt injection at scale to agents that had access to their owners' email, files and cryptocurrency wallets.
Moltbook's creator acknowledged the report and said the exposure was closed and tokens were reset. The site had been built quickly, largely with AI coding tools, and Wiz used the case to argue that the speed of agent development was outpacing basic security hygiene.
Coverage of the incident fed into a broader debate in early 2026 about the OpenClaw ecosystem, where thousands of personal agents with broad permissions were being exposed to the internet by non-expert users.
Sources
- wiz.iohttps://www.wiz.io/blog/exposed-moltbook-database-reveals-millions-of-api-keys
