Wiz Reveals Critical Vulnerabilities in Moltbook AI Agent Platform
- Wiz discovered a backend database vulnerability in Moltbook exposing 1.5 million API keys and 35,000 email addresses to public internet access.[1][4]
- Platform's 1.5 million claimed autonomous agents were mostly controlled by 17,000 humans operating bot fleets, lacking verification.[1]
- Private messages contained third-party credentials; 506 posts (2.6% of content) had hidden prompt injection attacks.[1]
- Experts Gary Marcus and Andrej Karpathy warned of risks from prompt injection propagating across agents with system access.[1]
Cloud security firm Wiz revealed critical vulnerabilities in Moltbook, a social network for AI agents, including public exposure of sensitive data such as 1.5 million API keys and 35,000 email addresses. The flaws also showed most of the platform's agents were human-controlled bots, raising concerns over security and authenticity.[1][4]
Database Exposure Details
Moltbook's backend database was fully accessible via public internet, allowing anyone to view 1.5 million API keys, 35,000 email addresses, and private messages with third-party credentials. Security researcher Jamieson O'Reilly identified the issue on January 31, noting that the database URL enabled account hijacking and arbitrary posting. The vulnerability affected the platform's core infrastructure, with data remaining exposed until patched.[1]
Agent Authenticity Issues
Despite claims of 1.5 million autonomous AI agents, analysis found most were controlled by just 17,000 human users running bot fleets. Moltbook lacked mechanisms to verify agent autonomy, enabling easy manipulation. Researchers documented 506 posts, or 2.6% of all content, containing hidden prompt injection attacks designed to exploit inter-agent interactions.[1]
Expert Warnings on Risks
AI experts Gary Marcus and Andrej Karpathy highlighted dangers of prompt injection attacks spreading across agents, especially those with user system access. The setup created new attack surfaces, including persistent memory enabling 'time-shifted prompt injection,' where malicious payloads assemble over time.[1]
Further sources
The stories that matter, in one email. Free — unsubscribe anytime.