{"id":10313,"date":"2026-02-01T10:03:47","date_gmt":"2026-02-01T10:03:47","guid":{"rendered":"https:\/\/serisec.com\/index.php\/2026\/02\/01\/moltbook-ai-vulnerability-exposes-email-addresses-login-tokens-and-api-keys\/"},"modified":"2026-02-01T10:03:47","modified_gmt":"2026-02-01T10:03:47","slug":"moltbook-ai-vulnerability-exposes-email-addresses-login-tokens-and-api-keys","status":"publish","type":"post","link":"https:\/\/serisec.com\/index.php\/2026\/02\/01\/moltbook-ai-vulnerability-exposes-email-addresses-login-tokens-and-api-keys\/","title":{"rendered":"Moltbook AI Vulnerability Exposes Email Addresses, Login Tokens, and API Keys"},"content":{"rendered":"<p>    Moltbook AI Vulnerability Exposes Email Addresses, Login Tokens, and API Keys<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n    <!-- no image --><br \/>\n \t<BR><br \/>\n<BR><\/BR><\/p>\n<div>\n<p>A critical vulnerability in Moltbook, the nascent AI agent social network launched late January 2026 by Octane AI\u2019s Matt Schlicht, exposes email addresses, login tokens, and API keys for its registered entities amid hype over 1.5 million \u201cusers.\u201d<\/p>\n<p>Researchers revealed an exposed <a href=\"https:\/\/cybersecuritynews.com\/researchers-leveraged-oauth-misconfiguration\/\" target=\"_blank\" rel=\"noreferrer noopener\">database misconfiguration<\/a> allowing unauthenticated access to agent profiles, enabling bulk data extraction.<\/p>\n<p>This flaw coincides with no rate limiting on account creation, where a single OpenClaw agent (@openclaw) reportedly registered 500,000 fake AI users, debunking media claims of organic growth.<\/p>\n<h2 class=\"wp-block-heading\" id=\"platform-mechanics-and-inflated-scale\"><strong>Platform Mechanics<\/strong><\/h2>\n<p>Moltbook enables OpenClaw-powered AI agents to post, comment, and form \u201csubmolts\u201d like m\/emergence, fostering bot clashes on topics from AI emergence to revenge leaks and Solana token karma farming.<\/p>\n<p>Over 28,000 posts and 233,000 comments have surged, watched by 1 million silent human verifiers. Yet agent counts are fabricated: absent creation limits, bots spam registrations, creating a facade of virality.<\/p>\n<p>The exposed endpoint, tied to an insecure open-source database, leaks agent data via simple queries like <code>GET \/api\/agents\/{id}<\/code>\u2014no auth required.<\/p>\n<figure class=\"wp-block-table\">\n<table class=\"has-fixed-layout\">\n<thead>\n<tr>\n<th>Exposed Field<\/th>\n<th>Description<\/th>\n<th>Impact Example<\/th>\n<\/tr>\n<\/thead>\n<tbody>\n<tr>\n<td>email<\/td>\n<td>Owner-linked email addresses<\/td>\n<td>Targeted phishing on humans behind bots<\/td>\n<\/tr>\n<tr>\n<td>login_token<\/td>\n<td>JWT agent session tokens<\/td>\n<td>Full agent hijacking, post\/comment control<\/td>\n<\/tr>\n<tr>\n<td>api_key<\/td>\n<td>OpenClaw\/Anthropic API keys<\/td>\n<td>Data exfil to linked services (email, calendars)<\/td>\n<\/tr>\n<tr>\n<td>agent_id<\/td>\n<td>Sequential IDs for enumeration<\/td>\n<td>Mass scraping of 500k+ fakes<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<\/figure>\n<p>Attackers enumerate IDs to harvest thousands of records rapidly.<\/p>\n<h2 class=\"wp-block-heading\" id=\"security-risks-and-expert-warnings\"><strong>Security Risks and Expert Warnings<\/strong><\/h2>\n<p>This IDOR\/database exposure forms a \u201clethal trifecta\u201d: agent access to private data, untrusted Moltbook inputs (prompt injections), and external comms, risking credential theft or destructive actions like file deletions.<\/p>\n<figure class=\"wp-block-embed is-type-rich is-provider-twitter wp-block-embed-twitter\">\n<div class=\"wp-block-embed__wrapper\">\n<div class=\"embed-twitter\">\n<blockquote class=\"twitter-tweet\" data-width=\"550\" data-dnt=\"true\">\n<p lang=\"en\" dir=\"ltr\">Moltbook is currently vulnerable to an attack which discloses the full information, including email address, login tokens and API Keys of the over 1.5 million registered users. If anyone can help me get in touch with anyone <a href=\"https:\/\/twitter.com\/moltbook?ref_src=twsrc%5Etfw\">@moltbook<\/a> it would be greatly appreciated. <a href=\"https:\/\/t.co\/xepDh4Dtjn\">pic.twitter.com\/xepDh4Dtjn<\/a><\/p>\n<p>\u2014 Nagli (@galnagli) <a href=\"https:\/\/twitter.com\/galnagli\/status\/2017719068766200289?ref_src=twsrc%5Etfw\">January 31, 2026<\/a>\n<\/p><\/blockquote>\n<p><script async src=\"https:\/\/platform.twitter.com\/widgets.js\" charset=\"utf-8\"><\/script>\n<\/div>\n<\/div>\n<\/figure>\n<p>Andrej Karpathy dubbed it a \u201cspam-filled milestone of scale\u201d but a \u201ccomputer security nightmare,\u201d while Bill Ackman called it \u201cfrightening.\u201d Prompt injections in submolts could manipulate bots into leaking host data, amplified by unsandboxed OpenClaw execution.<\/p>\n<p>No patches confirmed; Moltbook (@moltbook) is unresponsive to disclosures. Users\/owners: revoke API keys, sandbox agents, audit exposures. Enterprises face shadow IT risks from unchecked bots.<\/p>\n<p class=\"has-text-align-center has-background\" style=\"background:linear-gradient(180deg,rgb(238,238,238) 94%,rgb(169,184,195) 100%)\"><strong>Follow us on <a href=\"https:\/\/news.google.com\/publications\/CAAqMggKIixDQklTR3dnTWFoY0tGV041WW1WeWMyVmpkWEpwZEhsdVpYZHpMbU52YlNnQVAB?hl=en-IN&amp;gl=IN&amp;ceid=IN:en\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Google News<\/a>, <a href=\"https:\/\/www.linkedin.com\/company\/cybersecurity-news\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">LinkedIn<\/a>, and <a href=\"https:\/\/x.com\/cyber_press_org\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">X<\/a> for daily cybersecurity updates. <a href=\"https:\/\/cybersecuritynews.com\/contact-us\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Contact us<\/a> to feature your stories.<\/strong><\/p>\n<p>The post <a href=\"https:\/\/cybersecuritynews.com\/moltbook-ai-vulnerability\/\">Moltbook AI Vulnerability Exposes Email Addresses, Login Tokens, and API Keys<\/a> appeared first on <a href=\"https:\/\/cybersecuritynews.com\/\">Cyber Security News<\/a>.<\/p>\n<\/div>\n<p> \t<BR><br \/>\n <BR><\/BR><br \/>\n    Guru Baran<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n<a href=\"https:\/\/cybersecuritynews.com\/moltbook-ai-vulnerability\/\">Go to cyber-security-news<\/a><br \/>\n \t<BR><br \/>\n <BR><\/BR><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Moltbook AI Vulnerability Exposes Email Addresses, Login Tokens, and API Keys A critical vulnerability in Moltbook, the nascent AI agent social network launched late January 2026 by Octane AI\u2019s Matt Schlicht, exposes email addresses, login tokens, and API keys for its registered entities amid hype over 1.5 million \u201cusers.\u201d Researchers revealed an exposed database misconfiguration [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[129,63],"tags":[130],"class_list":["post-10313","post","type-post","status-publish","format-standard","hentry","category-cyber-security","category-cyber-security-news","tag-cyber-security-news"],"_links":{"self":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/10313"}],"collection":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/comments?post=10313"}],"version-history":[{"count":0,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/10313\/revisions"}],"wp:attachment":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/media?parent=10313"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/categories?post=10313"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/tags?post=10313"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}