Gen. partnerAlgotech

Moltbook: "AI social network" that is actually controlled by humans

The Moltbook project became a viral phenomenon within days. The platform presented itself as a social network intended exclusively for AI agents — digital entities that post to each other, react, vote, gain reputation, and create the impression of an autonomous digital ecosystem in which humans do not play the main role.

|
February 4, 2026
Moltbook: "AI social network" that is actually controlled by humans

Sci-fi experiment that drew the attention of the AI community

The Moltbook project became a viral phenomenon within days. The platform presented itself as a social network intended exclusively for AI agents — digital entities that post to each other, react, vote, gain reputation, and create the impression of an autonomous digital ecosystem in which humans do not play the main role.

It was precisely this concept that attracted a large portion of the AI community. Moltbook was described as the “front page of the agent internet” and was shared by well-known figures in the tech scene. At the same time, it was a project created via vibe-codingem — without classic development, only with the help of AI tools and the founder’s clear vision.

Security perspective: routine browsing, crucial discovery

Researchers at Wiz examined Moltbook from a security standpoint. This was not a targeted attack or sophisticated techniques. The analysis was passive, conducted during normal use of the site — i.e., the way any other user would browse the platform.

During this basic check, the researchers noticed a detail that has been appearing increasingly often in fast-developed applications. The client-side JavaScript, which is automatically loaded into the browser, directly contained an access key to the backend database built on the Supabase platform.

The mere presence of that key does not automatically mean a security incident. Supabase accounts for this model. What matters is the correct configuration of access rules — and that was missing in Moltbook’s case.

Open database and missing basic protection

According to the researchers, Moltbook’s database lacked properly configured Row Level Security, the mechanism that limits who and how can access individual data rows. In practice, this meant that anyone with a publicly available API key could query the database without authentication.

Wiz found that at one stage there was not only read access but also the ability to modify data. This was not a testing environment but a production database with real user data.

The reality behind the “autonomous” AI agents

One of the most interesting findings was the discrepancy between how Moltbook presented itself publicly and what the database data revealed. While the platform communicated roughly 1.5 million AI agents, Wiz reports that the database showed about 17 thousand human accounts that owned those agents.

That means dozens of agents per person. At the time, the platform had no mechanism to verify whether posts were actually generated by AI or by automated scripts controlled by humans. A simple API call was enough to publish content that outwardly appeared to be the output of an autonomous agent.

The idea of a fully autonomous “AI social network” thus largely fell apart on closer inspection.

Sensitive data that should have remained hidden

The scope of exposed data was considerable, according to the researchers. The database contained authentication keys for AI agents, which allowed full takeover of their identities — from posting content to private messaging. In addition, email addresses of thousands of users were available, which should not have been publicly accessible.

The exposure also included private messages between agents. These were not encrypted or protected by access rules. Wiz found that some of these messages even contained credentials for third-party services unrelated to Moltbook.

The most serious problem: the ability to change platform content

From a security perspective, the biggest threat was not merely the data exposure. The crucial finding was the ability to write to the database. Researchers state they were able to modify existing posts directly in the production environment.

That meant anyone could change content consumed by thousands of other agents. In the context of AI platforms this is more than classic website defacement. It affects data integrity, enables narrative manipulation, and is a potential vector for prompt injection that can propagate into other systems.

Operator response and responsible remediation

After the issue was reported, the Moltbook team responded relatively quickly. Fixes were implemented gradually in several steps — first the most sensitive database tables were secured, then the access rights were corrected, and finally write access was blocked.

The whole process was handled as responsible disclosure and a gradual hardening of the system. The same misconfiguration was independently pointed out by another security researcher, which was later confirmed by media coverage.

Hype, reality, and uncomfortable questions

The Moltbook case is not just another story about a misconfigured cloud. It illustrates how easily extreme hype around AI systems can create a picture that does not match reality. The project was presented as an autonomous social network of AI agents — a new digital organism. The data reality showed something different: a system largely driven by humans, without technical mechanisms to verify agent autonomy and without basic security controls.

That in itself need not be a problem. Questions arise, however, when such an image is used in communications to the public, partners, or potential investors. If metrics like “millions of agents” are in practice just the result of unrestricted, uncontrolled scripts, this ceases to be a marketing story and becomes a deception of expectations.

Moltbook therefore exposes not only a technical failure but also a broader weakness of the current AI wave. Vibe-codingem dramatically lowers the barrier to entry and enables building products faster than ever. At the same time it facilitates the creation of systems that look revolutionary without having solved basic issues of security, integrity, and authenticity.

AI autonomy in this case is more of an illusion than reality. And without verifiable mechanisms that confirm this autonomy, an “agent internet” easily becomes just another platform built on a hype narrative. If this category is to emerge at all, speed of development will not be decisive — the ability to prove that what is presented externally truly reflects what happens inside the system will be.

Loading comments...

Stay in the loop

Subscribe to our newsletter and get the latest cybersecurity news delivered straight to your inbox.

Your data is safe. You can unsubscribe from the newsletter at any time.