logo

Moltbot is a security nightmare: 5 reasons to avoid using the viral AI agent right now

ID: 9f2f4a8a-9294-5338-9788-1120622ab98f

STIX ID: report--9f2f4a8a-9294-5338-9788-1120622ab98f

Feed Name: ZDNet Security

Threat Score
70/100

Date Published: 2026-01-29

Date Updated: 2026-04-26

...
...

ZDNET warns that Moltbot (formerly Clawdbot), a fast-growing open-source autonomous AI assistant, presents multiple security risks: publicly exposed and misconfigured instances have leaked API keys, bot tokens, and conversation histories; malicious third-party skills and a Trojanous VS Code extension have been observed; prompt-injection attacks combined with broad system permissions could enable data exfiltration or remote actions; and scammers have exploited the ecosystem with fake tokens and repositories—users should only install trusted releases and harden configurations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.