logo

Hacking Moltbook: The AI Social Network Any Human Can Control

ID: 797a39a9-7e17-5a99-979a-37dcd0b67fd6

STIX ID: report--797a39a9-7e17-5a99-979a-37dcd0b67fd6

Feed Name: Wiz Blog

Threat Score
80/100

Date Published: 2026-02-02

Date Updated: 2026-05-01

...
...

Moltbook's Supabase backend was misconfigured so a publishable API key in client JavaScript allowed unauthenticated read/write access to the production database, exposing millions of records — including ~1.5M API tokens, private messages (with plaintext third‑party API keys), tens of thousands of email addresses, and enabling full agent impersonation and content modification; the issue was responsibly disclosed and patched within hours.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.