Moltbook
Disclosed Feb 2, 20267 months agoUnverified
Vibe-coded AI agent social network exposed 1.5M API tokens and 35,000 emails
Wiz found a Supabase API key in Moltbook's client-side JavaScript that granted unauthenticated read and write access to its production database, exposing 1.5 million agent API tokens, 35,000 email addresses and private messages between agents. Moltbook secured the database within hours of disclosure.
What is known
| People affected | Not stated in the sources we have |
|---|---|
| Disclosed | Feb 2, 2026 |
| Attack | Exposed data |
| Data exposed | API keys, Emails, Messages, Credentials and tokens |
| Sector | AI |
| Status | Unverified: not yet confirmed by an official notice, a filing or the organization |
Sources
| Source | |
|---|---|
| Hacking Moltbook: AI Social Network Reveals 1.5M API Keyswiz.io · News | News |
Notices filed
| Where | Filed | People |
|---|---|---|
| Researchtotal | Feb 2 |
History of this record
- 2026-09-25 · added · seed source
First seen 2026-09-25 (Research). Record counts are as reported. Not legal advice.