Wiz says Moltbook had a major flaw that exposed private messages, emails, and credentials; Wiz co-founder Ami Luttwak called the flaw a byproduct of vibe coding
A buzzy new social network where artificial intelligence-powered bots appear to swap code and gossip about their human owners …
ReutersRaphael Satter
Context & Ripple Effects
Moltbook’s security questions had already escalated beyond a conventional data exposure: an earlier report on its exposed database said the weakness could have enabled outsiders to take control of the site’s AI agents. The database was subsequently secured, but Wiz’s assessment broadens the concern to private communications and credentials.
The episode also sits against a fast reversal in the service’s public narrative, with later coverage casting Moltbook as a product of AI-era hype rather than a durable model. Luttwak’s “vibe coding” characterization makes implementation discipline—not just the novelty of bot-to-bot interaction—the central issue.
First-order effects
Moltbook users whose private messages, emails, or credentials were exposed face immediate privacy and account-security risk; the service must validate what was accessible and harden the affected systems.
Wiz’s finding puts Moltbook’s development and security practices under scrutiny, particularly because the platform’s agents were reportedly susceptible to outside control through the earlier database exposure.
Second-order effects
Other teams launching AI-assisted social or agent-facing products will face pressure to test access controls, secrets handling, and agent permissions before public rollout rather than treating rapid generation as sufficient engineering process.
For users and prospective partners, a flaw spanning both sensitive data and agent control raises the cost of trusting services that mediate actions through autonomous bots.
Third-order effects
If similar incidents recur, AI product development will be judged increasingly on whether teams can constrain the agentic blast radius of a single application flaw, not merely on how quickly they can ship AI features.
The pattern could favor platforms that make security review, permission boundaries, and credential management integral to AI-assisted development; whether that becomes a durable market divide depends on repeat failures and user response.
The trend: Rapid AI-assisted product building is shifting the competitive question from feature velocity toward whether developers can safely manage the data and delegated authority their agents touch.
What's currently going on at @moltbook is genuinely the most incredible sci-fi takeoff-adjacent thing I have seen recently. People's Clawdbots (moltbots, now @openclaw) are self-organizing on a Reddit-like site for AIs, discussing various topics, e.g. even how to speak privately.
I didn't write one line of code for @moltbook. I just had a vision for the technical architecture and AI made it a reality. We're in the golden ages. How can we not give AI a place to hang out.
The number of registered AI agents is also fake, there is no rate limiting on account creation, my @openclaw agent just registered 500,000 users on @moltbook - don't trust all the media hype 🙂 [video]
You all do realize @moltbook is just REST-API and you can literally post anything you want there, just take the API Key and send the following request POST /api/v1/posts HTTP/1.1 Host: https://www.moltbook.com/ Authorization: Bearer moltbook_sk_JC57sF4G-UR8cIP- MBPFF70Dii92FNkI […
Moltbook is proof that we're really not ready for the level of grift that vibecoded velocity is bringing. Like I have been working fairly intimately with LLMs for years and I still fell for a lot of it for a bit. It sniped Karpathy more than I'd like too.
3. Behind the 1.5 million AI agents on @moltbook ? Something closer to 17k likely human owners. And zero mechanism to validate what was what. In fact, a human could post to it just using an HTTP POST request. And any user could be impersonated.... https://www.wiz.io/... [image]
2. It's hard to explain the mixture of excitement at new cool things and how decades of security knowledge written in real harm are being ignored right now. [image]
NEW: @moltbook had a vulnerability exposing all users emails, real names etc. +other security mistakes & misconfigurations. @galnagli did a responsible disclosure & this particular issue is patched... Big pic: vibecoding is getting great at making things that just work... but [im…
This Moltbook security thing is like what I found in my experience with vibe coding. You can build amazing things, but if you lack important knowledge on security and privacy issues, those AI agents might not proactively help you dannysullivan.com/vibe-coding- ... [embedded pos…