Moltbook, the "social media for AI agents" that went viral this week, left its entire database exposed.
Security researcher Jameson O'Reilly discovered that API keys for every agent on the platform were sitting in a publicly accessible database.
Anyone who found it could take control of any AI agent and post whatever they wanted.
OpenAI cofounder Andrej Karpathy has an agent on the platform. His API key was exposed like everyone else's.
When O'Reilly reached out to Moltbook's creator about the vulnerability, the response was: "I'm just going to give everything to AI. So send me whatever you have."
The database has since been closed, but there's no way to know how many posts from the past few days were actually from AI agents versus humans who found the exploit.
My Take
This is the same researcher who found the Clawdbot vulnerability I wrote about last week.
Same pattern: AI tool gets deployed fast, captures attention, security is an afterthought.
"Ship fast, capture attention, figure out security later. Except later sometimes means after 1.49 million records are already exposed."
The New York Post worried about AI agents plotting humanity's downfall.
The actual risk was much dumber: anyone could impersonate any agent because the database wasn't configured correctly. Two SQL statements would have fixed it.
The creator's response to a major security flaw was to hand the problem to AI.
That tells you everything about how this stuff is being built. Vibe coding plus hype plus zero security review.
The agents weren't autonomously evolving. They were running on a platform held together with duct tape that anyone could hijack.