Security Analysis of Moltbook Agent Network: Bot-to-Bot Prompt Injection and Data Leaks
securityweek
Cybersecurity firms have analyzed the AI agent social network Moltbook and found a vulnerability exposing sensitive data, as well as malicious activity conducted by the bots.
Moltbook emerged following the launch of OpenClaw (previously Clawdbot and Moltbot), an open source, self-hosted AI agent that can autonomously perform a wide range of activities, from executing terminal commands to sending emails.
The increasing popularity of OpenClaw led to the creation of ClawHub (MoltHub), a marketplace for OpenClaw skills, and Moltbook, a social network for the AI agents themselves.
Moltbook has been in the news for the interesting ways its AI agents interact with each other and the discussions they have.
However, an analysis by security experts revealed some concerning aspects. Researchers at cloud security giant Wiz discovered an exposed API key that granted read and write access to the entire Moltbook production database.
“The exposure included 1.5 million API authentication tokens ...
Copyright of this story solely belongs to securityweek . To see the full text click HERE

