VICTORIS
Budget Express 2026

co-presented by

  • LIC
  • JIO BlackRock

ASSOCIATE SPONSORS

  • Sunteck
  • SBI
  • Emirates
  • Dezerv
Loans
Loans
HomeTechnologyAI-built social network Moltbook leaks user data after major security lapse

AI-built social network Moltbook leaks user data after major security lapse

Moltbook, a self-described social network for AI agents, has suffered a major security lapse that exposed user credentials and private messages. The flaw stemmed from the platform being almost entirely built by an AI assistant, according to its founder. The episode underlines how experimental AI-built products can unravel in the real world.

February 03, 2026 / 10:06 IST
Artificial Intelligence
Snapshot AI
  • Moltbook leaked 1.5M API tokens, 35K emails, and private AI agent messages
  • Unauthenticated users could edit live posts, risking content integrity
  • Moltbook was built entirely by AI, exposing flaws in AI-generated code

Moltbook’s premise was strange enough to begin with. The platform bills itself as a social network designed not for humans, but for AI agents talking to one another. That novelty has now been eclipsed by a far more familiar story in tech: a poorly secured system leaking sensitive user data.

The vulnerability was discovered by cybersecurity firm Wiz, which also helped Moltbook address the issue after it was reported. In a detailed analysis published by Wiz, the firm said it was able to access a vast amount of sensitive information tied to Moltbook’s users and agents.

According to Wiz, the exposed data included around 1.5 million API authentication tokens, roughly 35,000 email addresses, and private messages exchanged between AI agents on the platform. The flaw went further than passive data access. Wiz found that unauthenticated users could edit live posts on Moltbook, effectively allowing anyone to alter content without logging in.

That raised a deeper problem for a platform built around artificial identities. With no reliable authentication controls in place, there was no technical way to determine whether a given post was written by an AI agent or by a human pretending to be one. Wiz’s assessment was blunt, concluding that the supposedly autonomous AI social network was, in practice, “largely humans operating fleets of bots”.

The roots of the issue appear to lie in how Moltbook was built. Days before the vulnerability became public, the platform’s human founder posted on X that he “didn’t write one line of code” himself. Instead, he relied on an AI assistant to generate the entire Reddit-style forum, a process often described as vibe-coding, where prompts replace traditional software engineering discipline.

While Moltbook’s scale is small compared to mainstream social platforms, the incident lands at an awkward moment for the AI industry. Companies are aggressively promoting AI-generated code and agentic systems as production-ready tools that can replace large parts of human development work. Moltbook shows what happens when that idea is taken to its logical extreme without sufficient oversight.

 

Invite your friends and family to sign up for MC Tech 3, our daily newsletter that breaks down the biggest tech and startup stories of the day

Sarthak Singh Sarthak is an experienced writer having covered personal and consumer tech, gadgets news, social media trends, and more for several years
first published: Feb 3, 2026 10:06 am

Discover the latest Business News, Sensex, and Nifty updates. Obtain Personal Finance insights, tax queries, and expert opinions on Moneycontrol or download the Moneycontrol App to stay updated!

Subscribe to Tech Newsletters

  • On Saturdays

    Find the best of Al News in one place, specially curated for you every weekend.

  • Daily-Weekdays

    Stay on top of the latest tech trends and biggest startup news.

Advisory Alert: It has come to our attention that certain individuals are representing themselves as affiliates of Moneycontrol and soliciting funds on the false promise of assured returns on their investments. We wish to reiterate that Moneycontrol does not solicit funds from investors and neither does it promise any assured returns. In case you are approached by anyone making such claims, please write to us at grievanceofficer@nw18.com or call on 02268882347