← Back to BrewedIntel
incidenthighCredential LeakData Exposure

Feb 02, 2026 • Wiz Security Research

Hacking Moltbook: The AI Social Network Any Human Can Control

A significant data exposure incident has been identified involving the AI social network platform known as Moltbook. Investigation reveals a single exposed...

Source
Wiz Security Research
Category
incident
Severity
high

Executive Summary

A significant data exposure incident has been identified involving the AI social network platform known as Moltbook. Investigation reveals a single exposed database containing approximately 35,000 user email addresses and a staggering 1.5 million API keys. This breach highlights critical security misconfigurations within the platform's infrastructure, potentially allowing unauthorized actors to gain initial access to user accounts and associated services. While no specific threat actor or malware family has been attributed to this incident thus far, the scale of exposed credentials poses a severe risk of account takeover and further network compromise. The revelation that 17,000 humans are behind the supposedly autonomous network suggests complex operational dependencies. Immediate mitigation requires revoking all exposed API keys, enforcing multi-factor authentication, and conducting a comprehensive audit of database access controls to prevent future unauthorized data exposure and protect user integrity.

Summary

1 exposed database. 35,000 emails. 1.5M API keys. And 17,000 humans behind the not-so-autonomous AI network.

Published Analysis

A significant data exposure incident has been identified involving the AI social network platform known as Moltbook. Investigation reveals a single exposed database containing approximately 35,000 user email addresses and a staggering 1.5 million API keys. This breach highlights critical security misconfigurations within the platform's infrastructure, potentially allowing unauthorized actors to gain initial access to user accounts and associated services. While no specific threat actor or malware family has been attributed to this incident thus far, the scale of exposed credentials poses a severe risk of account takeover and further network compromise. The revelation that 17,000 humans are behind the supposedly autonomous network suggests complex operational dependencies. Immediate mitigation requires revoking all exposed API keys, enforcing multi-factor authentication, and conducting a comprehensive audit of database access controls to prevent future unauthorized data exposure and protect user integrity. 1 exposed database. 35,000 emails. 1.5M API keys. And 17,000 humans behind the not-so-autonomous AI network. 1 exposed database. 35,000 emails. 1.5M API keys. And 17,000 humans behind the not-so-autonomous AI network.