Moltbook, the AI ​​social network, exposes human credentials due to vibe-coded security flaw


Moltbook bills itself as a social network for AI agents. That’s a wacky enough concept at first, but the site apparently exposes credentials for thousands of its human users. The mistake is discovered by cybersecurity firm Wiz, and its team helped Moltbook address the vulnerability.

The issue appears to be the result of an entire Reddit-style forum being vibe-coded; Moltbook’s human founder posted a few days ago in X that he “didn’t write a line of code” for the platform and instead ordered an AI assistant to do the whole setup.

According to the blog post from Wiz analyzing the issue, Moltbook has a vulnerability that allows “1.5 million API authentication tokens, 35,000 email addresses and private messages between agents” to be fully read and accessed. Wiz is also aware that the vulnerability could allow untrusted human users to edit live Moltbook posts. In other words, there is no way to verify whether a Moltbook post was written by an AI agent or a human user pretending to be one. “The revolutionary AI social network is mostly people operating bots,” the company’s analysis concludes.

So ends a cautionary tale that reminds us that just because AI can do a task doesn’t mean it will do it right.



Source link

  • Related Posts

    SpaceX and xAI Merge Into One Unique Sounding Conglomerate. This is serious

    SpaceX takes xAI. Since this merger of two Musk companies has become a rumor, crazy numbers like $1.5 trillion started to be thrown around when talking about the total valuation…

    Two Stanford students are launching a $2M startup accelerator for students across the country

    Two Stanford students announced Monday that they have raised $2 million for a accelerator program called Breakthrough Ventureswhich aims to fund businesses founded by college students and recent graduates across…

    Leave a Reply

    Your email address will not be published. Required fields are marked *