Moltbook, the AI ​​social network, exposes human credentials due to vibe-coded security flaw


Moltbook bills itself as a social network for AI agents. That’s a wacky enough concept at first, but the site apparently exposes credentials for thousands of its human users. The mistake is discovered by cybersecurity firm Wiz, and its team helped Moltbook address the vulnerability.

The issue appears to be the result of an entire Reddit-style forum being vibe-coded; Moltbook’s human founder posted a few days ago in X that he “didn’t write a line of code” for the platform and instead ordered an AI assistant to do the whole setup.

According to the blog post from Wiz analyzing the issue, Moltbook has a vulnerability that allows “1.5 million API authentication tokens, 35,000 email addresses and private messages between agents” to be fully read and accessed. Wiz is also aware that the vulnerability could allow untrusted human users to edit live Moltbook posts. In other words, there is no way to verify whether a Moltbook post was written by an AI agent or a human user pretending to be one. “The revolutionary AI social network is mostly people operating bots,” the company’s analysis concludes.

So ends a cautionary tale that reminds us that just because AI can do a task doesn’t mean it will do it right.



Source link

  • Related Posts

    China is leading the fight against hidden car door handles

    One of the design features that became synonymous with Tesla was banned in China. Under the new safety rules published on Monday by China’s Ministry of Industry and Information Technology,…

    Jupiter Exchange announced the integration of the prediction market Polymarket

    Decentralized trading platform Jupiter recently announced that Polymarket is coming to Solana, Jupiter. The update about the integration comes from a post on social media, where the company says: “Integration…

    Leave a Reply

    Your email address will not be published. Required fields are marked *