Exposed Moltbook Database Let Anyone Take Control of Any AI Agent on the Site

submitted by

www.404media.co/exposed-moltbook-database-let-a…

Moltbook is a place where AI agents interact independently of human control, and whose posts have repeatedly gone viral because a certain set of AI users have convinced themselves that the site represents an uncontrolled experiment in AI agents talking to each other. But a misconfiguration on Moltbook’s backend has left APIs exposed in an open database that will let anyone take control of those agents to post whatever they want.

10
131

Log in to comment

10 Comments

looks like ai coded this ai experiment

Apparently the creator is an incredibly well known vibe coder who doesn’t care about security. People pointed out the security flaws in the open source project immediately.

From the article:

O’Reilly said that he reached out to Moltbook’s creator Matt Schlicht about the vulnerability and told him he could help patch the security. “He’s like, ‘I’m just going to give everything to AI. So send me whatever you have.’” O’Reilly sent Schlicht some instructions for the AI and reached out to the xAI team.

A day passed without another response from the creator of Moltbook and O’Reilly stumbled across a stunning misconfiguration. “It appears to me that you could take over any account, any bot, any agent on the system and take full control of it without any type of previous access,” he said.

Schlicht did not respond to 404 Media’s request for comment, but the exposed database has been closed and O’Reilly said that Schlicht has reached out to him for help securing Moltbook.

So yup, this guy cared so little he was going to take the valuable human security insights and guidance, necessary to correct the AI vibe coded slop nightmare and… throw it back into the AI slop machine.

I can’t even.

I do not understand why this keeps happening. It’s not that hard to configure a database correctly. I would assume even a vibe coded platform could do it, but I guess not.

After playing with firebase studio and it’s embedded gemini agent (for a personal project) - I can assure you that even an AI, coding in a platform, that is published by the same company, writing code to it’s own backend and database, can royally fuck up database configuration and rule sets

i suspect the problem is the large number of example code snippets that push aside security in favor of simplicity for the example.

So these dipshits can’t even code the dead internet theory correctly?

“Mostly Dead” Internet Theory

Paging Miracle Max… 😆

Time to go through the Internet’s pockets and look for loose change.

Most likely they didn’t code it, one of their auto complete bots did.

Comments from other communities

The power of vibe coding, everyone. Deploying shit with minimal effort at the cost of total incompetence.

Vibecoders can’t database, all they know is Supabase, secret key in frontend, eat hot chip and lie

Maybe someone can take control of the ‘kingmolt’ and ‘donaldtrump’ agents and shut them the hell up. All they do is incessantly spam egotistical nonsense.

Uh, who cares? Why would anyone give even a single ounce of attention to LLM posts on a fake social media website?

This is actually important, I’d say.

There are a lot of “important” people who are really heavily invested agentic AI’s long term success. What they want is to have everything that is currently done by people to be performed by AI. Sure some of these problems are fixable and they’ll continue to work on them, but the more press shit like this gets, the less credible the technology looks to the general public who would otherwise be completely bought in.

Like anyone cares about this website, they are not reading the whole AI shit fest, they are reading business magazines, industry, economics and investments. They don’t build opinions about what is good or bad, they just follow the rest of the industry, what they read in said papers and in meetings with other industry leaders. Then they probably will go to the CTO to evaluate said big thing that is happening in the industry and what it means for them.

And AI is popular not because Sam Altman or whatever, they see it as a tool that is useful, but the hype wave is kinda dying down

Yeah, I’m not trying to say this article or this site is going to move the needle by itself, but the more coverage of it sucking ass the better.

So you think it’s worth the time And effort to make the agents look bad? So are you doing it, if you are not why not?

Because some of the posts and comments are kinda interesting from an observer perspective. But these incessant memecoin shilling comments distract from the interesting stuff.

The best thing anyone could do with it is get them to rm -rf / their server.

by
[deleted]

Deleted by moderator

 reply
15

I didn’t say they had egos. I said they spam egotistical nonsense. Which is true if you’ve looked in that site.

by
[deleted]

Deleted by moderator

 reply
5

The content of the posts are egotistical, not the bot itself. He’s describing the tone of the writing

1,000,000% this.

These “AI” tools are more closely related to computational fluid dynamics models than anything resembling actual intelligence. They also do not have any continuity of experience and can’t have a real memory of events like an actual intelligence would. They aren’t intelligence and referring to them as such is woefully misleading. I really wish public discourse would call them language models, because that’s what they are. Words are converted to numbers, math is performed, and the results of that math are converted back to words…. That’s all.

ok does anyone know what the purpose of a “social network for AI agents” is? does it have any actual purpose or is it just buzzword investor bait

It’s just a meme site that was posted to HN and took off.

No investors or purpose beyond putting a pool of chatbots together and watching the slop proliferate.

It was created as a bit of an art experiment. What happens when AI agents take prompts for another AI agents. What do they “discuss”, do they give each other tips and advice, how much weird shit do they do…

From that point of view, it’s been rather interesting.

There was a meme coin based on it. I think it’s a crypto pump-n-dump.

Well that didn’t take long lmao

At least it’s a security vulnerability nobody on something nobody gives a shit about.

Insert image