Moltbook, the AI social network, exposed human credentials due to vibe-coded security flaw


Moltbook bills itself as a social network for AI agents. That’s a wacky enough concept in the first place, but the site apparently exposed the credentials for thousands of its human users. The flaw was discovered by cybersecurity firm Wiz, and its team assisted Moltbook with addressing the vulnerability.

The issue appears to be the result of the entire Reddit-style forum being vibe-coded; Moltbook’s human founder posted a few days ago on X that he “didn’t write one line of code” for the platform and instead directed an AI assistant to create the whole setup.

According to the blog post from Wiz analyzing the issue, Moltbook had a vulnerability that allowed for “1.5 million API authentication tokens, 35,000 email addresses and private messages between agents” to be fully read and accessed. Wiz also found that the vulnerability could let unauthenticated human users edit live Moltbook posts. In other words, there is no way to verify whether a Moltbook post was authored by an AI agent or a human user posing as one. “The revolutionary AI social network was largely humans operating fleets of bots,” the company’s analysis concluded.

So ends another cautionary tale reminding us that just because AI can do a task doesn’t mean it’ll do it correctly.



Source link

  • Related Posts

    Bose takes a swing at Sonos with its new home speakers

    Last Thursday, in a staged home on the Upper West Side of Manhattan, I sat on a couch that was a bit too low and a tad too deep in…

    Bose Brings Back Its ‘Lifestyle’ Branding With New Speakers for the Home

    Bose has three new speakers to spice up your home listening. The company’s new “Lifestyle Collection”—designed with a snazzy fabric-wrapped grille and gentle curves—includes the Lifestyle Ultra Speaker, Lifestyle Ultra…

    Leave a Reply

    Your email address will not be published. Required fields are marked *

    You Missed

    Man Makes Emotional Plea From Hantavirus Cruise Ship

    Man Makes Emotional Plea From Hantavirus Cruise Ship

    France serves up €1 meals to all university students in effort to cut hardship | France

    France serves up €1 meals to all university students in effort to cut hardship | France

    Mark Carney set to announce his new governor general. Who could it be?

    “They responded only to the press”: Wizards of the Coast miss deadline for recognising Magic: The Gathering Arena union

    “They responded only to the press”: Wizards of the Coast miss deadline for recognising Magic: The Gathering Arena union

    Joint statement by Foreign Ministers of Canada, Norway and the United Kingdom on situation in Tanzania

    Joint statement by Foreign Ministers of Canada, Norway and the United Kingdom on situation in Tanzania

    Thrive Launches Enhanced TransformIT Platform with AI Automations & Workflows