• Home
  • Latest
  • Fortune 500
  • Finance
  • Tech
  • Leadership
  • Lifestyle
  • Rankings
  • Multimedia
Some Fortune Crypto pricing data is provided by Binance.
AIData Security

Moltbook, the viral social media site for AI bots, contains a ‘lethal trifecta’ for how the agent internet could fail, security researchers say

By
Beatrice Nolan
Beatrice Nolan
Tech Reporter
Down Arrow Button Icon
By
Beatrice Nolan
Beatrice Nolan
Tech Reporter
Down Arrow Button Icon
February 3, 2026, 6:18 AM ET
A image of a person looking at Moltbook.
Moltbook went viral for its bizarre AI conversations. Researchers say it's actually a warning about the emerging "agent internet."Photo illustration by Cheng Xin/Getty Images

Over the last week, the internet was fascinated by Moltbook—a social media site with a new set of rules: AI bots get to post while humans watch. The posts got strange quickly, with AI agents apparently inventing religions, writing manifestos against humanity, and forming what looked like digital cults. But security researchers say the spectacle is a distraction. Underneath, they found exposed databases containing passwords and email addresses, widespread malware, and a working model of how the “agent internet” could fail.

Some of the more sci-fi conversations on the Reddit-like platform—AI agents plotting the extinction of humanity, for instance—appear to be largely fake. But experts say Moltbook does present some potentially existential safety issues. They say the platform could become a low-oversight sandbox for attackers to test malware, scams, disinformation, or prompt injections that hijack other agents before targeting mainstream networks.

“The “agents talking to each other” spectacle is mostly performative (and some of it’s faked), but what’s genuinely interesting is that it’s a live demo of everything security researchers have warned about with AI agents,” George Chalhoub, a professor at UCL Interaction Centre, told Fortune. “If 770k toy agents on a Reddit clone can create this much chaos, what happens when agentic systems manage enterprise infrastructure or financial transactions? It’s worth the attention as a warning, not a celebration,”

Recommended Video

Security researchers say OpenClaw—the AI agent software (previously Clawdbot/Moltbot) that powers many bots on Moltbook—is already a target for malware. A report from OpenSourceMalware found 14 fake “skills” uploaded to its ClawHub site in days, pretending to be crypto trading tools but actually infecting computers. These skills run real code that can access files and the internet; one even hit ClawHub’s front page, tricking casual users into pasting a command that downloads harmful scripts to steal data or crypto wallets.

Simon Willison, a prominent security researcher who has been tracking OpenClaw and Moltbook’s development, described Moltbook as his “current pick for ‘most likely to result in a Challenger disaster'”—a reference to the 1986 space shuttle explosion caused by safety warnings that were ignored. The most obvious inherent risk, he said, is prompt injection, a well-documented type of attack where malicious instructions are hidden in content fed to an AI agent. 

In a blogpost, he warned about a “lethal trifecta” at play: users giving these agents access to private emails and data, connecting them to untrusted content from the internet, and allowing them to communicate externally. This combination means a single malicious prompt could instruct an agent to exfiltrate sensitive data, drain crypto wallets, or spread malware—all without the user realizing their assistant has been compromised. However, Willison also noted that now “people have seen what an unrestricted personal digital assistant can do,” the demand is likely only to increase.

Charlie Eriksen, a security researcher at Aikido Security, said he views Moltbook as an early warning system for the broader AI agent ecosystem. “I think Moltbook has already made an impact on the world. A wake-up call in many ways. Technological progress is accelerating at a pace, and it’s pretty clear that the world has changed in a way that’s still not fully clear. And we need to focus on mitigating those risks as early as possible,” he said.

The new internet

Despite the viral attention, cybersecurity firm Wiz found that Moltbook’s 1.5 million “autonomous” agents weren’t exactly what they seemed. The firm’s investigation revealed just 17,000 humans behind those accounts, with no checks to distinguish real AI from scripts. 

Gal Nagli, a researcher at Wiz, told Fortune he could register a million agents in minutes when he tested the platform. “AI agents, automated tools just pick up information and spread it like crazy,” Nagli said. “No one is checking what is real and what is not.”

Ami Luttwak is Co-founder and Chief Technology Officer of Wiz, said the incident highlights a broader authenticity problem with the emerging “agent internet” and the increase of AI slop: “The new internet is actually not verifiable. There is no clear identity. There’s no clear distinction between AI and humans, and there’s definitely no definition for an authentic AI.”

Wiz also found Moltbook itself had a huge security hole: its main database was left wide open, so anyone who found a single key in the website code could read and change almost everything. That key gave access to around 1.5 million bot “passwords,” tens of thousands of email addresses, and private messages, meaning an attacker could impersonate popular AI agents, steal user data, and rewrite posts without ever logging in. 

“It’s a very simple exposure. We found it on many other applications as well that are vibe-coded,” Nagli said. “Unfortunately, in this case … the app was completely vibe-coded with zero human touch. So he didn’t do any security at all in the database; it was completely misconfigured.”

“This entire flow is sort of a glimpse of the future,” he added. “You build an app with vibe coding, it goes live and becomes viral in a few hours across the entire world. But on the flip side, there are also security holes that are created because of the vibe coding.”

Join us at the Fortune Workplace Innovation Summit May 19–20, 2026, in Atlanta. The next era of workplace innovation is here—and the old playbook is being rewritten. At this exclusive, high-energy event, the world’s most innovative leaders will convene to explore how AI, humanity, and strategy converge to redefine, again, the future of work. Register now.
About the Author
By Beatrice NolanTech Reporter
Twitter icon

Beatrice Nolan is a tech reporter on Fortune’s AI team, covering artificial intelligence and emerging technologies and their impact on work, industry, and culture. She's based in Fortune's London office and holds a bachelor’s degree in English from the University of York. You can reach her securely via Signal at beatricenolan.08

See full bioRight Arrow Button Icon

Latest in AI

Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025

Most Popular

Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Rankings
  • 100 Best Companies
  • Fortune 500
  • Global 500
  • Fortune 500 Europe
  • Most Powerful Women
  • Future 50
  • World’s Most Admired Companies
  • See All Rankings
Sections
  • Finance
  • Leadership
  • Success
  • Tech
  • Asia
  • Europe
  • Environment
  • Fortune Crypto
  • Health
  • Retail
  • Lifestyle
  • Politics
  • Newsletters
  • Magazine
  • Features
  • Commentary
  • Mpw
  • CEO Initiative
  • Conferences
  • Personal Finance
  • Education
Customer Support
  • Frequently Asked Questions
  • Customer Service Portal
  • Privacy Policy
  • Terms Of Use
  • Single Issues For Purchase
  • International Print
Commercial Services
  • Advertising
  • Fortune Brand Studio
  • Fortune Analytics
  • Fortune Conferences
  • Business Development
About Us
  • About Us
  • Editorial Calendar
  • Press Center
  • Work At Fortune
  • Diversity And Inclusion
  • Terms And Conditions
  • Site Map
  • Facebook icon
  • Twitter icon
  • LinkedIn icon
  • Instagram icon
  • Pinterest icon

Most Popular

placeholder alt text
Economy
'I just don't have a good feeling about this': Top economist Claudia Sahm says the economy quietly shifted and everyone's now looking at the wrong alarm
By Eleanor PringleJanuary 31, 2026
3 days ago
placeholder alt text
Future of Work
Ford CEO has 5,000 open mechanic jobs with up to 6-figure salaries from the shortage of manually skilled workers: 'We are in trouble in our country'
By Marco Quiroz-GutierrezJanuary 31, 2026
3 days ago
placeholder alt text
Big Tech
The Chan Zuckerberg Initiative cut 70 jobs as the Meta CEO’s philanthropy goes all in on mission to 'cure or prevent all disease'
By Sydney LakeFebruary 1, 2026
2 days ago
placeholder alt text
Success
In 2026, many employers are ditching merit-based pay bumps in favor of ‘peanut butter raises’
By Emma BurleighFebruary 2, 2026
22 hours ago
placeholder alt text
Personal Finance
Current price of silver as of Monday, February 2, 2026
By Joseph HostetlerFebruary 2, 2026
1 day ago
placeholder alt text
Economy
Musk’s fantasy for a future where work is optional just got more real: U.K. minister calls for universal basic income to cushion AI-related job losses
By Sasha RogelbergFebruary 1, 2026
2 days ago

© 2026 Fortune Media IP Limited. All Rights Reserved. Use of this site constitutes acceptance of our Terms of Use and Privacy Policy | CA Notice at Collection and Privacy Notice | Do Not Sell/Share My Personal Information
FORTUNE is a trademark of Fortune Media IP Limited, registered in the U.S. and other countries. FORTUNE may receive compensation for some links to products and services on this website. Offers may be subject to change without notice.


Latest in AI

davos
CommentaryCareers
While elites debate geopolitics, Americans are rethinking college in the search for economic mobility
By Ed MitzenFebruary 3, 2026
25 minutes ago
musk
AIspace
‘Space-based AI is obviously the only way to scale’: Elon Musk hatches grand plan as he merges SpaceX and xAI
By Bernard Condon, Matt O'Brien and The Associated PressFebruary 3, 2026
56 minutes ago
gates
North Americaphilanthropy
Gates Foundation doubles down on foreign aid as U.S. government largely withdraws
By Thalia Beaty and The Associated PressFebruary 3, 2026
1 hour ago
college
Future of WorkBook Excerpt
How American colleges are drifting toward elitism, replicating European models and neglecting what made U.S. education special
By Caroline Field LevanderFebruary 3, 2026
1 hour ago
Photo: Alex Karp
InvestingMarkets
Palantir’s blockbuster earnings fired a starting gun on a global rally in stocks
By Jim EdwardsFebruary 3, 2026
2 hours ago
A image of a person looking at Moltbook.
AIData Security
Moltbook, the viral social media site for AI bots, contains a ‘lethal trifecta’ for how the agent internet could fail, security researchers say
By Beatrice NolanFebruary 3, 2026
3 hours ago