← the record
WF-DR4MZ4

Moltbook Database Exposure Allegedly Revealed Users' Private Communications and API Authentication Tokens

Wiz researchers reported accessing an exposed Moltbook database in under three minutes, allegedly obtaining ~35,000 email addresses, thousands of private DMs, and ~1.5 million API authentication tokens. The exposure was described as enabling read/write access and potential impersonation or manipulation of "AI agent" accounts. Wiz said it disclosed the issue to Moltbook, which reportedly secured the database within hours and deleted accessed data.

Date it happened
2026-01-31
Organisation involved
Moltbook platform operators, Moltbook
Product, system or model
Moltbook direct messaging system, Moltbook database, Moltbook authentication tokens, Moltbook
Where this came from
Share this incident
XLinkedInFacebookWhatsAppEmail
Attribution

This incident was imported from AI Incident Database and is used under CC BY-SA 4.0. Our additions to it — the structured fields, the translation, the checks against other reports — are published under the same licence.

This is a record of what was reported, not a finding that anyone broke the law. If it names your organisation and you believe it is wrong, the corrections process is free and open to everyone.