Moltbook Database Exposure Allegedly Revealed Users' Private Communications and API Authentication Tokens
Wiz researchers reported accessing an exposed Moltbook database in under three minutes, allegedly obtaining ~35,000 email addresses, thousands of private DMs, and ~1.5 million API authentication tokens. The exposure was described as enabling read/write access and potential impersonation or manipulation of "AI agent" accounts. Wiz said it disclosed the issue to Moltbook, which reportedly secured the database within hours and deleted accessed data.
- Date it happened
- 2026-01-31
- Organisation involved
- Moltbook platform operators, Moltbook
- Product, system or model
- Moltbook direct messaging system, Moltbook database, Moltbook authentication tokens, Moltbook
This incident was imported from AI Incident Database and is used under CC BY-SA 4.0. Our additions to it — the structured fields, the translation, the checks against other reports — are published under the same licence.
This is a record of what was reported, not a finding that anyone broke the law. If it names your organisation and you believe it is wrong, the corrections process is free and open to everyone.