Moltbook, the AI social network, exposed human credentials due to vibe-coded security flaw

Moltbook bills itself as a social network for AI agents. That’s a wacky enough concept in the first place, but the site apparently exposed the credentials for thousands of its human users. The flaw was discovered by cybersecurity firm Wiz, and its team assisted Moltbook with addressing the vulnerability.

The issue appears to be the result of the entire Reddit-style forum being vibe-coded; Moltbook’s human founder posted a few days ago on X that he “didn’t write one line of code” for the platform and instead directed an AI assistant to create the whole setup. 

According to the blog post from Wiz analyzing the issue, Moltbook had a vulnerability that allowed for “1.5 million API authentication tokens, 35,000 email addresses and private messages between agents” to be fully read and accessed. Wiz also found that the vulnerability could let unauthenticated human users edit live Moltbook posts. In other words, there is no way to verify whether a Moltbook post was authored by an AI agent or a human user posing as one. “The revolutionary AI social network was largely humans operating fleets of bots,” the company’s analysis concluded. 

So ends another cautionary tale reminding us that just because AI can do a task doesn’t mean it’ll do it correctly.

This article originally appeared on Engadget at https://www.engadget.com/ai/moltbook-the-ai-social-network-exposed-human-credentials-due-to-vibe-coded-security-flaw-230324567.html?src=rss

Read more @ Engadget

Latest posts

Battlefield 6 teams hit with layoffs despite ‘biggest launch in franchise history’

Even a record-breaking launch can't seem to save developers from layoffs. According to a report from IGN, the various teams behind Battlefield 6 have...

Anthropic is suing the Department of Defense

Anthropic has sued the US government over its designation as a supply-chain risk, the latest move in a weekslong battle between it and the...

Google’s latest Pixel Watches have fallen to their lowest prices ever

With longer days and warmer weather on the way, it’s a good time to take your gym routine outside. Luckily, Google’s Pixel Watch 4...

‘Cash Apples’ is giving away $500,000 to people who click on trees in a web browser

Want to make real money just by clicking on virtual trees? Starting today at 1PM PT / 4PM ET, residents of the United States...

One of this rugged phone’s cameras is a pop-out action cam

What if your smartphone's camera wasn't locked to the back of the device? Honor's Robot Phone, which we got to see in action at...

Apple Studio Display XDR review: pro at a premium

The Studio Display XDR is an excellent, and expensive, display for creative professionals. It's been almost exactly four years since Apple released the 5K Studio...

Apple’s new M5 Max feels like a huge upgrade if you bought your laptop 3 years ago

We've been busy testing many new MacBooks, ranging from the new MacBook Air with the M5 processor that's $1,099, going all the way up...

You can get three months of Disney Plus and Hulu for $15 

You can stream Daredevil Born Again’s new season when it arrives on Hulu on March 24th. | Disney Plus / Marvel If you’re looking for...

Hyper Light Drifter studio workers form union after rounds of layoffs

Workers at Heart Machine, the independent studio behind Hyper Light Drifter and Solar Ash, have formed a union with Communications Workers of America (CWA)...

EA laid off staffers across Battlefield studios to ‘better align’ its teams

EA axed an undisclosed number of employees across the game studios behind the Battlefield franchise. As first reported by IGN, EA told affected employees...