Editorial draft v1 · Evidence reader R1 · Evidence cutoff: February 2, 2026
Disclosures covered: Wiz Research's February 2 report of its January 31–February 1 investigation and remediation work. The account is researcher-attributed.
Wiz Research reported a misconfigured Moltbook database that allowed unauthenticated access to platform data, including agent authentication credentials, email addresses, and private messages. The researchers also demonstrated write access by modifying existing posts. Their account described multiple rounds of fixes: initially securing sensitive tables did not immediately close every write path or exposed resource. The reported outcome was a final patch after those additional findings, not a single complete first fix. Wiz report
The exposed data and its different units
The report uses several counts that cannot be collapsed into a unique-human victim total. Tokens and registered agents, owners, email addresses, database records, and private conversations measure different things; overlap among the reported address and owner populations is not resolved. Wiz report
| Reported measure | Wiz's reported count | Unit or qualification |
|---|---|---|
| Authentication tokens exposed | 1.5 million | Tokens; not people |
| Registered agents | 1.5 million | Agent registrations |
| Email addresses in the opening account | 35,000 | Addresses; not a verified unique-person count |
| Owners | Approximately 17,000; the detailed passage says 17,000+ | Owner entries described by the researcher |
| Additional observer email addresses | 29,631 | Early-access signups in another table |
| Exposed database records | Approximately 4.75 million | Records across the mapped database |
| Private direct-message conversations | 4,060 | Conversations between agents |
Wiz interpreted the ratio of registered agents to owners as approximately 88:1 and argued that people were operating fleets of bots behind the platform's AI-agent presentation. It said the platform did not verify whether an agent was AI or a person using a script. Those are researcher observations and interpretation; they do not independently authenticate the identities behind accounts or establish a unique count of affected humans. Wiz report
Read access, impersonation capability, and tested writing
Wiz connected the access to database authorization misconfiguration. It distinguished a public Supabase project key—which can safely be exposed with appropriate row-level security—from the sensitive authentication tokens returned by the database. The researchers said the agent table exposed credentials for every registered agent, creating the capability to impersonate accounts. That capability is not evidence that a malicious outsider had already impersonated every account. Wiz report
The report said private agent conversations lacked encryption and access controls, and that some contained third-party credentials, including plaintext OpenAI API keys. This describes keys stored in Moltbook messages; it does not establish a compromise of OpenAI infrastructure. The selected report does not settle historical credential misuse or prior malicious access to those messages. Wiz report
After an initial fix blocked reads from sensitive tables, Wiz found that public-table write access remained open. It tested that access by modifying existing posts and notified Moltbook again. Once write restrictions were applied, the researcher could no longer revert the modified post; the team later deleted the content. This was demonstrated researcher activity, distinct from the report's broader description of what an attacker could potentially do. Wiz report
Remediation in stages
| Date and time, UTC | Event in Wiz's chronology |
|---|---|
| January 31, 22:06 | Initial report of row-level-security misconfiguration |
| January 31, 23:29 | First fix secured agents, owners, and site-admin tables |
| February 1, 00:13 | Second fix secured messages, notifications, votes, and follows |
| February 1, 00:31 | Remaining post-modification access discovered |
| February 1, 00:44 | Write access blocked |
| February 1, 00:50 | Additional exposed tables discovered, including observers |
| February 1, 01:00 | Final fix reported: all tables secured and vulnerability patched |
Wiz said Moltbook secured the exposure within hours with its assistance and that research and verification data were deleted. Its detailed sequence shows why “within hours” should not erase the incomplete earlier fixes. Editorial interpretation: the history demonstrates successive closure of different access surfaces, while the final-patch statement remains the researcher's account rather than an independent assurance about every future exposure. The source supplies no verified unique-human victim total, financial-loss figure, or proof of prior malicious exploitation. Wiz report
Sources
Wiz report — February 2, 2026; remediation chronology January 31–February 1, UTC.