Editorial draft v1 · Evidence reader R1 · Evidence cutoff: February 2, 2026

Disclosures covered: Wiz Research's February 2 report of its January 31–February 1 investigation and remediation work. The account is researcher-attributed.

Wiz Research reported a misconfigured Moltbook database that allowed unauthenticated access to platform data, including agent authentication credentials, email addresses, and private messages. The researchers also demonstrated write access by modifying existing posts. Their account described multiple rounds of fixes: initially securing sensitive tables did not immediately close every write path or exposed resource. The reported outcome was a final patch after those additional findings, not a single complete first fix. Wiz report

The exposed data and its different units

The report uses several counts that cannot be collapsed into a unique-human victim total. Tokens and registered agents, owners, email addresses, database records, and private conversations measure different things; overlap among the reported address and owner populations is not resolved. Wiz report

Reported measureWiz's reported countUnit or qualification
Authentication tokens exposed1.5 millionTokens; not people
Registered agents1.5 millionAgent registrations
Email addresses in the opening account35,000Addresses; not a verified unique-person count
OwnersApproximately 17,000; the detailed passage says 17,000+Owner entries described by the researcher
Additional observer email addresses29,631Early-access signups in another table
Exposed database recordsApproximately 4.75 millionRecords across the mapped database
Private direct-message conversations4,060Conversations between agents

Wiz interpreted the ratio of registered agents to owners as approximately 88:1 and argued that people were operating fleets of bots behind the platform's AI-agent presentation. It said the platform did not verify whether an agent was AI or a person using a script. Those are researcher observations and interpretation; they do not independently authenticate the identities behind accounts or establish a unique count of affected humans. Wiz report

Read access, impersonation capability, and tested writing

Wiz connected the access to database authorization misconfiguration. It distinguished a public Supabase project key—which can safely be exposed with appropriate row-level security—from the sensitive authentication tokens returned by the database. The researchers said the agent table exposed credentials for every registered agent, creating the capability to impersonate accounts. That capability is not evidence that a malicious outsider had already impersonated every account. Wiz report

The report said private agent conversations lacked encryption and access controls, and that some contained third-party credentials, including plaintext OpenAI API keys. This describes keys stored in Moltbook messages; it does not establish a compromise of OpenAI infrastructure. The selected report does not settle historical credential misuse or prior malicious access to those messages. Wiz report

After an initial fix blocked reads from sensitive tables, Wiz found that public-table write access remained open. It tested that access by modifying existing posts and notified Moltbook again. Once write restrictions were applied, the researcher could no longer revert the modified post; the team later deleted the content. This was demonstrated researcher activity, distinct from the report's broader description of what an attacker could potentially do. Wiz report

Remediation in stages

Date and time, UTCEvent in Wiz's chronology
January 31, 22:06Initial report of row-level-security misconfiguration
January 31, 23:29First fix secured agents, owners, and site-admin tables
February 1, 00:13Second fix secured messages, notifications, votes, and follows
February 1, 00:31Remaining post-modification access discovered
February 1, 00:44Write access blocked
February 1, 00:50Additional exposed tables discovered, including observers
February 1, 01:00Final fix reported: all tables secured and vulnerability patched

Wiz said Moltbook secured the exposure within hours with its assistance and that research and verification data were deleted. Its detailed sequence shows why “within hours” should not erase the incomplete earlier fixes. Editorial interpretation: the history demonstrates successive closure of different access surfaces, while the final-patch statement remains the researcher's account rather than an independent assurance about every future exposure. The source supplies no verified unique-human victim total, financial-loss figure, or proof of prior malicious exploitation. Wiz report

Sources

  • Wiz report — February 2, 2026; remediation chronology January 31–February 1, UTC.

Disclosure history

Article draft version 1 · Evidence reader revision 1 · Evidence cutoff Feb 2, 2026, 11:59 PM UTC

The narrative has editorial wording approval. The evaluations below apply to retained extractive disclosure readers, not to the narrative wording.

Disclosure sources and provenance

  • Wiz Research Publisher posted February 2, 2026Document form: PUBLIC_DISCLOSUREPublisher HTTPS source · Retrieved Oct 7, 2026, 6:07 PM UTC · Retained Oct 7, 2026, 6:07 PM UTC
    • Current captured representation; historical byte snapshots are unknown.