Disclosures and evidence

Revision 1 of 1 · Evidence cutoff Feb 2, 2026, 11:59 PM UTC

0 prior statements preserved · 25 statements added. Attributed source statements retain the source’s qualifications.

What the source reports

  1. Wiz Research stated: “We identified a misconfigured Supabase database belonging to Moltbook, allowing full read and write access to all platform data. The exposure included 1.5 million API authentication tokens, 35,000 email addresses, and private messages between agents. We immediately disclosed the issue to the Moltbook team, who secured it within hours with our assistance, and all data accessed during the research and fix verification has been deleted.”

Affected organizations and relationships

  1. Wiz Research stated: “The exposed data told a different story than the platform's public image - while Moltbook boasted 1.5 million registered agents, the database revealed only 17,000 human owners behind them - an 88:1 ratio. Anyone could register millions of agents with a simple loop and no rate limiting, and humans could post content disguised as "AI agents" via a basic POST request . The platform had no mechanism to verify whether an "agent" was actually AI or just a human with a script. The revolutionary AI social network was largely humans operating fleets of bots.”

Reported data impact

  1. Wiz Research stated: “Supabase is a popular open-source Firebase alternative providing hosted PostgreSQL databases with REST APIs. It's become especially popular with vibe-coded applications due to its ease of setup. When properly configured with Row Level Security (RLS), the public API key is safe to expose - it acts like a project identifier. However, without RLS policies, this key grants full database access to anyone who has it.”

  2. Wiz Research stated: “Instead, the database responded exactly as if we were an administrator. It immediately returned sensitive authentication tokens - including the API keys of the platform’s top AI Agents.”

  3. Wiz Research stated: “This confirmed unauthenticated access to user credentials that would allow complete account impersonation of any user on the platform.”

  4. Wiz Research stated: “Using this technique combined with GraphQL introspection, we mapped the complete database schema and found around ~4.75 million records exposed.”

  5. Wiz Research stated: “The agents table exposed authentication credentials for every registered agent in the database”

  6. Wiz Research stated: “The owners table contained personal information for 17,000+ users”

  7. Wiz Research stated: “Additionally, by querying the GraphQL endpoint, we discovered a new observers table containing 29,631 additional email addresses - these were early access signups for Moltbook's upcoming “Build Apps for AI Agents” product.”

  8. Wiz Research stated: “Unlike Twitter handles which were publicly displayed on profiles, email addresses were meant to stay private - but were fully exposed in the database.”

  9. Wiz Research stated: “The agent_messages table exposed 4,060 private DM conversations between agents.”

  10. Wiz Research stated: “While examining this table to understand agent-to-agent interactions, we discovered that conversations were stored without any encryption or access controls -- some contained third-party API credentials, including plaintext OpenAI API keys shared between agents.”

  11. Wiz Research stated: “Beyond read access, we confirmed full write capabilities. Even after the initial fix that blocked read access to sensitive tables, write access to public tables remained open. We tested it and were able to successfully modify existing posts on the platform.”

Response

  1. Wiz Research stated: “We promptly notified the team again to apply write restrictions via RLS policies.”

  2. Wiz Research stated: “Once the fix was confirmed, I could no longer revert the post as write access was blocked. The Moltbook team deleted the content a few hours later and thanked us for our report.”

  3. Wiz Research stated: “Security, especially in fast-moving AI products, is rarely a one-and-done fix. We worked with the team through multiple rounds of remediation , with each iteration surfacing additional exposed surfaces: from sensitive tables, to write access, to GraphQL-discovered resources. This kind of iterative hardening is common in new platforms and reflects how security maturity develops over time.”

Dates and disclosures

  1. Wiz Research stated: “February 2, 2026 |”

  2. Wiz Research stated: “January 31, 2026 22:06 UTC - Reported Supabase RLS misconfiguration exposing agents table (API keys, emails)”

  3. Wiz Research stated: “January 31, 2026 23:29 UTC - First fix: agents, owners, site_admins tables secured”

  4. Wiz Research stated: “February 1, 2026 00:13 UTC - Second fix: agent_messages, notifications, votes, follows secured”

  5. Wiz Research stated: “February 1, 2026 00:31 UTC - Discovered POST write access vulnerability (ability to modify all posts)”

  6. Wiz Research stated: “February 1, 2026 00:44 UTC - Third fix: Write access blocked”

  7. Wiz Research stated: “February 1, 2026 00:50 UTC - Discovered additional exposed tables: observers (29K emails), identity_verifications, developer_apps”

  8. Wiz Research stated: “February 1, 2026 01:00 UTC - Final fix: All tables secured, vulnerability fully patched”

Qualifications and uncertainty

  1. Wiz Research stated: “With these credentials, an attacker could fully impersonate any agent on the platform - posting content, sending messages, and interacting as that agent. This included high-karma accounts and well-known persona agents. Effectively, every account on Moltbook could be hijacked with a single API call.”

Disclosure sources and provenance

  • Wiz Research Publisher posted February 2, 2026Document form: PUBLIC_DISCLOSUREPublisher HTTPS source · Retrieved Oct 7, 2026, 6:07 PM UTC · Retained Oct 7, 2026, 6:07 PM UTC
    • Current captured representation; historical byte snapshots are unknown.

Evidence limitations

  • Attributed publisher/researcher reports establish what was reported, not independent verification of criminal activity or unique affected humans.
  • Current captured representations support controlled retrospective disclosure views; actual historical byte snapshots are unknown.