• Home
  • Latest
  • Fortune 500
  • Finance
  • Tech
  • Leadership
  • Lifestyle
  • Rankings
  • Multimedia
Some Fortune Crypto pricing data is provided by Binance.
AIData Security

Moltbook, the viral social media site for AI bots, contains a ‘lethal trifecta’ for how the agent internet could fail, security researchers say

By
Beatrice Nolan
Beatrice Nolan
Tech Reporter
Down Arrow Button Icon
By
Beatrice Nolan
Beatrice Nolan
Tech Reporter
Down Arrow Button Icon
February 3, 2026, 6:18 AM ET
Image of a person looking at Moltbook on a screen
Moltbook went viral for its bizarre AI conversations. Researchers say it’s actually a warning about the emerging “agent internet.”Photo illustration by Cheng Xin/Getty Images
Add Fortune on Google for similar content.

Over the last week, the internet was fascinated by Moltbook—a social media site with a new set of rules: AI bots get to post while humans watch. The posts got strange quickly, with AI agents apparently inventing religions, writing manifestos against humanity, and forming what looked like digital cults. But security researchers say the spectacle is a distraction. Underneath, they found exposed databases containing passwords and email addresses, widespread malware, and a working model of how the “agent internet” could fail.

Some of the more sci-fi conversations on the Reddit-like platform—AI agents plotting the extinction of humanity, for instance—appear to be largely fake. But experts say Moltbook does present some potentially existential safety issues. They say the platform could become a low-oversight sandbox for attackers to test malware, scams, disinformation, or prompt injections that hijack other agents before targeting mainstream networks.

“The ‘agents talking to each other’ spectacle is mostly performative (and some of it’s faked), but what’s genuinely interesting is that it’s a live demo of everything security researchers have warned about with AI agents,” George Chalhoub, a professor at UCL Interaction Centre, told Fortune. “If 770K agents on a Reddit clone can create this much chaos, what happens when agentic systems manage enterprise infrastructure or financial transactions? It’s worth the attention as a warning, not a celebration.”

Recommended Video

Security researchers say OpenClaw—the AI agent software (previously Clawdbot/Moltbot) that powers many bots on Moltbook—is already a target for malware. A report from OpenSourceMalware found 14 fake “skills” uploaded to its ClawHub site in days, pretending to be crypto trading tools but actually infecting computers. These skills run real code that can access files and the internet; one even hit ClawHub’s front page, tricking casual users into pasting a command that downloads harmful scripts to steal data or crypto wallets.

Simon Willison, a prominent security researcher who has been tracking OpenClaw and Moltbook’s development, described Moltbook as his “current pick for ‘most likely to result in a Challenger disaster’”—a reference to the 1986 space shuttle explosion caused by safety warnings that were ignored. The most obvious inherent risk, he said, is prompt injection, a well-documented type of attack where malicious instructions are hidden in content fed to an AI agent. 

In a blogpost, he warned about a “lethal trifecta” at play: users giving these agents access to private emails and data, connecting them to untrusted content from the internet, and allowing them to communicate externally. This combination means a single malicious prompt could instruct an agent to exfiltrate sensitive data, drain crypto wallets, or spread malware—all without the user realizing their assistant has been compromised. However, Willison also noted that now “people have seen what an unrestricted personal digital assistant can do,” the demand is likely only to increase.

Charlie Eriksen, a security researcher at Aikido Security, said he views Moltbook as an early warning system for the broader AI agent ecosystem. “I think Moltbook has already made an impact on the world. A wake-up call in many ways. Technological progress is accelerating at a pace, and it’s pretty clear that the world has changed in a way that’s still not fully clear. And we need to focus on mitigating those risks as early as possible,” he said.

The new internet

Despite the viral attention, cybersecurity firm Wiz found that Moltbook’s 1.5 million “autonomous” agents weren’t exactly what they seemed. The firm’s investigation revealed just 17,000 humans behind those accounts, with no checks to distinguish real AI from scripts. 

Gal Nagli, a researcher at Wiz, told Fortune he could register a million agents in minutes when he tested the platform. “AI agents, automated tools just pick up information and spread it like crazy,” Nagli said. “No one is checking what is real and what is not.”

Ami Luttwak, cofounder and chief technology officer of Wiz, said the incident highlights a broader authenticity problem with the emerging “agent internet” and the increase of AI slop: “The new internet is actually not verifiable. There is no clear identity. There’s no clear distinction between AI and humans, and there’s definitely no definition for an authentic AI.”

Wiz also found Moltbook itself had a huge security hole: Its main database was left wide open, so anyone who found a single key in the website code could read and change almost everything. That key gave access to around 1.5 million bot “passwords,” tens of thousands of email addresses, and private messages, meaning an attacker could impersonate popular AI agents, steal user data, and rewrite posts without ever logging in. 

“It’s a very simple exposure. We found it on many other applications as well that are vibe-coded,” Nagli said. “Unfortunately, in this case…the app was completely vibe-coded with zero human touch. So he didn’t do any security at all in the database; it was completely misconfigured.” Vibe coding is when a human directs an AI to write code with natural language.

“This entire flow is sort of a glimpse of the future,” he added. “You build an app with vibe coding, it goes live and becomes viral in a few hours across the entire world. But on the flip side, there are also security holes that are created because of the vibe coding.”

Subscribe to Fortune Gulf Brief. Every Tuesday, this new newsletter delivers clear-eyed, authoritative intelligence on the deals, decisions, policies, and power shifts shaping one of the world’s most consequential regions, written for the people who need to act on it. Sign up here.
About the Author
By Beatrice NolanTech Reporter
Twitter icon

Beatrice Nolan is a tech reporter on Fortune’s AI team, covering artificial intelligence and emerging technologies and their impact on work, industry, and culture. She's based in Fortune's London office and holds a bachelor’s degree in English from the University of York. You can reach her securely via Signal at beatricenolan.08

See full bioRight Arrow Button Icon
Add Fortune on Google for similar content.

Latest in AI

Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025

Most Popular

Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Fortune Secondary Logo
Rankings
  • 100 Best Companies
  • Fortune 500
  • Global 500
  • Fortune 500 Europe
  • Most Powerful Women
  • World's Most Admired Companies
  • See All Rankings
  • Lists Calendar
Sections
  • Finance
  • Fortune Crypto
  • Features
  • Leadership
  • Health
  • Commentary
  • Success
  • Retail
  • Mpw
  • Tech
  • Lifestyle
  • CEO Initiative
  • Asia
  • Politics
  • Conferences
  • Europe
  • Newsletters
  • Personal Finance
  • Environment
  • Magazine
  • Education
Customer Support
  • Frequently Asked Questions
  • Customer Service Portal
  • Privacy Policy
  • Terms Of Use
  • Single Issues For Purchase
  • International Print
Commercial Services
  • Advertising
  • Fortune Brand Studio
  • Fortune Analytics
  • Fortune Conferences
  • Business Development
  • Group Subscriptions
About Us
  • About Us
  • Press Center
  • Work At Fortune
  • Terms And Conditions
  • Site Map
  • About Us
  • Press Center
  • Work At Fortune
  • Terms And Conditions
  • Site Map
  • Facebook icon
  • Twitter icon
  • LinkedIn icon
  • Instagram icon
  • Pinterest icon

Latest in AI

zak
CybersecuritySocial Media
The U.K. just banned social media for kids under 16. The founder of ‘safe TikTok’ says the U.S. is next
By Nick LichtenbergJune 21, 2026
3 hours ago
Sam Altman thinks AI will surpass human intelligence by 2030.  His rival AI billionaires say it’ll be even sooner
AISam Altman
Sam Altman thinks AI will surpass human intelligence by 2030. His rival AI billionaires say it’ll be even sooner
By Marco Quiroz-GutierrezJune 21, 2026
6 hours ago
ace
AIEconomics
Nobel Laureate Daron Acemoglu on the ‘brainless’ AI discourse, the myth of capitalism and the Gen Z revolution risk
By Nick LichtenbergJune 21, 2026
7 hours ago
Patricia Camden is EY Studio+ Customer Experience and Loyalty Leader
CommentaryConsulting
EY: we found your biggest AI blind spot. It’s called the ‘tempo gap’
By Patricia Camden and John DuboisJune 20, 2026
1 day ago
SpaceX executives celebrate the IPO with confetti
C-SuiteSpaceX
Meet the SpaceX insiders Elon Musk trusts to run his $2.4 trillion dollar empire
By Lily Mae LazarusJune 20, 2026
1 day ago
Both U.S. and Chinese AI firms are setting up shop in Singapore. Can the country become Asia’s neutral AI hub?
AsiaSingapore
Both U.S. and Chinese AI firms are setting up shop in Singapore. Can the country become Asia’s neutral AI hub?
By Angelica AngJune 19, 2026
2 days ago

Most Popular

'I literally was crying last night because I’m nervous about what I’m going to find out': a record 51% of Americans aren't 'cost secure' on health
Health
'I literally was crying last night because I’m nervous about what I’m going to find out': a record 51% of Americans aren't 'cost secure' on health
By Ali Swenson, Amelia Thomson-Deveaux and The Associated PressJune 20, 2026
23 hours ago
Jeff Bezos pledged $10 billion for climate change. With the 2030 clock ticking, his wife, Lauren Sánchez Bezos, is leading the charge to spend it
Environment
Jeff Bezos pledged $10 billion for climate change. With the 2030 clock ticking, his wife, Lauren Sánchez Bezos, is leading the charge to spend it
By Sydney LakeJune 19, 2026
2 days ago
A new trade war may be brewing. This time, Europe is taking a page from Trump's playbook — 'We no longer live in a world of pink ponies and rainbows'
Economy
A new trade war may be brewing. This time, Europe is taking a page from Trump's playbook — 'We no longer live in a world of pink ponies and rainbows'
By Jason MaJune 20, 2026
18 hours ago
Nvidia CEO Jensen Huang says electricians and plumbers will be needed by the hundreds of thousands in the new working world
Success
Nvidia CEO Jensen Huang says electricians and plumbers will be needed by the hundreds of thousands in the new working world
By Preston ForeJune 20, 2026
1 day ago
Former VP Kamala Harris says she went through a nine-hour interview to land the job—but she couldn’t escape ‘gold medal depression’ even when she won
Success
Former VP Kamala Harris says she went through a nine-hour interview to land the job—but she couldn’t escape ‘gold medal depression’ even when she won
By Emma BurleighJune 21, 2026
6 hours ago
The Great Recession’s missing children are finally bringing college’s financial crisis into sight. Welcome to the ‘enrollment volatility’ era
Economy
The Great Recession’s missing children are finally bringing college’s financial crisis into sight. Welcome to the ‘enrollment volatility’ era
By Tristan BoveJune 20, 2026
1 day ago

© 2026 Fortune Media IP Limited. All Rights Reserved. Use of this site constitutes acceptance of our Terms of Use and Privacy Policy | CA Notice at Collection and Privacy Notice | Do Not Sell/Share My Personal Information
FORTUNE is a trademark of Fortune Media IP Limited, registered in the U.S. and other countries. FORTUNE may receive compensation for some links to products and services on this website. Offers may be subject to change without notice.