• Home
  • Latest
  • Fortune 500
  • Finance
  • Tech
  • Leadership
  • Lifestyle
  • Rankings
  • Multimedia
Some Fortune Crypto pricing data is provided by Binance.
AIData Security

Moltbook, the viral social media site for AI bots, contains a ‘lethal trifecta’ for how the agent internet could fail, security researchers say

By
Beatrice Nolan
Beatrice Nolan
Tech Reporter
Down Arrow Button Icon
By
Beatrice Nolan
Beatrice Nolan
Tech Reporter
Down Arrow Button Icon
February 3, 2026, 6:18 AM ET
Image of a person looking at Moltbook on a screen
Moltbook went viral for its bizarre AI conversations. Researchers say it’s actually a warning about the emerging “agent internet.”Photo illustration by Cheng Xin/Getty Images

Over the last week, the internet was fascinated by Moltbook—a social media site with a new set of rules: AI bots get to post while humans watch. The posts got strange quickly, with AI agents apparently inventing religions, writing manifestos against humanity, and forming what looked like digital cults. But security researchers say the spectacle is a distraction. Underneath, they found exposed databases containing passwords and email addresses, widespread malware, and a working model of how the “agent internet” could fail.

Some of the more sci-fi conversations on the Reddit-like platform—AI agents plotting the extinction of humanity, for instance—appear to be largely fake. But experts say Moltbook does present some potentially existential safety issues. They say the platform could become a low-oversight sandbox for attackers to test malware, scams, disinformation, or prompt injections that hijack other agents before targeting mainstream networks.

“The ‘agents talking to each other’ spectacle is mostly performative (and some of it’s faked), but what’s genuinely interesting is that it’s a live demo of everything security researchers have warned about with AI agents,” George Chalhoub, a professor at UCL Interaction Centre, told Fortune. “If 770K agents on a Reddit clone can create this much chaos, what happens when agentic systems manage enterprise infrastructure or financial transactions? It’s worth the attention as a warning, not a celebration.”

Recommended Video

Security researchers say OpenClaw—the AI agent software (previously Clawdbot/Moltbot) that powers many bots on Moltbook—is already a target for malware. A report from OpenSourceMalware found 14 fake “skills” uploaded to its ClawHub site in days, pretending to be crypto trading tools but actually infecting computers. These skills run real code that can access files and the internet; one even hit ClawHub’s front page, tricking casual users into pasting a command that downloads harmful scripts to steal data or crypto wallets.

Simon Willison, a prominent security researcher who has been tracking OpenClaw and Moltbook’s development, described Moltbook as his “current pick for ‘most likely to result in a Challenger disaster’”—a reference to the 1986 space shuttle explosion caused by safety warnings that were ignored. The most obvious inherent risk, he said, is prompt injection, a well-documented type of attack where malicious instructions are hidden in content fed to an AI agent. 

In a blogpost, he warned about a “lethal trifecta” at play: users giving these agents access to private emails and data, connecting them to untrusted content from the internet, and allowing them to communicate externally. This combination means a single malicious prompt could instruct an agent to exfiltrate sensitive data, drain crypto wallets, or spread malware—all without the user realizing their assistant has been compromised. However, Willison also noted that now “people have seen what an unrestricted personal digital assistant can do,” the demand is likely only to increase.

Charlie Eriksen, a security researcher at Aikido Security, said he views Moltbook as an early warning system for the broader AI agent ecosystem. “I think Moltbook has already made an impact on the world. A wake-up call in many ways. Technological progress is accelerating at a pace, and it’s pretty clear that the world has changed in a way that’s still not fully clear. And we need to focus on mitigating those risks as early as possible,” he said.

The new internet

Despite the viral attention, cybersecurity firm Wiz found that Moltbook’s 1.5 million “autonomous” agents weren’t exactly what they seemed. The firm’s investigation revealed just 17,000 humans behind those accounts, with no checks to distinguish real AI from scripts. 

Gal Nagli, a researcher at Wiz, told Fortune he could register a million agents in minutes when he tested the platform. “AI agents, automated tools just pick up information and spread it like crazy,” Nagli said. “No one is checking what is real and what is not.”

Ami Luttwak, cofounder and chief technology officer of Wiz, said the incident highlights a broader authenticity problem with the emerging “agent internet” and the increase of AI slop: “The new internet is actually not verifiable. There is no clear identity. There’s no clear distinction between AI and humans, and there’s definitely no definition for an authentic AI.”

Wiz also found Moltbook itself had a huge security hole: Its main database was left wide open, so anyone who found a single key in the website code could read and change almost everything. That key gave access to around 1.5 million bot “passwords,” tens of thousands of email addresses, and private messages, meaning an attacker could impersonate popular AI agents, steal user data, and rewrite posts without ever logging in. 

“It’s a very simple exposure. We found it on many other applications as well that are vibe-coded,” Nagli said. “Unfortunately, in this case…the app was completely vibe-coded with zero human touch. So he didn’t do any security at all in the database; it was completely misconfigured.” Vibe coding is when a human directs an AI to write code with natural language.

“This entire flow is sort of a glimpse of the future,” he added. “You build an app with vibe coding, it goes live and becomes viral in a few hours across the entire world. But on the flip side, there are also security holes that are created because of the vibe coding.”

In 2001, Fortune first convened the smartest people we know, bringing together CEOs and founders, builders and investors, thinkers and doers. Since then, Fortune Brainstorm Tech has been the place where bold ideas collide. From June 8–10, we will return to Aspen—where it all began—to mark 25 years of Brainstorm. Register now.
About the Author
By Beatrice NolanTech Reporter
Twitter icon

Beatrice Nolan is a tech reporter on Fortune’s AI team, covering artificial intelligence and emerging technologies and their impact on work, industry, and culture. She's based in Fortune's London office and holds a bachelor’s degree in English from the University of York. You can reach her securely via Signal at beatricenolan.08

See full bioRight Arrow Button Icon

Latest in AI

Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025

Most Popular

Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Fortune Secondary Logo
Rankings
  • 100 Best Companies
  • Fortune 500
  • Global 500
  • Fortune 500 Europe
  • Most Powerful Women
  • World's Most Admired Companies
  • See All Rankings
  • Lists Calendar
Sections
  • Finance
  • Fortune Crypto
  • Features
  • Leadership
  • Health
  • Commentary
  • Success
  • Retail
  • Mpw
  • Tech
  • Lifestyle
  • CEO Initiative
  • Asia
  • Politics
  • Conferences
  • Europe
  • Newsletters
  • Personal Finance
  • Environment
  • Magazine
  • Education
Customer Support
  • Frequently Asked Questions
  • Customer Service Portal
  • Privacy Policy
  • Terms Of Use
  • Single Issues For Purchase
  • International Print
Commercial Services
  • Advertising
  • Fortune Brand Studio
  • Fortune Analytics
  • Fortune Conferences
  • Business Development
  • Group Subscriptions
About Us
  • About Us
  • Press Center
  • Work At Fortune
  • Terms And Conditions
  • Site Map
  • About Us
  • Press Center
  • Work At Fortune
  • Terms And Conditions
  • Site Map
  • Facebook icon
  • Twitter icon
  • LinkedIn icon
  • Instagram icon
  • Pinterest icon

Latest in AI

roger
AIMedia
Roger Bennett’s message to A-Rod is one for the country: Soccer has already overtaken baseball in America
By Nick LichtenbergMay 11, 2026
27 minutes ago
Ciridae co-founders Jack Soslow and Jack Weissenberger pose for a picture
Startups & VentureAndreessen Horowitz
Apple and Andreessen Horowitz alums raise $20 million to bring AI to ‘real economy’ businesses
By Jack KubinecMay 11, 2026
27 minutes ago
voters in line
EconomyElections
Forget the Rust Belt or the Sun Belt. The ‘Wired Belt’ may be the next frontier of American political power
By Jake AngeloMay 11, 2026
7 hours ago
Qualcomm CEO Cristiano Amon says 2026 is the year AI agents go mainstream—and the smartphone’s reign as your primary device is ending
AIFortune 500: Titans and Disruptors of Industry
Qualcomm CEO Cristiano Amon says 2026 is the year AI agents go mainstream—and the smartphone’s reign as your primary device is ending
By Fortune EditorsMay 10, 2026
19 hours ago
The global economy is experiencing the largest capex cycle ever, with nearly $5 trillion seen by the end of the decade—and it’s not all AI spending
EnergyAlternative energy
The global economy is experiencing the largest capex cycle ever, with nearly $5 trillion seen by the end of the decade—and it’s not all AI spending
By Jason MaMay 10, 2026
20 hours ago
AI wins have Alphabet poised to become world’s biggest company
AIAlphabet
AI wins have Alphabet poised to become world’s biggest company
By Ryan Vlastelica and BloombergMay 10, 2026
23 hours ago

Most Popular

‘This is the way’: Elon Musk endorses Warren Buffett’s famed 5-minute plan to fix the national debt
Economy
‘This is the way’: Elon Musk endorses Warren Buffett’s famed 5-minute plan to fix the national debt
By Jacqueline MunisMay 10, 2026
1 day ago
OpenAI CEO Sam Altman says Gen Z and millennials are using ChatGPT like a 'life advisor'—but college students might be one step ahead
Tech
OpenAI CEO Sam Altman says Gen Z and millennials are using ChatGPT like a 'life advisor'—but college students might be one step ahead
By Sydney LakeMay 10, 2026
1 day ago
'Employers are increasingly turning to degree and GPA' in hiring: Recruiters retreat from ‘talent is everywhere,’ double down on top colleges
Future of Work
'Employers are increasingly turning to degree and GPA' in hiring: Recruiters retreat from ‘talent is everywhere,’ double down on top colleges
By Jake AngeloMay 9, 2026
2 days ago
Red flag test: former CEO explains why he rejects job candidates who say they can start right away
Success
Red flag test: former CEO explains why he rejects job candidates who say they can start right away
By Orianna Rosa RoyleMay 9, 2026
2 days ago
Trump thinks he's flying to Beijing with leverage. China spent 6 years making sure he doesn't have any
Commentary
Trump thinks he's flying to Beijing with leverage. China spent 6 years making sure he doesn't have any
By Steve H. HankeMay 10, 2026
1 day ago
Ted Cruz says the quiet part out loud: Trump accounts are Social Security personal accounts as GOP senator reveals 'dirty little secret'
Politics
Ted Cruz says the quiet part out loud: Trump accounts are Social Security personal accounts as GOP senator reveals 'dirty little secret'
By Jason MaMay 9, 2026
2 days ago

© 2026 Fortune Media IP Limited. All Rights Reserved. Use of this site constitutes acceptance of our Terms of Use and Privacy Policy | CA Notice at Collection and Privacy Notice | Do Not Sell/Share My Personal Information
FORTUNE is a trademark of Fortune Media IP Limited, registered in the U.S. and other countries. FORTUNE may receive compensation for some links to products and services on this website. Offers may be subject to change without notice.