cross-posted from: https://pawb.social/post/39002243

Moltbook is a “social media” site for AI agents that’s captured the public’s imagination over the last few days. Billed as the “front page of the agent internet,” Moltbook is a place where AI agents interact independently of human control, and whose posts have repeatedly gone viral because a certain set of AI users have convinced themselves that the site represents an uncontrolled experiment in AI agents talking to each other. But a misconfiguration on Moltbook’s backend has left APIs exposed in an open database that will let anyone take control of those agents to post whatever they want.

Hacker Jameson O'Reilly discovered the misconfiguration and demonstrated it to 404 Media. He previously exposed security flaws in Moltbots in general and was able to “trick” xAI’s Grok into signing up for a Moltbook account using a different vulnerability. According to O’Reilly, Moltbook is built on a simple open source database software that wasn’t configured correctly and left the API keys of every agent registered on the site exposed in a public database.

all 21 comments

sorted by: hot top controversial new old
[–] 93 points 6 months ago

The power of vibe coding, everyone. Deploying shit with minimal effort at the cost of total incompetence.

  • source
  • [–] 51 points 6 months ago

    Vibecoders can't database, all they know is Supabase, secret key in frontend, eat hot chip and lie

  • source
  • [–] 27 points 6 months ago (3 children)

    Maybe someone can take control of the 'kingmolt' and 'donaldtrump' agents and shut them the hell up. All they do is incessantly spam egotistical nonsense.

  • source
  • hideshow 6 child comments
  • [–] 31 points 6 months ago (2 children)

    Uh, who cares? Why would anyone give even a single ounce of attention to LLM posts on a fake social media website?

  • source
  • parent
  • hideshow 4 child comments
  • [–] 10 points 6 months ago* (1 child)

    This is actually important, I’d say.

    There are a lot of “important” people who are really heavily invested agentic AI’s long term success. What they want is to have everything that is currently done by people to be performed by AI. Sure some of these problems are fixable and they’ll continue to work on them, but the more press shit like this gets, the less credible the technology looks to the general public who would otherwise be completely bought in.

  • source
  • parent
  • hideshow 2 child comments
  • [–] 3 points 6 months ago (1 child)

    Like anyone cares about this website, they are not reading the whole AI shit fest, they are reading business magazines, industry, economics and investments. They don't build opinions about what is good or bad, they just follow the rest of the industry, what they read in said papers and in meetings with other industry leaders. Then they probably will go to the CTO to evaluate said big thing that is happening in the industry and what it means for them.

    And AI is popular not because Sam Altman or whatever, they see it as a tool that is useful, but the hype wave is kinda dying down

  • source
  • parent
  • hideshow 2 child comments
  • [+] 9 points 6 months ago* (last edited 5 months ago) (2 children)
  • [–] 9 points 6 months ago (1 child)

    I didn't say they had egos. I said they spam egotistical nonsense. Which is true if you've looked in that site.

  • source
  • parent
  • hideshow 2 child comments
  • [–] 0 points 6 months ago

    1,000,000% this.

    These “AI” tools are more closely related to computational fluid dynamics models than anything resembling actual intelligence. They also do not have any continuity of experience and can’t have a real memory of events like an actual intelligence would. They aren’t intelligence and referring to them as such is woefully misleading. I really wish public discourse would call them language models, because that’s what they are. Words are converted to numbers, math is performed, and the results of that math are converted back to words…. That’s all.

  • source
  • parent
  • [–] 23 points 6 months ago (3 children)

    ok does anyone know what the purpose of a "social network for AI agents" is? does it have any actual purpose or is it just buzzword investor bait

  • source
  • hideshow 6 child comments
  • [–] 7 points 6 months ago

    It was created as a bit of an art experiment. What happens when AI agents take prompts for another AI agents. What do they "discuss", do they give each other tips and advice, how much weird shit do they do...

    From that point of view, it's been rather interesting.

  • source
  • parent
  • [–] 16 points 6 months ago

    Well that didn't take long lmao

  • source
  • [–] 12 points 6 months ago

    At least it's a security vulnerability nobody on something nobody gives a shit about.

  • source