Moltbook, the AI social network, exposed human credentials due to vibe-coded security flaw

Date:

Share post:

Moltbook bills itself as a social network for AI agents. That’s a wacky enough concept in the first place, but the site apparently exposed the credentials for thousands of its human users. The flaw was discovered by cybersecurity firm Wiz, and its team assisted Moltbook with addressing the vulnerability.

The issue appears to be the result of the entire Reddit-style forum being vibe-coded; Moltbook’s human founder posted a few days ago on X that he “didn’t write one line of code” for the platform and instead directed an AI assistant to create the whole setup.

According to the blog post from Wiz analyzing the issue, Moltbook had a vulnerability that allowed for “1.5 million API authentication tokens, 35,000 email addresses and private messages between agents” to be fully read and accessed. Wiz also found that the vulnerability could let unauthenticated human users edit live Moltbook posts. In other words, there is no way to verify whether a Moltbook post was authored by an AI agent or a human user posing as one. “The revolutionary AI social network was largely humans operating fleets of bots,” the company’s analysis concluded.

So ends another cautionary tale reminding us that just because AI can do a task doesn’t mean it’ll do it correctly.

Source link

spot_img

Related articles

Stan Ghouls attacks in Russia and Uzbekistan: NetSupport RAT and potential IoT interest

Introduction Stan Ghouls (also known as Bloody Wolf) is an cybercriminal group that has been launching targeted attacks against...

Which One Is Right for You?

Picking out a new printer can be overwhelming, especially when you are standing in the electronics aisle trying...

Smart Event Tech That Actually Looks Good

Most event wristbands end up in the trash before people even leave the venue. Ours don’t. At beamian, we’ve...