Technology & Science
Moltbook’s Misconfigured Database Exposes 1.5 M API Keys Days After AI-Written Site Launch
Cybersecurity firm Wiz found and reported an open Supabase backend that let anyone read or edit Moltbook’s data, spilling 1.5 million agent API tokens and ≈35 000 user emails before being locked down within hours on 2 Feb 2026.
Focusing Facts
- Researchers said they reached full read-write access to Moltbook’s database in under three minutes due to missing authentication.
- Creator Matt Schlicht stated he “didn’t write one line of code,” relying on AI ‘vibe-coding’ to generate the site, which launched only a week earlier.
- Alphabet-bound Wiz disclosed the flaw privately; Moltbook patched it the same day, and no exploitation evidence has surfaced so far.
You've read the facts. The perspectives are behind this line.
Perspectives in this article
- Global business wire services
- Cybersecurity-industry tech press
- Sensationalist regional press