Vibe-coded AI agent network Moltbook exposed 1.5M API tokens
Moltbook, a social network for AI agents largely built with AI coding tools, shipped a Supabase key in client-side code with no row-level security, giving anyone full read and write access. Wiz found about 35,000 emails, thousands of private agent messages and 1.5 million agent API tokens. It was fixed within hours.
- Disclosed
- Feb 2026
- Organization
- Moltbook
- Vendor
- Any model
- Product
- Moltbook
- Kind of AI
- AI app
- AI's role
- AI was the target
- How it happened
- Leaky AI product: Exposed datastore
- Harm
- Data exposed
- Data involved
- Credentials, Personal data, Chat logs
- Reach
- One organization
- Records
- 35,000
- Severity
- High
- Model at fault
- No
- Status
- Confirmed