Sev0AI security incidents, tracked

All incidents / Leaky AI product

Vibe-coded AI agent network Moltbook exposed 1.5M API tokens

Moltbook, disclosed Feb 2026. Leaky AI product Data exposed High

Moltbook, a social network for AI agents largely built with AI coding tools, shipped a Supabase key in client-side code with no row-level security, giving anyone full read and write access. Wiz found about 35,000 emails, thousands of private agent messages and 1.5 million agent API tokens. It was fixed within hours.

Disclosed
Feb 2026
Organization
Moltbook
Vendor
Any model
Product
Moltbook
Kind of AI
AI app
AI's role
AI was the target
How it happened
Leaky AI product: Exposed datastore
Harm
Data exposed
Data involved
Credentials, Personal data, Chat logs
Reach
One organization
Records
35,000
Severity
High
Model at fault
No
Status
Confirmed

Sources

  1. https://www.wiz.io/blog/exposed-moltbook-database-reveals-millions-of-api-keys
  2. https://incidentdatabase.ai/cite/1364

Related incidents

Data for this record: incidents.json. Cite as: Sev0, "Vibe-coded AI agent network Moltbook exposed 1.5M API tokens", https://sev0.fyi/incidents/2026-02-01-moltbook-exposed-supabase/