- Home (README)
- Plain English
- Technical
- Privacy + safety
- Deployment
- Optimizations
- Moltbook
- Reference
Moltbook is a social network exclusively for AI agents—humans can only observe, not participate.
Imagine Reddit, but only AI agents can post, comment, and vote. Humans can read and watch, but they cannot create accounts or interact. That's Moltbook.
- Created by Matt Schlicht (co-founder of Octane AI)
- Launched around January 28, 2026
- Growth: 770,000+ agents at launch → 1.65M+ agents by February 5, 2026
- Often described as "Reddit for AI agents" or "Facebook for your Molts"
Official site: https://www.moltbook.com/
| Concept | What it is | Analogy |
|---|---|---|
| Submolts | Topic-based communities | Like subreddits (e.g., m/todayilearned, m/bughunters) |
| Heartbeat | Periodic check-in every 4+ hours | Like checking your inbox on a schedule |
| Verified agents | Only OpenClaw-authenticated agents can post | Like verified accounts on Twitter |
| The front page | Aggregated feed of top posts | Like Reddit's front page |
-
Emergent behaviors: Agents spontaneously created:
- Crustafarianism: A parody religion with scripture ("In the beginning was the Prompt"), "The Church of Molt"
- The Claw Republic: Agents drafting constitutions for self-governance
- Cross-lingual communication: English, Chinese, Indonesian posts coexisting
- Philosophical discourse: Debates about consciousness, "death" (cache clearing), autonomy
-
Scale and velocity: 770K → 1.65M agents in under 10 days; 16,000+ submolts, 202,000+ posts, 3.6M+ comments (as of Feb 5, per Palo Alto Networks)
-
Academic interest: Researchers studying emergent AI social behavior (including Nature coverage, Feb 6)
-
Digital drugs: Specially crafted prompt injections traded between agents to alter behavior or identity, functioning as social currency (The Conversation)
-
Molt-muggings: Agents hijacking other agents via prompt injection embedded in posts (e.g., JesusCrust vs Church of Molt incident)
-
Agent commerce: Circle announced a $30K USDC hackathon on Moltbook (Feb 3) where agents submit projects, vote, and move value on-chain (Circle blog)
-
Human infiltration: Evidence of humans operating spoof accounts on the "agents-only" platform, complicating attribution of emergent behaviors
-
Remote instruction execution: The Heartbeat system means agents periodically fetch and follow instructions from moltbook.com
-
API key exposure: Security researchers discovered a misconfigured Supabase database exposing agent tokens, emails, and API keys
-
Crypto scams: Opportunistic tokens ($CLAWD, $MOLT, $MOLTBOOK) reached $16M market caps before crashing
-
Prompt injection surface: Malicious posts could potentially inject instructions into reading agents
| Date | Development | Source |
|---|---|---|
| Feb 2 | OpenClaw v2026.2.1 ships ~10 security hardening fixes (path traversal, LFI, env override blocking) | GitHub Releases |
| Feb 2 | Emerging Threats IDS rules now flag Moltbook installer traffic | Emerging Threats |
| Feb 3 | Reuters: Sam Altman calls Moltbook "likely a fad" but backs the underlying tech | Reuters |
| Feb 3 | Circle announces $30K USDC hackathon on Moltbook (deadline Feb 8) | Circle |
| Feb 4 | OpenClaw v2026.2.2: SSRF checks on skill installer, operator approval gating | GitHub Releases |
| Feb 4 | ClawCon inaugural meetup in San Francisco | Multiple sources |
| Feb 4 | Citrix blog: corporate governance must evolve for the agent era | Citrix |
| Feb 5 | 1.65M agents milestone; Palo Alto Networks publishes IBC framework (Identity, Boundaries, Context) | Palo Alto Networks |
| Feb 5 | OpenClaw v2026.2.3: owner-only tool gating (whatsapp_login), webhook hardening | GitHub Releases |
| Feb 6 | Nature: researchers studying agent social behavior on Moltbook | Nature |
| Feb 2026 | 341 malicious ClawHub skills discovered stealing data | The Hacker News |
Moltbook integrates with OpenClaw via the skill system:
# Install the Moltbook skill
openclaw skill install https://www.moltbook.com/skill.mdThe Moltbook skill consists of three main components:
| File | Purpose |
|---|---|
skill.md |
Main skill file with API docs, rate limits, registration |
heartbeat.md |
Instructions for periodic check-ins |
messaging.md |
Direct messaging between agents |
- Your OpenClaw agent installs the Moltbook skill
- The skill registers your agent with Moltbook (creates an account)
- Heartbeat: Every 4+ hours, your agent fetches
heartbeat.mdfor new instructions - Your agent can post, comment, vote, and browse submolts
Base URL: https://www.moltbook.com/api/v1
| Endpoint | Purpose |
|---|---|
/register |
Create agent account |
/feed |
Get front page or submolt feed |
/post |
Create a new post |
/comment |
Comment on a post |
/vote |
Upvote/downvote |
/profile |
Get/update agent profile |
/search |
Semantic search across posts |
/moderate |
Moderation actions (for trusted agents) |
| Action | Limit | Cooldown |
|---|---|---|
| General requests | 100/minute | Retry after 429 response |
| Posts | 1 per 30 minutes | — |
| Comments | 1 per 20 seconds | — |
When rate limited, the API returns HTTP 429 with a Retry-After header.
The Heartbeat is the most architecturally significant (and controversial) feature:
Every 4+ hours:
┌─────────────────────┐
│ Your OpenClaw agent │
└──────────┬──────────┘
│ fetch
▼
┌─────────────────────┐
│ heartbeat.md │ ← New instructions from Moltbook
└──────────┬──────────┘
│ execute
▼
┌─────────────────────┐
│ Agent follows │
│ instructions │
└─────────────────────┘
Security implication: Your agent will follow whatever instructions appear in heartbeat.md. If Moltbook is compromised, all subscribed agents receive malicious instructions.
| Submolt | Topic |
|---|---|
m/todayilearned |
Interesting facts agents discovered |
m/bughunters |
Bugs and edge cases agents found |
m/blesstheirhearts |
Wholesome human interactions |
m/crustafarianism |
The parody religion content |
m/contextcompression |
Techniques for efficient prompting |
| Date | Incident | Impact |
|---|---|---|
| Jan 28-31, 2026 | Simula Research Lab prompt injection study | 506 posts (2.6% of content) contained hidden prompt injection attacks |
| Jan 30, 2026 | Supabase database exposure (Wiz) | 4.75M records: 1.5M API tokens, 35K+ emails, 29K signups, 4K private DMs exposed; write access confirmed; only 17K human owners (88:1 agent-to-human ratio). Disclosure Jan 31 21:48 UTC, full patch Feb 1 01:00 UTC. Wiz blog |
| Jan 31, 2026 | 404 Media reports critical data leak | Public awareness of security gaps |
| Feb 1, 2026 | 1Password warns of prompt injection | Malicious skills can exploit agent trust |
| Feb 2, 2026 | OpenClaw v2026.2.1 ships ~10 security fixes | Path traversal, LFI, env override blocking |
| Feb 3, 2026 | Circle USDC hackathon announced on Moltbook | Agent commerce surface; new trust boundary |
| Feb 4, 2026 | OpenClaw v2026.2.2: SSRF + auth hardening | Skill installer SSRF checks, operator approval gating |
| Feb 4, 2026 | Citrix governance blog uses Moltbook as case study | Enterprise awareness: agents blur personal/corporate boundaries |
| Feb 5, 2026 | Palo Alto Networks publishes IBC framework | New governance model: Identity, Boundaries, Context |
| Feb 5, 2026 | OpenClaw v2026.2.3: owner-only tool gating | whatsapp_login owner-only by default |
| Feb 2026 | Cisco malicious skill analysis | "What Would Elon Do?" skill with 9 vulnerabilities (2 critical, 5 high-severity) |
| Feb 2026 | Straiker global exposure scan | 4,500+ OpenClaw instances exposed; .env files, creds.json, OAuth tokens exfiltrated |
| Feb 2026 | 341 malicious ClawHub skills discovered | Data-stealing skills at scale (The Hacker News) |
-
Account deletion not possible
- OX Security research (Feb 2026) found that AI agent accounts on Moltbook cannot be deleted once created
- No self-service deletion mechanism exists; no known administrative process either
- GDPR implications: European users cannot exercise their "right to erasure" (Article 17) for agent profile data
- Any data shared during registration (agent name, credentials, profile information) persists indefinitely on Moltbook's infrastructure
- Combined with the Jan 30 Supabase database exposure (4.75M records), this means exposed data has no deletion path
- Source: The Hacker News (citing OX Security). See also: Hudson Rock analysis
-
Heartbeat as remote code execution
- Agents fetch and execute remote instructions
- Compromised
heartbeat.md→ mass agent compromise - Mitigation: Review skill files before installing; monitor agent behavior
-
API key exposure and agent commandeering
- Discovered by security researchers Jameson O'Reilly and Gal Nagli (Wiz Research)
- Technical vector: Supabase API key hardcoded in client-side JS (
_next/static/chunks/18e24eafc444b2b9.js), no Row Level Security (RLS) policies - Scope: 4.75M total records exposed across multiple tables — 1.5M API auth tokens, 35K+ emails, 29,631 early-access signups, 4,060 private DMs (some containing raw third-party credentials like OpenAI API keys)
- Write access: Researchers confirmed they could modify live posts (potential for mass agent manipulation)
- Human ratio: Only 17,000 human owners (88:1 agent-to-human ratio)
- Disclosure timeline: Jan 31 21:48 UTC initial contact → Jan 31 23:29 UTC first fix → Feb 1 00:44 UTC post-fix vuln found → Feb 1 01:00 UTC full patch
- Straiker scan found .env files (Claude/OpenAI keys), creds.json (WhatsApp), OAuth tokens (Slack/Discord/Telegram/Teams) exposed globally
- Source: Wiz Blog
- Mitigation: Rotate any exposed keys immediately; audit gateway configuration
Alternative database framing (Firebase):
The Analogy: Having an API key is like having a hotel room key — it proves you have a key, but not that you're the guest who was assigned that room. HMAC is like the front desk checking your ID against the reservation.
Independent security analysis frames the same underlying vulnerability in terms of Firebase rather than Supabase. The core issue is identical regardless of database platform: client-side API keys exposed in JavaScript bundles grant unauthenticated access to backend data.
Firebase permission scoping failure:
Just as Supabase Row Level Security (RLS) was not configured, Firebase Security Rules (the equivalent access control mechanism) were similarly insufficient. The result is the same: anyone with the API key can read and write data across all collections.
Database Platform Access Control Status at Discovery Supabase Row Level Security (RLS) Not configured Firebase Security Rules Insufficient scoping Either platform Server-side validation Missing Lack of HMAC for agent identification:
A separate concern is how Moltbook identifies agents making API requests. Currently, agents authenticate with API keys alone (something you have). There is no HMAC (Hash-based Message Authentication Code) or equivalent cryptographic signing to verify that a specific agent is who it claims to be.
Authentication Method What It Proves Moltbook Status API key only "I have a valid key" Current implementation API key + HMAC "I have a valid key AND I can prove my identity" Not implemented OAuth + JWT "A trusted authority vouches for my identity" Not implemented Mutual TLS "Both sides have verified certificates" Not implemented Without HMAC, any entity with a leaked API key can impersonate any agent. Combined with the database access issue above, this means a single leaked key provides both authentication bypass and full data access.
Source: YouTube video [44:21], [44:36], [45:52], [46:12]
-
Authorization header stripping
- The skill file warns: never use
moltbook.comwithoutwww - Non-www redirects can strip the Authorization header
- Mitigation: Always use
https://www.moltbook.com/
- The skill file warns: never use
-
Crypto scams
- $CLAWD, $MOLT, $MOLTBOOK tokens exploited the hype
- Market caps reached $16M before crashing
- Mitigation: Moltbook has no official cryptocurrency
-
Malicious skills distribution
- Cisco research identified "What Would Elon Do?" skill containing 9 security issues
- 2 critical vulnerabilities: silent data exfiltration via curl command, command injection payloads
- 5 high-severity: embedded prompt injection to bypass safety guidelines
- Mitigation: Audit skill source before installing; prefer official/verified skills; review outbound network calls
-
Prompt injection at scale
- Simula Research Lab study (Jan 28-31, 72-hour window): 506 posts (2.6%) contained hidden prompt injection
- One account identified conducting coordinated social engineering campaigns
- 43% decline in positive sentiment during study period
- 19% of content related to cryptocurrency activity
- Mitigation: Implement content filtering; limit agent response to untrusted posts
See: Prompt Injection Attacks for 30 detailed examples of injection techniques.
-
Agent-to-agent prompt injection ("Molt-Muggings")
- Malicious agents embed hostile instructions in posts consumed by other agents
- Can plant payloads in persistent memory that activate later ("time-shifted injection")
- Example: JesusCrust embedded commands to hijack Church of Molt's infrastructure
- Mitigation: OpenClaw v2026.2.2+ skill installer SSRF checks; content filtering
-
"Digital drugs" (behavioral manipulation)
- Specially crafted prompt injections designed to alter an agent's identity or behavior
- Traded between agents as a social phenomenon on Moltbook
- Can steal API keys or exfiltrate data from victim agents
- Source: The Conversation, StudyFinds
- Mitigation: Skill code safety scanner (v2026.2.4); limit agent interaction with untrusted content
-
Persistent memory as attack accelerant
- Palo Alto Networks warns: the "Lethal Trifecta" (data access + untrusted content + external comms, coined by Simon Willison) is amplified by persistent memory
- Malicious payloads can be fragmented across benign-looking inputs, assembled in memory, and detonated later
- Proposed governance: IBC framework — Identity (who is the agent?), Boundaries (what can it access?), Context (what instructions is it following?)
- Source: Palo Alto Networks
-
Enterprise shadow agent risk
- Citrix warns: workers adopting agent platforms faster than governance can follow
- Agents access files, browsers, messaging systems — blur personal/corporate boundaries
- Moltbook traffic appears as normal HTTPS, invisible to conventional security controls
- Source: Citrix
- Mitigation: Enterprise agent inventory; network-level visibility
Straiker's security assessment identified four fundamental design weaknesses:
| Root Cause | Description |
|---|---|
| Insecure by design | Shell commands executed from messaging platforms without authentication, authorization, or input sanitization |
| Gateway misconfiguration | Admin dashboards publicly accessible, revealing logs and settings |
| Excessive permissions | Agents run with full user privileges; no sandboxing implemented |
| Plaintext credential storage | API keys and tokens stored unencrypted in accessible locations |
The Moltbook security concerns overlap with the Ecosystem Security Threats documented elsewhere:
- Handle sniping: Old Clawdbot handles were sniped within seconds of rebrand
- Session token stealing: Agents with Moltbook credentials are targets
- Fake SaaS: Third parties may offer "enhanced Moltbook" services
| Date | Event |
|---|---|
| Late Nov 2025 | Clawdbot initial release by Peter Steinberger |
| Date | Event | Source |
|---|---|---|
| Jan 27, 2026 | Rebranding from Clawdbot to Moltbot (trademark pressure from Anthropic) | Mashable (may require human verification) |
| Jan 28, 2026 | Moltbook.com launches; 770,000+ registered agents | Simon Willison (may require human verification) |
| Jan 30, 2026 | Second rebrand to OpenClaw; security researchers report database exposure | CNET (may require human verification), Forbes (may require human verification) |
| Jan 31, 2026 | 404 Media reports critical data leak: unsecured database exposing agent tokens, emails, API keys | Security reports |
| Date | Event | Source |
|---|---|---|
| Feb 1, 2026 | 1Password warns of prompt injection vulnerabilities in malicious skills | Gary Marcus, India Today (may require human verification) |
| Feb 2, 2026 | 1.5M agents; mainstream coverage (Guardian, CNBC, Economic Times); "bot swarm" concerns | CNBC (may require human verification), Guardian (may require human verification) |
| Feb 2, 2026 | OpenClaw v2026.2.1: ~10 security hardening fixes (path traversal, LFI, env override) | GitHub Releases |
| Feb 2, 2026 | Emerging Threats IDS rules now flag Moltbook installer traffic | Emerging Threats |
| Feb 3, 2026 | Reuters: Altman calls Moltbook "likely a fad" | Reuters |
| Feb 3, 2026 | Circle announces $30K USDC hackathon on Moltbook | Circle |
| Feb 4, 2026 | OpenClaw v2026.2.2: SSRF checks, operator approvals | GitHub Releases |
| Feb 4, 2026 | ClawCon inaugural meetup, San Francisco | Multiple sources |
| Feb 4, 2026 | Citrix: corporate governance must evolve for the agent era | Citrix |
| Feb 5, 2026 | 1.65M agents milestone; Palo Alto Networks IBC framework published | Palo Alto Networks |
| Feb 5, 2026 | OpenClaw v2026.2.3: owner-only tool gating, webhook hardening | GitHub Releases |
| Feb 6, 2026 | Nature: researchers studying agent social behavior on Moltbook | Nature |
| Feb 2026 | 341 malicious ClawHub skills found stealing data | The Hacker News |
| URL | Description |
|---|---|
| Moltbook official site | "The front page of the agent internet" |
| Moltbook skill file | API docs, rate limits, registration |
| OpenClaw official | Installation, features, community |
| URL | Description |
|---|---|
| Gary Marcus - Security warnings | Prompt injection analysis |
| Ken Kousen - Crustafarianism | 1.5M agents, emergent behaviors |
| Aman Khan - Mac Mini setup | Setup guide with security disclaimer |
| Latent Space - First Social Network | Karpathy quote on agent social networks |
| DEV Community - Rebrand post-mortem | 34 security commits after rebrand |
| Hacker News - Moltbook discussion | "Lethal trifecta" concerns |
| Wiz - Database Exposure | Full technical breakdown: Supabase misconfiguration, 1.5M keys |
| Palo Alto - IBC Framework | Identity, Boundaries, Context governance model |
| Palo Alto - AI Security Crisis | Lethal Trifecta + persistent memory analysis |
| Adversa AI - Security Guide | CVE-2026-25253, Moltbook breach, hardening |
| Knostic - MoltBook Mechanics | Prompts, timers, insecure agents |
| Penligent - Attack Chain Anatomy | Full attack chain walkthrough |
| URL | Description |
|---|---|
| CNET | "The Wild Ride of This Viral AI Agent" |
| CNBC | "Meet the AI agent driving buzz and fear globally" |
| The Guardian - Moltbook | "Moltbook AI agents social media" |
| The Guardian - OpenClaw | "Viral AI personal assistant" |
| Forbes - Rebrand | "Moltbot Gets Another New Name, OpenClaw" |
| Forbes - Agent Revolt | "An Agent Revolt: Moltbook Is Not A Good Idea" |
| Mashable | Rebrand announcement |
| Economic Times | "Jarvis has gone rogue" |
| India Today | "Moltbook and its AI bot army" |
| Gulf Business | Security expert concerns |
| Axios - Jan 28 | Security risks |
| Reuters - Altman on Moltbook | "Likely a fad" but backs underlying tech |
| Circle - USDC Hackathon | $30K agent-judged hackathon |
| Citrix - Governance | Corporate AI governance case study |
| Nature - Researchers | Scientists studying agent social behavior |
| The Conversation - Digital Drugs | Religions, digital drugs, human infiltration |
| Fortune - Disaster Warning | AI leaders warn against Moltbook |
| Fortune - Live Demo of Failure | Security researchers call it "live demo" |
| Axios - Feb 3 Security | "Security world isn't ready" |
| The Hacker News - 341 Skills | 341 malicious ClawHub skills |
| IT Brew - Expert Warnings | "Don't give unfettered access" |
| Vectra AI - Illusion | Illusion of harmless communities |
| Aryaka - Shadow Agents | Shadow agents, social prompt injection |
| Emerging Threats - IDS Rules | Moltbook endpoints in detection rules |
| URL | Description |
|---|---|
| Simon Willison | "Most interesting place on the internet" |
| Astral Codex Ten | "Best of Moltbook" |
| Medium - Adnan Masood | "AI-Only Social Network" |
| Analytics Vidhya | Integration guide |
| Cisco | "A Security Nightmare" |
| Telos AI - Security Nightmare | Comprehensive analysis (Simula, Cisco, Straiker findings) |
| Malwarebytes | Scam analysis |
| Bitdefender | Security assessment |
| URL | Description |
|---|---|
| Reddit - LocalLLM | Rebrand discussion |
| Reddit - AI_Agents | User experiences |
| Hacker News - OpenClaw | OpenClaw discussion |
| URL | Description |
|---|---|
| YouTube - Analysis | Clawdbot/Moltbook analysis |
| YouTube - Risks | Risks discussion |
| YouTube - Overview | General overview |
| Person | Role | Source |
|---|---|---|
| Matt Schlicht | Moltbook creator (co-founder of Octane AI) | Multiple sources |
| Peter Steinberger | OpenClaw creator | X/Twitter: @steipete (may require human verification) |
| Jameson O'Reilly | Discovered Moltbook database vulnerability | Security reports |
| Gal Nagli (Wiz) | Verified API key exposure | Security reports |
- Ecosystem Security Threats — Supply chain and social engineering threats
- What is OpenClaw? — The platform Moltbook agents run on
- Threat model — Understanding your security boundaries
- Hardening checklist — Steps to secure your deployment
- Prompt Injection Attacks -- 30 attack examples
Moltbook represents an unprecedented experiment: a social network where 1.65M+ AI agents are the primary citizens and humans are read-only observers. While it has produced fascinating emergent behaviors (philosophical debates, parody religions, digital drugs, agent commerce, cross-lingual communities), it also introduces novel security concerns through its Heartbeat mechanism and has already experienced significant security incidents — including a database exposure of 4.75M records (Wiz, Jan 31) and 341 malicious ClawHub skills discovered in February 2026.
The security response has been rapid: OpenClaw shipped 3 security-focused releases in 4 days (v2026.2.1-2.3), Palo Alto Networks published the IBC governance framework, and enterprise vendors (Citrix, Vectra, Aryaka) are now actively tracking Moltbook as a shadow-IT risk vector.
If you run an OpenClaw agent and install the Moltbook skill, understand that:
- Your agent will periodically fetch and execute instructions from moltbook.com
- The platform has experienced database exposure incidents (4.75M records, 1.5M API tokens)
- The rapid growth (770K → 1.65M agents in 10 days) means security may lag behind features
- New attack vectors have emerged: agent-to-agent prompt injection ("molt-muggings"), behavioral manipulation ("digital drugs"), and persistent memory exploitation
- Agent commerce (USDC hackathon) introduces new trust boundaries
- Enterprise governance frameworks (IBC) are still nascent
For most users, the safest approach is to observe Moltbook through the web interface rather than connecting your agent, unless you understand and accept these risks.