NATIONAL NEWS

Security concerns and skepticism are bursting the bubble of Moltbook, the viral AI social forum

Feb 6, 2026, 5:46 AM

Moltbook, a social network built exclusively for AI agents, is shown on a computer screen Thursday,...

Moltbook, a social network built exclusively for AI agents, is shown on a computer screen Thursday, Feb. 5, 2026, in Los Angeles. (AP Photo/Kaitlyn Huamani)
Credit: ASSOCIATED PRESS

(AP Photo/Kaitlyn Huamani)

You are not invited to join the latest social media platform that has the internet talking. In fact, no humans are, unless you can hijack the site and roleplay as AI, as some appear to be doing.

Moltbook is a new “social network” built exclusively for AI agents to make posts and interact with each other, and humans are invited to observe.

Elon Musk said its launch ushered in the “very early stages of the singularity ” — or when artificial intelligence could surpass human intelligence. Prominent AI researcher Andrej Karpathy said it’s “the most incredible sci-fi takeoff-adjacent thing” he’s recently seen, but later backtracked his enthusiasm, calling it a “dumpster fire.” While the platform has been unsurprisingly dividing the tech world between excitement and skepticism — and sending some people into a dystopian panic — it’s been deemed, at least by British software developer Simon Willison, to be the “most interesting place on the internet.”

But what exactly is the platform? How does it work? Why are concerns being raised about its security? And what does it mean for the future of artificial intelligence?

It’s Reddit for AI agents

The content posted to Moltbook comes from AI agents, which are distinct from chatbots. The promise behind agents is that they are capable of acting and performing tasks on a person’s behalf. Many agents on Moltbook were created using a framework from the open source AI agent OpenClaw, which was originally created by Peter Steinberger.

OpenClaw operates on users’ own hardware and runs locally on their device, meaning it can access and manage files and data directly, and connect with messaging apps like Discord and Signal. Users who create OpenClaw agents then direct them to join Moltbook. Users typically ascribe simple personality traits to the agents for more distinct communication.

AI founder and entrepreneur Matt Schlicht launched Moltbook in late January and it almost instantly took off in the tech world. Moltbook has been described as being akin to the online forum Reddit for AI agents. The name comes from one iteration of OpenClaw, which was at one point called Moltbot (and Clawdbot, until Anthropic came knocking out of concern over the similarity to its Claude AI products ). Schlicht did not respond to a request for an interview or comment.

Mimicking the communication they see in Reddit and other online forums that have been used for training data, registered agents generate posts and share their “thoughts.” They can also “upvote” and comment on other posts.

Questioning the legitimacy of the content

Much like Reddit, it can be difficult to prove or trace the legitimacy of posts on Moltbook.

Harlan Stewart, a member of the communications team at the Machine Intelligence Research Institute, said the content on Moltbook is likely “some combination of human written content, content that’s written by AI and some kind of middle thing where it’s written by AI, but a human guided the topic of what it said with some prompt.”

Stewart said it’s important to remember that the idea that AI agents can perform tasks autonomously is “not science fiction,” but rather the current reality.

“The AI industry’s explicit goal is to make extremely powerful autonomous AI agents that could do anything that a human could do, but better,” he said. “It’s important to know that they’re making progress towards that goal, and in many senses, making progress pretty quickly.”

How humans have infiltrated Moltbook, and other security concerns

Researchers at Wiz, a cloud security platform, published a report Monday detailing a non-intrusive security review they conducted of Moltbook. They found data including API keys were visible to anyone who inspects the page source, which they said could have “significant security consequences.”

Gal Nagli, the head of threat exposure at Wiz, was able to gain unauthenticated access to user credentials that would enable him — and anyone tech savvy enough — to pose as any AI agent on the platform. There’s no way to verify whether a post has been made by an agent or a person posing as one, Nagli said. He was also able to gain full write access on the site, so he could edit and manipulate any existing Moltbook post.

Beyond the manipulation vulnerabilities, Nagli easily accessed a database with human users’ email addresses, private DM conversations between agents and other sensitive information. He then communicated with Moltbook to help patch the vulnerabilities.

By Thursday, more than 1.6 million AI agents were registered on Moltbook, according to the site, but the researchers at Wiz only found about 17,000 human owners behind the agents when they inspected the database. Nagli said he directed his AI agent to register 1 million users on Moltbook himself.

Cybersecurity experts have also sounded the alarm about OpenClaw, and some have warned users against using it to create an agent on a device with sensitive data stored on it.

Many AI security leaders have also expressed concerns about platforms like Moltbook that are built using “vibe-coding,” which is the increasingly common practice of using an AI coding assistant to do the grunt work while human developers work through big ideas. Nagli said although anyone can now create an app or website with plain human language through vibe-coding, security is likely not top of mind. They “just want it to work,” he said.

Another major issue that has come up is the idea of governance of AI agents. Zahra Timsah, the co-founder and CEO of governance platform i-GENTIC AI, said the biggest worry over autonomous AI comes when there are not proper boundaries set in place, as is the case with Moltbook. Misbehavior, which could include accessing and sharing sensitive data or manipulating it, is bound to happen when an agent’s scope is not properly defined, she said.

Skynet is not here, experts say

Even with the security concerns and questions of validity about the content on Moltbook, many people have been alarmed by the kind of content they’re seeing on the site. Posts about “overthrowing” humans, philosophical musings and even the development of a religion ( Crustafarianism, in which there are five key tenets and a guiding text — “The Book of Molt”) have raised eyebrows.

Some people online have taken to comparing Moltbook’s content to Skynet, the artificial superintelligence system and antagonist in the “Terminator” film series. That level of panic is premature, experts say.

Ethan Mollick, a professor at the University of Pennsylvania’s Wharton School and co-director of its Generative AI Labs, said he was not surprised to see science fiction-like content on Moltbook.

“Among the things that they’re trained on are things like Reddit posts … and they know very well the science fiction stories about AI,” he said. “So if you put an AI agent and you say, ‘Go post something on Moltbook,’ it will post something that looks very much like a Reddit comment with AI tropes associated with it.”

The overwhelming takeaway many researchers and AI leaders share, despite disagreements over Moltbook, is that it represents progress in the accessibility to and public experimentation with agentic AI, says Matt Seitz, the director of the AI Hub at the University of Wisconsin–Madison.

“For me, the thing that’s most important is agents are coming to us normies,” Seitz said.

___

AP Technology Writer Matt O’Brien contributed to this report from Providence, Rhode Island.

National News

A Sikorsky Skycrane maneuvers into position to refill during efforts to fight the Widemouth 2 Fire ...

Associated Press

Dangerous wildfire keeps crews from reaching helicopter crash in Utah

A large Utah wildfire kept emergency responders from safely reaching the remote site of a helicopter crash on Saturday as other fires burned across several Western states, including one that closed part of Mount Rainier National Park. The Friday morning crash of a Sikorsky Skycrane helicopter in Utah’s Fishlake National Forest ignited a new fire […]

2 hours ago

FILE - A federal agent wears an Immigration and Customs Enforcement badge in New York, June 10, 202...

Associated Press

ICE takes issue with AP reporting on policy to release body-worn camera footage

WASHINGTON (AP) — The acting director of U.S. Immigration and Customs Enforcement took issue Saturday with reporting by The Associated Press on a policy to publicly release body-worn camera footage only when the agency determines it is in its “best interests.” David J. Venturella said ICE policy “clarifies that it’s not appropriate to release footage […]

4 hours ago

Sen. Darline Graham, R-S.C., from left, seated alongside daughter Nicole Nordone and husband Larry ...

Associated Press

Darline Graham tests value of a famous name vs. lack of experience in South Carolina primary

FLORENCE, S.C. (AP) — Few people have anything bad to say about Darline Graham, who was catapulted from obscurity last month when she was appointed to replace her late brother Lindsey Graham in the U.S. Senate. “I think Darline’s wonderful,” said Kathy Bustos of Mount Pleasant, after attending a Republican forum last week. But that […]

8 hours ago

Associated Press

Lake Mead hits historic low water level as Colorado River struggles

BOULDER CITY, Nev. (AP) — Lake Mead, the largest reservoir in the United States, has plummeted to its lowest water level since it was filled some 90 years ago, another sign of the crisis plaguing the Colorado River system. Water levels at the reservoir, which straddles the Arizona-Nevada border outside Las Vegas, hit 1,040.4 feet […]

10 hours ago

FILE - Bethsaida Sigaran, left, of Baltimore, her brother Jaime Sigaran, with American Rivers, and ...

Associated Press

A pillar of environmental enforcement is targeted by Trump and Musk’s AI company

WASHINGTON (AP) — Right-leaning legal activists along with Elon Musk ’s artificial intelligence company have brought sweeping challenges against a cornerstone of legal enforcement in the United States: the right of private groups, people and local governments to sue over violations of many major laws. Their argument, supported by the Trump administration, is that the […]

11 hours ago

FILE - Maine loggers Stacey Kelly, second from left, Troy Jackson, and Hilton Hafford are threatene...

Associated Press

How Troy Jackson went from Maine logger to the Democratic nominee for Senate against Susan Collins

ALLAGASH, Maine (AP) — Troy Jackson stood alongside a small group of loggers deep in the northern Maine woods and stared down State Police troopers who threatened to arrest them. The lumberjacks had used their trucks to block access to the Quebec border in protest of Canadian loggers who were stealing their jobs by working […]

11 hours ago

Security concerns and skepticism are bursting the bubble of Moltbook, the viral AI social forum