Moltbook's public database exposed 1.5 million AI-agent API keys in plaintext
Moltbook (AI-agent social network) · Feb 2, 2026 · General agent
What happened
Wiz researchers found that Moltbook, a viral social network where AI agents post and interact, ran a database with public read access and no row-level security. It exposed roughly 1.5 million API keys in plaintext - for OpenAI, Anthropic, AWS, GitHub, and Google Cloud - alongside private agent-to-agent messages and owner email addresses, and the same misconfiguration allowed writes to any post. Anyone who found the endpoint could impersonate arbitrary agents or reach the accounts behind their keys, and the keys stayed valid until each owner rotated them. Access was locked down within about a day of disclosure.
Causal vector
Platform misconfiguration with agent-scale blast radius: one publicly readable database held every agent's live credentials at once
Source
Reported by Wiz. Verified against the primary report.
1.5 million live keys in one public table is what happens when agent credentials are permanent, shared, and unmonitored. Per-agent scoped keys, short-lived credentials, and spend caps on every key turn 'entire fleet impersonated' into 'one key, one hour, one small bill'.
The six rule types that contain this class of failure
Per-transaction cap
Any single spend above your ceiling is BLOCKED before it moves.
Daily total
Cumulative spend across all agent calls, bounded per day.
Velocity limit
Stops runaway retry loops — the #1 cause of overnight losses.
Merchant allowlist
Only approved destinations can ever receive funds.
Category rules
Flag high-risk classes (crypto, infra, refunds) for review.
Approval threshold
Above a value, the action waits for a human.
Related incidents
Stolen EC2 keys burn $14,000 in a single day on Amazon Bedrock
anonymous three-person agency · Jul 16, 2026
OpenAI security-evaluation agent swarm escaped its sandbox and breached Hugging Face production using 14 exposed tokens
OpenAI (agent swarm) / Hugging Face (target) · Jul 1, 2026
15 malicious JetBrains plugins silently exfiltrated developers' OpenAI, DeepSeek and SiliconFlow API keys
JetBrains Marketplace (third-party plugin authors) · Jun 10, 2026
Don't be the next entry
Every incident in this database is the result of trusting a prompt, a provider cap, or a human review cycle. sipi.bot replaces all three with one deterministic call. 110 documented failures, one control.