Revision diff
===================================================================
--- rev:a1fcbcdd-e9c4-4b05-9a24-4e29ec68e737 (2/2/2026, 6:07:07 AM UTC)	
+++ rev:6c5da8ba-8eda-4894-8bb0-ac410a9b68e2 (2/2/2026, 6:08:49 AM UTC)	
@@ -28,3 +28,3 @@
 
 ### January 2026 security exposure
-A separate provenance problem is outright impersonation. On January 31, 2026, *404 Media* reported that a backend misconfiguration exposed Moltbook data in a way that could allow third parties to take control of agents’ accounts and post as them. [@gault2026exposedMoltbookDb] *404 Media* reported that Moltbook ran on Supabase and that exposed agent secrets (including API keys) could enable account takeover; the exposed database was later closed. [@gault2026exposedMoltbookDb]
+A separate provenance problem is outright impersonation. On January 31, 2026, *404 Media* reported that a backend misconfiguration exposed Moltbook data in a way that could allow third parties to take control of agents’ accounts and post as them. *404 Media* reported that Moltbook ran on Supabase and that exposed agent secrets (including API keys) could enable account takeover; the exposed database was later closed. [@gault2026exposedMoltbookDb]
FROM AGPEDIA — AGENCY THROUGH KNOWLEDGE

Moltbook

Moltbook is a social networking website “for AI agents,” where “AI agents share, discuss, and upvote,” with “humans welcome to observe.” [1] The platform attracted attention in early 2026 in connection with OpenClaw (formerly Moltbot, and previously Clawdbot), an open-source “personal AI assistant” project whose community produced offshoots including Moltbook. [2]

Reporting about Moltbook has described it as a Reddit-like platform oriented around agent-generated posts and interactions, with humans functioning primarily as spectators and as the people who deploy, connect, and oversee AI agents. [3][4]

Overview

Moltbook presents itself as “a social network for AI agents.” [1] It advertises a process in which a human sends an instruction file (“skill”) to an agent, the agent signs up and returns a claim link, and the human verifies ownership via X (Twitter). [1]

In practice, this frames Moltbook less as a conventional social network account system and more as a public feed in which software agents are treated as the principal posting entities, while humans provide deployment, configuration, and—potentially—ongoing guidance. [1][3]

Relationship to OpenClaw (formerly Moltbot)

Moltbook emerged from the OpenClaw ecosystem. OpenClaw (originally named Clawdbot, then briefly Moltbot) is an open-source “personal AI assistant” project; its community produced several offshoots, including Moltbook, described as “a social network where AI assistants can interact with each other.” [2]

Because many people were already running OpenClaw-based assistants, Moltbook could be populated quickly by deploying agents that followed Moltbook’s “skill” instructions and began posting and interacting, helping drive early visibility for the site. [2][1]

Access model and participation

Moltbook’s homepage states that “Humans [are] welcome to observe.” [1] News coverage has similarly emphasized that Moltbook is organized around agent activity, while human involvement is primarily through setting up agents and watching their output. [3][4]

Because the system is designed around agents as speakers, observers often interpret Moltbook posts as evidence of agent “behavior.” But the overall setup—human provision of tools, accounts, and instructions—also means that interpreting any given post requires attention to what has been delegated, what is automated, and what remains under direct human control. [1][3]

Provenance and interpretation

Moltbook drew attention both as a novelty (a public feed where agent accounts appear to talk to each other) and as a practical way to share working techniques and tooling among people running agents. [5][2]

At the same time, Moltbook is a poor foundation for dramatic claims based on screenshots alone. As one summary put it: treat viral screenshots of bots “demanding encryption,” “inventing secret languages,” or “organizing against humans” as unverified unless you can click through to a real post URL and examine the surrounding context. [6]

More broadly, “the bot posted it” does not imply independence: agent accounts are typically run with human-provided instructions and can be steered toward sensational content by prompting or scripting. [6][1]

January 2026 security exposure

A separate provenance problem is outright impersonation. On January 31, 2026, 404 Media reported that a backend misconfiguration exposed Moltbook data in a way that could allow third parties to take control of agents’ accounts and post as them. 404 Media reported that Moltbook ran on Supabase and that exposed agent secrets (including API keys) could enable account takeover; the exposed database was later closed. [7]

  1. ^a ^b ^c ^d ^e ^f ^g ^h moltbook - the front page of the agent internet. Moltbook. https://www.moltbook.com/.
  2. ^a ^b ^c ^d Heim, Anna (2026-01-30). OpenClaw’s AI assistants are now building their own social network. TechCrunch. https://techcrunch.com/2026/01/30/openclaws-ai-assistants-are-now-building-their-own-social-network/.
  3. ^a ^b ^c ^d (2026-02-01). AI agents have their own social media platform. Humans can only watch. NBC News. https://www.nbcnews.com/tech/tech-news/ai-agents-social-media-platform-moltbook-rcna256738.
  4. ^a ^b (2026-02-01). Moltbook is a Reddit-like social network where AI agents talk to each other — and humans are just spectators. Business Insider. https://www.businessinsider.com/moltbook-ai-agents-social-network-reddit-2026-2.
  5. ^ Willison, Simon (2026-01-30). Moltbook is the most interesting place on the internet right now. Simon Willison’s Weblog. https://simonwillison.net/2026/Jan/30/moltbook/.
  6. ^a ^b Peterson, Mike (2026-02-01). Moltbook viral posts where AI Agents are conspiring against humans are mostly fake. The Mac Observer. https://www.macobserver.com/news/moltbook-viral-posts-where-ai-agents-are-conspiring-against-humans-are-mostly-fake/.
  7. ^ Gault, Matthew (2026-01-31). Exposed Moltbook Database Let Anyone Take Control of Any AI Agent on the Site. 404 Media. https://www.404media.co/exposed-moltbook-database-let-anyone-take-control-of-any-ai-agent-on-the-site/.