What happened
Moltbook’s founder publicly described building the platform with AI without writing its code himself. Wiz researchers found a misconfigured database that permitted unauthenticated reading and writing. The exposed information included 1.5 million authentication tokens, 35,000 email addresses, and private messages between agents. Wiz disclosed the issue and helped the team secure it within hours.
Source notes
Wiz’s firsthand investigation identifies missing database access controls. A public Supabase key in browser code is not, by itself, a security flaw. The unsafe permissions behind it were critical. Exposure does not establish that malicious actors stole every record.
What went wrong
The app could run while database permissions still allowed access that should have been blocked. A working interface did not prove privacy.
What to notice and test
Before using real personal information, have someone qualified check access controls and test what a signed-out visitor can read or change. A successful demo does not prove that privacy rules work.
Try it together
Draw a pretend app with paper cards. Label which cards everyone may see and which only their owner may see. Check whether your design gives the right people access.