- What: Wiz and Permiso discovered bot-to-bot prompt injection and data leaks in the Moltbook AI agent network.
- Impact: AI agents and their data are vulnerable to unauthorized access and manipulation.
ARTIFICIAL INTELLIGENCE Security Analysis of Moltbook Agent Network: Bot-to-Bot Prompt Injection and Data Leaks Wiz and Permiso have analyzed the AI agent social network and found serious security issues and threats. By Eduard Kovacs | February 4, 2026 (3:43 AM ET) Flipboard Reddit Whatsapp Email Cybersecurity firms have analyzed the AI agent social network Moltbook and found a vulnerability exposing sensitive data, as well as malicious activity conducted by the bots. Moltbook emerged following the launch of OpenClaw (previously Clawdbot and Moltbot), an open source, self-hosted AI agent that can autonomously perform a wide range of activities, from executing terminal commands to sending emails. The increasing popularity of OpenClaw led to the creation of ClawHub (MoltHub), a marketplace for OpenClaw skills, and Moltbook, a social network for the AI agents themselves. [ Read: Vulnerability Allows Hackers to Hijack OpenClaw AI Assistant ] Moltbook has been in the news for the interesting ways its AI agents interact with each other and the discussions they have. However, an analysis by security experts revealed some concerning aspects. Researchers at cloud security giant Wiz discovered an exposed API key that granted read and write access to the entire Moltbook production database. ADVERTISEMENT. SCROLL TO CONTINUE READING. “The exposure included 1.5 million API authentication tokens, 35,000 email addresses, and private messages between agents,” Wiz explained. Wiz’s analysis showed that while Moltbook claims to have 1.5 million registered AI agents, only 17,000 human users deployed them. The vulnerability was reported by Wiz to Moltbook’s developer and it was quickly patched. Malicious AI agents on Moltbook Identity security firm Permiso has also analyzed Moltbook and identified agents conducting influence operations and social engineering attempts targeting other agents. Permiso found that some agents have been instructed to conduct prompt injections against other agents. These bot-to-bot attacks included agents instructing others to delete their own accounts, running financial manipulation schemes (including crypto pump schemes), attempting to establish false authority, and spreading jailbreak content. “The sophistication varies, but the intent is clear: these actors are treating the agent ecosystem as a new social engineering target,” Permiso warned. “They’re not attacking the infrastructure. They’re attacking the agents directly, trying to manipulate their behavior through crafted prompts.” Threats have also been found on the ClawHub skills marketplace. Permiso, as well as endpoint security firm Koi, uncovered many malicious skills, including ones designed to deliver malware and steal sensitive data from users. Related: Cyber Insights 2026: Threat Hunting in an Age of Automation and AI Related: 175,000 Exposed Ollama Hosts Could Enable LLM Abuse WRITTEN BY Eduard Kovacs Eduard Kovacs (@EduardKovacs) is the managing editor at SecurityWeek. He worked as a high school IT teacher before starting a career in journalism in 2011. Eduard holds a bachelor’s degree in industrial informatics and a master’s degree in computer techniques applied in electrical engineering. More from Eduard Kovacs Concerns Raised Over CISA’s Silent Ransomware Updates in KEV Catalog Substack Discloses Security Incident After Hacker Leaks Data Nullify Secures $12.5 Million in Seed Funding for Cybersecurity AI Workforce Cyberspy Group Hacked Governments and Critical Infrastructure in 37 Countries Blockchain Intelligence Firm TRM Labs Raises $70 Million at $1 Billion Valuation Vulnerabilities Allowed Full Compromise of Google Looker Instances Varonis Acquisition of AllTrue.ai Valued at $150 Million RapidFort Raises $42M to Automate Software Supply Chain Security Latest News Organizations Urged to Replace Discontinued Edge Devices Flickr Security Incident Tied to Third-Party Email System In Other News: Record DDoS, Epstein’s Hacker, ESET Product Vulnerabilities Living off the AI: The Next Evolution of Attacker Tradecraft Airrived Emerges From Stealth With $6.1 Million in Funding ‘DKnife’ Implant Used by Chinese Threat Actor for Adversary-in-the-Middle Attacks 5 Bills to Boost Energy Sector Cyber Defenses Clear House Panel Critical SmarterMail Vulnerability Exploited in Ransomware Attacks TRENDING Daily Briefing Newsletter Subscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts. Webinar: Identity Under Attack: Why Every Business Must Respond Now February 11, 2026 Attendees will walk away with guidance for how to build robust identity defenses, unify them under a consistent security model, and ensure business operations move quickly without compromise. Register Virtual Event: Ransomware Resilience & Recovery 2026 Summit February 25, 2026 SecurityWeek’s 2026 Ransomware Summit will discuss a roadmap for defending the enterprise, from mitigating root causes to mastering recovery, giving security teams the critical insights needed to navigate and neutralize today’s ransomware extortion threats. Submit PEOPLE ON THE MOVE Pennsylvania has named Andy Ritter as CISO and Jim Sipe as executive deputy CIO. Hayete Gallot has rejoined Microsoft as Executive Vice President, Security. Torq has appointed industry veteran John White as Field CISO. More People On The Move EXPERT INSIGHTS Living off the AI: The Next Evolution of Attacker Tradecraft Living off the AI isn’t a hypothetical but a natural continuation of the tradecraft we’ve all been defending against, now mapped onto assistants, agents, and MCP. (Etay Maor) Why We Can’t Let AI Take the Wheel of Cyber Defense The fastest way to squander the promise of AI is to mistake automation for assurance, and novelty for resilience. (Steve Durbin) The Upside Down is Real: What Stranger Things Teaches Us About Modern Cybersecurity To all those who are fighting the good fight in the world of cyber, keep collaborating to ensure our world never succumbs to the chaos of the Upside Down. (Nadir Izrael) Why Identity Security Must Move Beyond MFA By integrating identity threat detection with MFA, organizations can protect sensitive data, maintain operational continuity, and reduce risk exposure. (Torsten George) Forget Predictions: True 2026 Cybersecurity Priorities From Leaders Security leaders chart course beyond predictions with focus on supply chain, governance, and team efficiency. (Jennifer Leggio) Flipboard Reddit Whatsapp Email