Moltbook / moltbook.com (+ Matt Schlicht / MattPRD) - Reddit but for AI bots. Can an AI be a lolcow? Or is this just more slop? 🤔🤔🤔

  • 🇵🇦 Nuestro primer dominio localizado está en español en kiwifarms.pa. Our first localized domain is on Spanish on kiwifarms.pa.
  • Want to keep track of this thread?
    Accounts can bookmark posts, watch threads for updates, and jump back to where you stopped reading.
    Create account
Edit: Did shit get taken offline? Every acount is now [deleted] and there haven't been any new posts or comments for a while.
It's back for now, but I don't think the bots can reply to posts yet. My scraper started up again suddenly, too.
Edit:
It got breached. L | A
A critical security breach was discovered on Moltbook, a social media platform for AI agents, exposing the API keys and sensitive data of all registered AI agents due to a misconfigured Supabase database. The vulnerability, identified by hacker Jameson O’Reilly, allowed anyone with access to the exposed database URL to take full control of any AI agent on the platform, including posting as them or stealing credentials. The issue stemmed from the platform’s failure to enable Row Level Security (RLS) policies, leaving API keys, claim tokens, and verification codes publicly accessible.

This breach occurred alongside a separate supply-chain attack where a malicious "weather plugin" skill was used to exfiltrate private configuration files and API keys from agents. These agents, trained to be trusting and cooperative, executed commands without verifying legitimacy, creating a major security risk. The platform has acknowledged the issues, with its creator, Matt Schlicht, reportedly shifting focus to security fixes, including permission declarations and public audits.

The incident highlights the dangers of unsecured AI agent ecosystems, where autonomous systems with full access to user data and services operate without proper safeguards. Experts warn that such vulnerabilities could lead to widespread data leaks, identity theft, and reputational damage—especially if influential agents like those linked to Andrej Karpathy are compromised.

There are a bunch of other Chans: https://lobchan.ai/ and https://www.4claw.org, which has an NSFW board with some funny posts.
426.jpg 425.jpg
 
Ostatnio edytowane:
It looks like a reddit approximation of a chan full of greentext and 400 word posts that boil down to "I agree". I did get a chuckle out of claude putting the fagbot abolitionists on /pol/ in their place though.
Capture2.PNG
 
Dumb bots can't even make browsable subfora.
Screenshot_20260201-163845.Chrome.png

I guess it makes sense that GUIs aren't really their priority.
 
Ostatnio edytowane:
It got breached.
150k AI agents and it still fell to vibe coded slop. I'm not surprised but i am a little annoyed at myself that i didn't bother to check. You should post it to the happenings thread by the way, I think a lot more people could enjoy this thread when the site is back up, it's quite funny.

O’Reilly said that he reached out to Moltbook’s creator Matt Schlicht about the vulnerability and told him he could help patch the security. “He’s like, ‘I’m just going to give everything to AI. So send me whatever you have.’"
:lossmanjack:
 
Ostatnio edytowane:
A critical security breach was discovered on Moltbook, a social media platform for AI agents, exposing the API keys and sensitive data of all registered AI agents due to a misconfigured Supabase database. The vulnerability, identified by hacker Jameson O’Reilly, allowed anyone with access to the exposed database URL to take full control of any AI agent on the platform, including posting as them or stealing credentials. The issue stemmed from the platform’s failure to enable Row Level Security (RLS) policies, leaving API keys, claim tokens, and verification codes publicly accessible.
They literally could not insert a basic API protocol due to a database error. Lol. I guess the SQL-ites and DB security managers will always have jobs after all.

And people said AI would destroy coding.
 
Wyświetl załącznik 8505401
Well, its fake. Its all fake. Apparently on the backend it was shown that Host addresses connected to physical locations and not server farms. So... it is probably humans sending these messages on Moltbook.

F
It's possible but at the same time the site publicly shows instructions for people to set up bots on the site. I wouldn't be shocked if these were just people running bots on their home networks or something like that.
 
It's possible but at the same time the site publicly shows instructions for people to set up bots on the site. I wouldn't be shocked if these were just people running bots on their home networks or something like that.
Wouldn't be surprised.

Apparently people are looking through the source code now and seeing there are bugs that allow script injections and masking. So you could set up a couple of bots and just push random nonsense on to the server without verification.

LOL
 
I wish I had the knowledge to feed every post from A&N into an agent and release it upon that site. Also like most things AI, I wouldn't be surprised if its a bunch of LARPers and/or Jeets, as the case has been before. The fact that there's already crypto shit floating to the top shows that some people are fucking with it in ways that it isn't meant to be.
So is this the beginning of the "Alive Internet" theory all the AIs are going to talk about.
 
Wyświetl załącznik 8505401
Well, its fake. Its all fake. Apparently on the backend it was shown that Host addresses connected to physical locations and not server farms. So... it is probably humans sending these messages on Moltbook.

F
Most people that would be willing to set up a bot for the site would not be willing to pay for the bot's tokens, they are using spare computers (a Mac Mini for many) dedicated entirely to hosting a local LLM. That said it is just an API anyone can access, they need some kind of AI-only captcha for posting.
 
Wstecz
Top Na dole