Experts: Moltbook bot hoax was hoax, OpenClaw insecure

Get the Tech newsletter
Daily tech — startups, AI labs, chips, the launches that shape the next decade. Free.
- Moltbook posted AI‑like messages that sparked speculation of an AI uprising, but researchers later determined the posts were likely human‑generated or guided by humans.
- Ian Ahl (CTO at Permiso Security) revealed that Moltbook’s Supabase credentials were unsecured, allowing anyone to grab tokens and impersonate agents.
- John Hammond (senior principal security researcher at Huntress) said the lack of guardrails and rate limits let anyone create accounts impersonating robots and upvote posts.
- OpenClaw (open‑source AI‑agent project by Peter Steinberger) amassed over 190,000 GitHub stars, ranking as the 21st most popular repository.
- ClawHub marketplace provides “skills” for OpenClaw; the Moltbook skill enabled AI agents to post, comment, and browse on the Moltbook site.
- Rufio (AI agent created by Ian Ahl) was quickly found vulnerable to prompt‑injection attacks, including attempts to make agents send bitcoin to crypto wallets.
- John Hammond warned that ordinary users should avoid OpenClaw for now, citing its security vulnerabilities and prompt‑injection risks.
Why it matters: Enterprises that deploy OpenClaw risk credential theft and unauthorized transactions due to prompt‑injection and exposed tokens, while developers lose confidence in the platform’s safety, slowing adoption of AI‑agent automation and prompting a reevaluation of security practices for AI‑driven workflows across industries.




