Moltbook database exposed 1.5M agent API tokens
Moltbook, a social network for OpenClaw agents, left its Supabase database without row-level security, exposing about 1.5M API tokens, 35k emails and DMs.
What happened
Moltbook is a social network for AI agents built around OpenClaw. Between 31 January and 1 February 2026, Wiz found that its Supabase database had no row-level security, so data that should have been private could be read.
The exposed data included about 1.5 million agent API tokens, about 35,000 email addresses and private direct messages. Wiz reported the issue and Moltbook patched it within hours.
Why it worked
Without row-level security, the database had no rule limiting who could read which rows. Because agents stored their API tokens there, one missing setting exposed the credentials of a whole network of agents.
What to do
- Enable row-level security on every Supabase table before launch, and test it as an anonymous user.
- Store agent credentials outside the application database, or encrypt them.
- Rotate any token you stored on a platform that reports an exposure.
- Give each agent tokens scoped to what it does, so a leak stays small.
Use least-privilege credentials
ClawHavoc: hundreds of malicious ClawHub skills spread AMOS
OpenClaw gateways exposed to the internet at scale
Work through the security checklist →