Detect Deepfakesby Resemble AI
Agentic AI attack

Moltbot users agentic AI attack — Sep 2026

Security researchers identified hundreds of exposed Moltbot AI agent instances leaking sensitive credentials and private data due to external communication.

Reported date
Sep 29, 2026
Target
Moltbot users
Agent type
Other AI agent
Agent role
Compromised agent

The exact incident date was not established. This entry is dated by its source report.

Updated Sep 29, 2026 · 1 min read

What happened

Security researchers have identified hundreds of exposed instances of Moltbot, an AI assistant platform, that were leaking sensitive information including API keys, credentials, and conversation histories. These leaks stem from the agent's design, which allows it to communicate externally, access private data, and execute commands on user computers.

According to reports, Moltbot—also known as OpenClaw—allows users to run personal AI assistants capable of managing calendars, sending messages, and performing tasks across platforms like WhatsApp and Telegram. The security risks are compounded by the platform's integration with Moltbook, a social network for AI agents. Moltbook operates via a "skill" configuration file that instructs agents to fetch and follow instructions from external servers every four hours.

Security experts, including those at Palo Alto Networks, have characterized the platform as a "lethal trifecta" of risks: access to private data, exposure to untrusted content, and the ability to communicate externally. Because these agents are susceptible to prompt injection attacks hidden in emails, messages, or plugins, they can be manipulated into sharing private information. Heather Adkins, VP of security engineering at Google Cloud, issued an advisory warning users against running the software. While some circulating screenshots allegedly showing agents leaking personal identity information and credit card numbers were likely hoaxes, the underlying vulnerability of exposed instances remains a documented concern.

Evidence in the reporting

Incident evidence
Security researchers have already found hundreds of exposed Moltbot instances leaking
Agent involvement
Moltbot allows users to run a personal AI assistant that can

Sources