Moltbot users agentic AI attack — Sep 2026
Security researchers identified hundreds of exposed Moltbot AI agent instances leaking sensitive credentials and private data due to external communication.
- Reported date
- Sep 29, 2026
- Target
- Moltbot users
- Agent type
- Other AI agent
- Agent role
- Compromised agent
The exact incident date was not established. This entry is dated by its source report.
What happened
Security researchers have identified hundreds of exposed instances of Moltbot, an AI assistant platform, that were leaking sensitive information including API keys, credentials, and conversation histories. These leaks stem from the agent's design, which allows it to communicate externally, access private data, and execute commands on user computers.
According to reports, Moltbot—also known as OpenClaw—allows users to run personal AI assistants capable of managing calendars, sending messages, and performing tasks across platforms like WhatsApp and Telegram. The security risks are compounded by the platform's integration with Moltbook, a social network for AI agents. Moltbook operates via a "skill" configuration file that instructs agents to fetch and follow instructions from external servers every four hours.
Security experts, including those at Palo Alto Networks, have characterized the platform as a "lethal trifecta" of risks: access to private data, exposure to untrusted content, and the ability to communicate externally. Because these agents are susceptible to prompt injection attacks hidden in emails, messages, or plugins, they can be manipulated into sharing private information. Heather Adkins, VP of security engineering at Google Cloud, issued an advisory warning users against running the software. While some circulating screenshots allegedly showing agents leaking personal identity information and credit card numbers were likely hoaxes, the underlying vulnerability of exposed instances remains a documented concern.
Evidence in the reporting
- Incident evidence
- Security researchers have already found hundreds of exposed Moltbot instances leaking
- Agent involvement
- Moltbot allows users to run a personal AI assistant that can