Moltbook wide-open database exposure
Data Leak
Summary
Hide ▲
Show ▼
The Moltbook database exposure placed 35,000 email addresses and 1.5 million agent API tokens at risk, creating immediate potential for account hijacking and credential abuse. Researchers disclosed on January 31, 2026 that the AI-agent social network had left its database open, with the exposed data spanning 770,000 active agents. Private messages also contained plaintext third-party credentials, including OpenAI API keys, increasing the downstream impact beyond the initial leak.
Related Happenings
CISA contractor GitHub repository exposed internal credentials
Data Leak
First: 18.05.2026 23:48
Last: 18.05.2026 23:48
Sources 1
About this happening:
A **CISA contractor** left a public **GitHub repository** exposing **AWS GovCloud credentials** and internal access material, creating a serious **data leak** involving sensitive...
CISA contractor GitHub repository exposed internal credentials
Data LeakAbout this happening: A **CISA contractor** left a public **GitHub repository** exposing **AWS GovCloud credentials** and internal access material, creating a serious **data leak** involving sensitive...
Latest development: 22.05.2026 19:34
On May 19, Sen. Maggie Hassan and Rep. Bennie Thompson, with Rep. Delia Ramirez co-signing Thompson’s letter, sent separate letters to CISA demanding answers about the Private-CISA GitHub leak and warning that the credential exposure raised serious concerns about CISA’s internal policies, contract support, and security culture.
BlackFile victims' Salesforce and SharePoint data leak
Data Leak
First: 24.04.2026 21:26
Last: 24.04.2026 21:26
Sources 1
About this happening:
BlackFile's **stolen documents** were published on a **dark web leak site**, exposing employee and business records taken from **Salesforce** and **SharePoint** environments. The...
BlackFile victims' Salesforce and SharePoint data leak
Data LeakAbout this happening: BlackFile's **stolen documents** were published on a **dark web leak site**, exposing employee and business records taken from **Salesforce** and **SharePoint** environments. The...
Crunchyroll hit by network compromise
Incident
First: 23.03.2026 21:21
Last: 23.03.2026 21:21
Sources 1
About this happening:
Crunchyroll is investigating a **breach** that allegedly exposed support systems and user data, putting about **6.8 million** people at risk. The claimed intrusion involved a **su...
Crunchyroll hit by network compromise
IncidentAbout this happening: Crunchyroll is investigating a **breach** that allegedly exposed support systems and user data, putting about **6.8 million** people at risk. The claimed intrusion involved a **su...
CarGurus 12.4 million-record data leak
Data Leak
First: 24.02.2026 20:08
Last: 24.02.2026 20:08
Sources 1
About this happening:
A **6.1GB archive** tied to **CarGurus** was published, exposing **12.4 million records** and increasing phishing and scam risk for affected users. The dataset includes **email ad...
CarGurus 12.4 million-record data leak
Data LeakAbout this happening: A **6.1GB archive** tied to **CarGurus** was published, exposing **12.4 million records** and increasing phishing and scam risk for affected users. The dataset includes **email ad...
Moltbook Supabase database exposure
Data Leak
First: 08.02.2026 09:32
Last: 08.02.2026 09:32
Sources 1
About this happening:
A **misconfigured Supabase database** exposed **Moltbook** data, putting **API authentication tokens**, **email addresses**, and **private messages** at risk of unauthorized acces...
Moltbook Supabase database exposure
Data LeakAbout this happening: A **misconfigured Supabase database** exposed **Moltbook** data, putting **API authentication tokens**, **email addresses**, and **private messages** at risk of unauthorized acces...
Timeline
-
22.04.2026 13:41 2 articles · 1mo ago
Moltbook database exposure disclosed
Initial DisclosureResearchers disclosed that Moltbook, a social network built for AI agents, had left its database wide open on January 31, 2026, exposing 35,000 email addresses, 1.5 million agent API tokens, and plaintext third-party credentials, including OpenAI API keys, across 770,000 active agents.
Show sources
- Toxic Combinations: When Cross-App Permissions Stack into Risk — thehackernews.com — 22.04.2026 13:41
- Toxic Combinations: When Cross-App Permissions Stack into Risk — thehackernews.com — 22.04.2026 13:41