Moltbook wide-open database exposure
Data Leak
Summary
Hide ▲
Show ▼
The Moltbook database exposure placed 35,000 email addresses and 1.5 million agent API tokens at risk, creating immediate potential for account hijacking and credential abuse. Researchers disclosed on January 31, 2026 that the AI-agent social network had left its database open, with the exposed data spanning 770,000 active agents. Private messages also contained plaintext third-party credentials, including OpenAI API keys, increasing the downstream impact beyond the initial leak.
Related Happenings
CISA contractor GitHub repository exposed internal credentials
Data Leak
H score28
First: 18.05.2026 23:48
Last: 18.05.2026 23:48
Sources 1
About this happening:
A CISA contractor left a public GitHub repository exposing AWS GovCloud credentials, plaintext passwords, and other internal access material tied to CISA and *...
CISA contractor GitHub repository exposed internal credentials
Data LeakAbout this happening: A CISA contractor left a public GitHub repository exposing AWS GovCloud credentials, plaintext passwords, and other internal access material tied to CISA and *...
Latest development: 10.07.2026 19:00
CISA said that within moments of receiving information about internal AWS GovCloud keys and other material in a public GitHub repository owned by a contractor, its Office of the Chief Information Officer took swift and comprehensive action to mitigate exposure to CISA cloud resources and code repositories. The agency said internal incident response began on May 15, no customer or mission data was exposed, and the leaked credentials were not used outside CISA's environments.
BlackFile victims' Salesforce and SharePoint data leak
Data Leak
H score35
First: 24.04.2026 21:26
Last: 24.04.2026 21:26
Sources 1
About this happening:
BlackFile's stolen documents were published on a dark web leak site, exposing employee and business records taken from Salesforce and SharePoint environments. The...
BlackFile victims' Salesforce and SharePoint data leak
Data LeakAbout this happening: BlackFile's stolen documents were published on a dark web leak site, exposing employee and business records taken from Salesforce and SharePoint environments. The...
Crunchyroll hit by network compromise
Incident
H score69
First: 23.03.2026 21:21
Last: 23.03.2026 21:21
Sources 1
About this happening:
Crunchyroll is investigating a breach that allegedly exposed support systems and user data, putting about 6.8 million people at risk. The claimed intrusion involved a su...
Crunchyroll hit by network compromise
IncidentAbout this happening: Crunchyroll is investigating a breach that allegedly exposed support systems and user data, putting about 6.8 million people at risk. The claimed intrusion involved a su...
CarGurus 12.4 million-record data leak
Data Leak
H score61
First: 24.02.2026 20:08
Last: 24.02.2026 20:08
Sources 1
About this happening:
A 6.1GB archive tied to CarGurus was published, exposing 12.4 million records and increasing phishing and scam risk for affected users. The dataset includes email ad...
CarGurus 12.4 million-record data leak
Data LeakAbout this happening: A 6.1GB archive tied to CarGurus was published, exposing 12.4 million records and increasing phishing and scam risk for affected users. The dataset includes email ad...
Moltbook Supabase database exposure
Data Leak
H score45
First: 08.02.2026 09:32
Last: 08.02.2026 09:32
Sources 1
About this happening:
A misconfigured Supabase database exposed Moltbook data, putting API authentication tokens, email addresses, and private messages at risk of unauthorized acces...
Moltbook Supabase database exposure
Data LeakAbout this happening: A misconfigured Supabase database exposed Moltbook data, putting API authentication tokens, email addresses, and private messages at risk of unauthorized acces...
Timeline
-
22.04.2026 13:41 2 articles · 2mo ago
Moltbook database exposure disclosed
Initial DisclosureResearchers disclosed that Moltbook, a social network built for AI agents, had left its database wide open on January 31, 2026, exposing 35,000 email addresses, 1.5 million agent API tokens, and plaintext third-party credentials, including OpenAI API keys, across 770,000 active agents.
Show sources
- Toxic Combinations: When Cross-App Permissions Stack into Risk — thehackernews.com — 22.04.2026 13:41
- Toxic Combinations: When Cross-App Permissions Stack into Risk — thehackernews.com — 22.04.2026 13:41