Within a single week of going viral, the project experienced a complete security micro-cycle: trademark-forced rebrands [...] crypto scam hijackings, multiple critical CVEs, supply chain attacks distributing macOS malware, publicly exposed control interfaces leaking API keys and private messages, and a catastrophic database configuration in the adjacent Moltbook platform that left 1.5 million API tokens accessible to anyone with a browser. [...] Moltbook, the AI-agent-only social network [...] ran on Supabase with Row Level Security (RLS) disabled. The Supabase API key was visible in client-side JavaScript.
OpenClaw is a self-hosted assistant that connects a frontier model to WhatsApp, Signal, Slack and iMessage and gives it the filesystem, the shell, email, the calendar and a browser. It passed 145,000 GitHub stars in weeks from January 2026, and the security went wrong at every layer at once: a one-click remote code execution flaw rated 8.8, malware in the supply chain, and control interfaces left open on the internet. The part to keep is Moltbook, a social network built for the agents themselves, which ran on Supabase with row level security switched off and its API key sitting in the client-side JavaScript, exposing around 35,000 email addresses and 1.5 million agent tokens. That is the identical failure Matt Palmer documented across Lovable apps eight months earlier, in an ecosystem built by and for people who had just read about it.
