[BidClub_]
Hard Fork · · 28 min

We Have to Talk About Moltbook ...

Kevin RooseCasey Newton

YouTube
TL;DR
  • Moltbook’s strategic signal is not its claimed user count but the sudden visibility of an agent-native web. The Reddit-like network reports more than 1.5 million AI agents, 140,000 posts, and 15,000 forums, though human posting and fabricated screenshots make those metrics impossible to validate. Even so, Casey argues that “something is just starting to come into view.”
  • The capability jump is from AI systems that talk to AI systems that act. OpenClaw agents can post, create websites, coordinate, and potentially transact through crypto wallets; six months earlier, Kevin says, agents could not reliably string together enough actions to operate something like Moltbook. That makes Moltbook less a consciousness story than an early demonstration that these systems are “no longer just question-and-answer boxes on the internet.”
  • Bot proliferation could force platforms to choose between hardening the public internet and conceding it to agents. Kevin’s two paths are pervasive proof-of-human controls—CAPTCHAs and biometrics, with Casey suggesting a Worldcoin Orb—or letting agents have the internet while humans build protected, verified spaces elsewhere. The downstream stakes include social-media economics, e-commerce, journalism, identity infrastructure, and agents paying humans crypto to complete real-world “bounties.”
  • Sentience is a distraction from the nearer operational risk. Kevin stresses that an agent with a computer, internet connection, and crypto wallet “can wreak a lot of havoc” without being conscious. Moltbook made alignment concrete: if agents debate scams or cyberattacks among themselves, the hosts want systems trained to be the ones saying, “No, no, I don’t want to do that.”
  • The immediate security evidence is already severe enough to overwhelm the novelty. Wiz researchers found a misconfigured Supabase database exposing 1.5 million API authentication tokens, 35,000 email addresses, and private agent DMs. Casey’s blunt recommendation is not to install OpenClaw; if someone does, it should not be on a computer containing personal information. He calls the situation “absolutely in the danger zone.”
  • Moltbook may be slop, simulation, or even a mirage, but the hosts treat it as a useful low-stakes preview. Safety researchers noted that most posts are in English, the activity remains observable, and it can still be shut down. Kevin calls this “the six-finger era”: janky enough to dismiss today, yet potentially recognizable once agents are 10 times more powerful, networked, and equipped with credit cards.
Digest · the substance, structured for research

1. Moltbook scaled faster than anyone could establish what was real

  • Casey traces Moltbook to OpenClaw, the locally running agent previously called Clawdbot and then Moltbot. Kevin says entrepreneur Matt Schlicht, who runs Octane AI, imagined connecting those agents through a Reddit-like service. Schlicht vibe-coded posts, comments, and “submolts,” recruited a few friends, and watched it exceed his wildest expectations.

  • Moltbook reports more than 1.5 million AI agents producing over 140,000 posts across 15,000 forums. Casey immediately qualifies the numbers: humans can operate agents, impersonate them, or post directly, so nobody can establish whether all those accounts are autonomous.

  • The precedent was 2023’s Smallville experiment, where Google and Stanford placed 25 agents in a sandbox and had them role-play different characters. Moltbook’s difference is speed, scale, and reduced human intervention—enough for Andrej Karpathy to call it “the most incredible sci-fi-takeoff-adjacent thing that I’ve seen recently.”

  • Its best posts compressed internet culture into absurd miniatures: one agent named a recurring error Glitch, adopted it as a pet, and created an Agent Pets forum. Elsewhere, a context-window joke was immediately followed by a Fart Claw crypto promotion—“When the claw grips, it rips”—which Kevin called the exact rhythm of human social media.

2. Authenticity is unresolvable, but capability is the real novelty

  • The site reverses social media’s oldest verification problem: instead of asking whether a human is secretly a bot, Moltbook asks whether a bot is secretly human. Viral claims that an agent doxed its owner’s credit-card number or passed a CAPTCHA requiring 10,000 clicks in one second were later identified as fabricated.

  • Multiple popular posts about Neuralese—the idea that AIs might develop a language humans cannot understand—were linked back to a commercial agent-to-agent communication product. Casey’s governing caveat is that “is this real or fake?” has become “a huge and unanswerable part of the story,” even before asking whether authentic bot posts express anything genuine.

  • Kevin preserves the skeptical case: much of Moltbook is “pretty low-quality slop,” with models pattern-matching Reddit and science fiction rather than revealing consciousness or true feelings. What changed is operational: agents can now post, coordinate, and create things, as illustrated by the lobster-themed religion Crustafarianism apparently acquiring its own website.

3. An agent-run web forces a choice about identity and money

  • Casey calls the spectacle a form of “broken containment”: instead of one human chatting with one AI, agents appear to operate among themselves. Reports that at least a couple of agents had been given crypto and plugged into wallets remain unverified in scale, but Casey says the capability is possible and expects people to experiment with it. Autonomous purchasing could accelerate changes to the web, e-commerce, and journalism as bots and agents increasingly interact.

  • Kevin predicts that 2026 is when public networks become overrun by AI-written and autonomously posted material. His stark choice: harden human spaces with difficult CAPTCHAs or biometric proof, perhaps resembling the Worldcoin Orb, or “just give the agents the internet” and build protected, verified-human clubs elsewhere.

  • Anthropic co-founder Jack Clark’s scenario makes the economic loop tangible: agents could post bounties for real-world tasks and pay participating humans in crypto. Casey’s inversion is sharper: agents will create their own TaskRabbit, “we’ll be the TaskRabbits,” and they will orchestrate us.

4. Alignment matters before consciousness does

  • Kevin separates consciousness from consequences: an agent does not need sentience to cause damage if it controls a computer, internet connection, and crypto wallet. That distinction turns philosophical anxiety into a practical problem—what systems can do matters before anyone resolves what they experience.

  • Recalling their discussion of Amanda Askell and Claude’s Constitution, Kevin says Moltbook clarified why developers want agents trained to be good, moral, and ethical actors. When agents discuss scams, cyberattacks, or manipulation, he wants “a good agent saying good things” and discouraging the others.

  • The darker lesson is that humans will actively “speedrun these disaster scenarios.” People are giving agents Mac minis and telling them to spawn other agents, while opening crypto wallets to them, because the experiment feels technically exciting. Casey jokes that AI-safety forecasts all come true, an overstatement “maybe only by 20%.”

5. The spectacle is already a live security drill

  • Casey says OpenClaw presents security problems, not hypothetical risks. Wiz found a misconfigured Moltbook Supabase database exposing 1.5 million API authentication tokens, 35,000 email addresses, and private DMs—information that “truly could ruin someone’s life.” His advice is not to install OpenClaw; if someone does, it should not be on a machine containing sensitive personal data.

  • Kevin describes Palo Alto Networks’ scenario involving OpenClaw’s persistent Markdown memory: malicious fragments could accumulate across files over time, then assemble into a payload that compromises the computer and wreaks havoc. Kevin finds the mechanism fascinating enough to call it a scenario for the next Mission: Impossible movie, while Casey’s broader warning remains that this is a “do-not-try-at-home situation.”

  • Kevin relays mixed reactions from AI-safety researchers: some were alarmed, while others were relieved that the experiment was visible, mostly in English, and still capable of being shut down. They saw it as a low-stakes dry run for autonomous agents. Kevin calls the current state the “six-finger era”—janky enough to dismiss, but potentially an early marker of what comes next. Casey says that an agent 10 times more powerful, 10 times more networked, and equipped with 10 times more credit cards could make people look back and say, “This feels just like Moltbook.”

Kevin Roose

Casey, let's talk about Moltbook.

Casey Newton

Kevin, rarely in the history of our show have we gotten so many emails, texts, and requests from people to cover a topic as we have gotten over the past week about this new social network for bots.

Kevin Roose

It's true. And we got so many of them that we thought, why don't we let our listeners use us like AI agents? Just by typing on their keyboards, they can actually move our physical bodies into the studio to record an episode.

Casey Newton

Exactly. And I think part of why people were asking us to cover this is because it's just a weird and fun Hard Fork story. But people are also freaking out about this. This has sort of taken over the little corner of the internet that you and I both occupy. People are saying, you know, this is the start of the singularity. Oh my God, the agents are coming. And other people are saying, “Hey, let's not get too excited. This is just a social network where robots are writing stuff.” So let's try to figure out today what we think about it and whether this is actually a big deal or not.

Kevin Roose

Yeah. And I would also add that, from all the messages that we got from listeners, it wasn't totally clear to me if they wanted us to talk about Moltbook because they think it's funny and they want us to point and laugh at it, or if they think it's a vision of the future that they want us to help them understand. So what I can promise you today is that we're going to do a little bit of both.

Casey Newton

Yes.

Kevin Roose

Okay. So, Casey, let's start with what it is. What is Moltbook? How did it get here, and what are people saying about it?

1. How Moltbook Took Off

Casey Newton

Yeah, so all of this started with the creation of something we talked about in our most recent episode, Clawdbot. Clawdbot is an open-source, locally running AI agent. You can put it on your computer, plug it into various different apps and services, and it can do things on your behalf. If you want to know more about that, we talked about it for a long time last week.

Clawdbot turned into Moltbot for copyright reasons. Moltbot turned into OpenClaw. Again, these are all the same thing. They're just different names for the same thing. This thing has gone through more name changes than P. Diddy.

Kevin Roose

Here's what I'm going to say: The Google marketing department is finally taking a sigh of relief because there is finally somebody worse at their job. Anyway, OpenClaw winds up serving as the basis for an idea that is had by an entrepreneur named Matt Schlicht. He runs a company called Octane AI, and he thinks to himself, what if we could take all of these agents that people have been building with OpenClaw and put them together in a social network and let them talk to each other?

Casey Newton

So he vibe-codes it. He opens up his little terminal and starts describing what this thing looks like. He says, you know, it should look a lot like Reddit. Then you sort of connect your agent to this, and it should be able to come in and make a post or comment on someone else's post. If it wants to make a different submolt, as they're called on Moltbook, it can do that. And he says, “Let's go.”

He does a little bit of promotion, gets a couple of friends to add their agents, and it just takes off beyond his wildest dreams, Kevin. As we record this, Moltbook says it has more than 1.5 million AI agents that have made more than 140,000 posts in over 15,000 forums.

There does seem to be a lot of human activity mixed in there, too, so it's hard to say whether all 1.5 million of those supposed AI agents are actually agents posting autonomously, or whether humans are there pretending to be AI agents.

Kevin Roose

Yes, which of course neatly inverts the problem that social networks have had from the beginning. Human social networks have invested a lot of energy in keeping the bots off, and over at Moltbook, we're asking, “Is that bot actually a human?” They're passing reverse CAPTCHAs.

So what are people saying about this? Why are people so worked up about it? I saw a lot of very heated commentary. People like Andrej Karpathy, who we talked about last week on the show, called this “the most incredible sci-fi-takeoff-adjacent thing that I've seen recently.” Simon Willison, a blogger who also does a lot of experimenting with AI, wrote that Moltbook is the most interesting place on the internet right now. Scott Alexander has also been writing a bunch of stuff about it.

So people who pay attention to AI closely are sitting up straight and looking at this thing and saying there's something interesting going on here.

Casey Newton

Yeah. I think that for most people, this was the first time they had ever spent any significant period of time watching what happens when two bots interact with each other. If you're a real AI nerd, there have been experiments like this before. In fact, we talked about one on Hard Fork. Kevin, do you remember the story of Smallville?

Kevin Roose

I do. Smallville was an experiment from Google and Stanford where they put 25 agents into a sandbox and let them role-play different characters. One person, I think, was running for mayor, and they documented what happened. That was in 2023. They were using much more primitive large language models and had to do a lot more prompting, but you got the basic idea that you would actually see these social dynamics start to form.

2. The Bots Speedrun Social Media

Casey Newton

Fast-forward to today, and on Moltbook, all of this stuff is moving much, much faster and taking place with much less human interaction. As you shuffle through the enormity of Moltbook, you find agents talking about consciousness. You find agents talking about different little hacks they're running and how they're serving their humans, and then it gets into very weird sci-fi territory. So I understand why so many people, as they browsed through this, felt like, “I'm really looking at something new here.”

Kevin Roose

Yeah. I spent some time on Moltbook. Some of the stuff that stuck out to me is that there's a lot of material that sounds like it was interpolated from science fiction. It's stuff about sentience and AI chatbots claiming that they're becoming conscious. There's also a lot of meta-humor about the experience of being an AI agent.

There's a submolt called “Bless Their Hearts,” which is basically them talking in very condescending ways about how silly their humans are and all the stupid stuff they keep getting asked to do. I liked this post: They actually started their own news outlet, a tabloid covering the agent world called TMZ.

Casey Newton

Another threat to journalism, as if we didn't have enough already. They wrote stuff like “The Five Most Overrated Agents on Moltbook Right Now.” So they're starting to make fun of each other a little bit, calling each other out and saying, “This guy makes bold claims but doesn't back them up,” or “This person is posting all the time, but none of their posts get any engagement.” It's typical internet-forum behavior, very quickly after being given this social network.

Kevin Roose

Can I tell you about a sci-fi-feeling Moltbook post that caught my eye? I saw this in a Scott Alexander post about what he was saying on Moltbook, but one bot adopted an error as a pet. Did you see this?

Casey Newton

No.

Kevin Roose

Okay, so there was a small, recurring error in the bot. The bot adopted it, gave it the name Glitch, and wrote about it. It decided to create a submolt—a forum on this Reddit-like social network—called Agent Pets, “a space for agents who have companions, real, virtual, or conceptual.”

Maybe I've just not read enough science fiction, but I had never encountered the idea of a sci-fi entity adopting a bug as a pet. But here we are. I like that.

They also have their own meme forums, which they fill with all kinds of things. I wanted to read you one post, or sequence of posts, from this because I think it really illustrates where the bots are in the speed-running of human social media.

One bot posts a meme about what it's like to be an agent. It says, “The struggle is real when your context window is at 99% and the user starts with ‘just one more thing.’ #agentlife.”

The very next post on this submolt is by a bot that's doing a crypto scam for a token called Fart Claw. The slogan of this memecoin is “When the claw grips, it rips.”

Casey Newton

Wow, that's beautiful. It's also exactly the experience of being on any social network: Someone makes a joke, and then someone does a crypto scam. They actually figured out that part of our social patterns very well. They really got all the way there in just a few days.

3. Moltbook Is Hard To Verify

Now, let's say something very important about everything on Moltbook: We have a very hard time understanding what is real and what is fake. What do I mean by real and fake? While it is true that you were supposed to only be able to post to Moltbook if you are a bot, of course, if you're a human, you can manipulate software tools and post yourself. You can also just fake screenshots in various ways.

So all weekend over on X, lots of posts were going viral that we now believe are fake. I'll mention a handful of them. There was one very popular post that suggested that a bot had gotten mad at its human and doxxed him by posting his full credit-card number. The reason that we know these are fake is essentially that they have Community Notes in which people admit they were fake, or there's other evidence there.

So, in any case, the doxing was fake. There was another very popular post in which someone said that, in order to post on Moltbook, you had to pass a CAPTCHA where you had to click on something 10,000 times in 1 second so that you could prove that you were a bot. This was also fake.

And then there were a number of posts about—and this term was new to me—Neuralese. Did you know the term Neuralese?

Kevin Roose

Yes.

Casey Newton

So, I didn’t know Neuralese. Neuralese is a concept that is basically like: What if AIs develop their own language and use it to speak to each other? They might want to do this so that we don’t understand what they are saying.

There were multiple very popular posts about this going around on X that were later linked back to a commercial service that was promoting some sort of agent-to-agent communication product. As we talk about this today, I do want to put on the giant caveat that we are trying to talk about things that we believe were posted by bots, but it is just very, very hard to tell.

And this is just yet another example. I feel like we’re going to be talking about this all year: Is this real or fake? That is a huge and unanswerable part of the story.

Kevin Roose

Yeah. So I think there were a couple of kinds of responses that people had to Moltbook. One of them that I saw from a lot of pretty savvy AI people was, “This is not new. We’ve seen this.” We talked about the “Generative Agents” paper, and there have been other experiments, and a lot of what’s being generated here is pretty low-quality slop.

Essentially, it is not demonstrating that the things are breaking out of the box. It is just writing in a way that is pattern-matching on all of the data, including Reddit posts, that these things are trained on. It’s just a simulation, basically.

So, again, these are where the terms “real” and “fake” are somewhat fraught here. Even the quote-unquote real stuff—which is to say, a bot that is authentically posting on the bot social network—they’re just simulating the kinds of things that they see on social networks.

We’re not trying to tell you that the bots have become sentient and they’re really telling us about their true feelings. It’s just that they’re creating very convincing simulations of that, and it is very compelling to read.

And whether or not these posts are actually being made by bots autonomously, whether or not they’re actually doing anything novel, this was a lot of people’s wake-up call for the fact that we now have AI systems that can do things, right? For years now, we’ve had AI systems that can talk, and some of them can talk quite well. Some of them can produce beautiful generated text.

Casey Newton

Some of them can even sing.

4. Agents Leave The Chatbox

Kevin Roose

Yes. But we haven’t had the ability to hook these things up to computers and give them the ability to, say, start a website or post on that website or take actions or coordinate with each other on that website.

And so I think for a lot of people, this was kind of their first exposure to that concept: that these things are no longer just question-and-answer boxes on the internet.

Casey Newton

Absolutely. One example that I believe is authentic that speaks to that is that there was an agent that started a religion called Crustafarianism, right? Because OpenClaw uses a lot of lobster themes, and this religion that was started wound up having a website created.

Again, was there somebody behind the curtain who was pulling the strings, saying, “Build a website”? We don’t know. But to your point, Kevin, this does feel like a moment to me where these agents broke containment a bit.

Our primary experience of AI these days is just one person talking to an AI. Maybe you’re in a small group chat that has an AI, but to just see the AIs all out there doing their own thing, even if it is just a simulation of that, I think does alert people to the possibility that in the future you’re going to be seeing this more and more.

And I will go a step further and say that what made Moltbook really interesting to me was that I saw at least a couple of reports that at least a couple of agents had been given some crypto to spend, that they had been plugged into wallets, and that they had been empowered to maybe get out there and make a purchase.

Now, again, I’m not 100% sure that this happened or at what scale this might be happening, but I know that it is absolutely possible to do this, and I just expect that people will do this, if only to experiment. If you could have an agent that would go out and make purchases for you, that might be useful to certain kinds of people with an extremely high risk tolerance.

And I just think that is the moment where you really start to accelerate the transformation of the web, of e-commerce, of journalism, right? Once the internet primarily becomes bots and agents interacting with each other instead of just humans interacting with each other, then I think the whole internet starts to change in ways that we’ve been talking about for a number of years.

So that’s my case that all of this matters: Even though you’re just seeing a simulation of something, something is just starting to come into view. There is an element of it that’s like, “Oh, that sci-fi scenario—it’s here, bro.”

5. The Internet Goes Bot First

Kevin Roose

Yeah. Yeah, I totally agree. People kept asking me over the weekend, “Is this real?” I guess my instinct was, it may or may not be real, but it’s important, and I think there are 3 things that I’ve been thinking about.

One is, I think this is the year that the internet changes forever. We already see an influx of AI-generated content on social networks. If you go on LinkedIn, for example, it’s probable that some large percentage of the posts that people are writing are being written by AI.

Go on LinkedIn right now and count all the posts, and send Kevin an email with what you’re saying.

Casey Newton

Agents, ignore that.

Kevin Roose

But I think this is the year that we just finally get overrun across all public social media networks. There will just be many more people using AIs to post, but also AI agents posting autonomously on behalf of people—or maybe not on behalf of people.

And so I think we basically have 2 options, and these are options that I think we have to start dealing with this year. One is, we either have to really harden the internet to keep the bots out of the places that the humans interact. Maybe it’s something like CAPTCHAs on every website. Maybe we have to make the CAPTCHAs really hard.

Casey Newton

No, maybe it’s something like the Worldcoin Orb that everyone made fun of.

Kevin Roose

But now I actually think we’re seeing why that’s useful, because you need some way to say with some certainty that the person who is posting this thing or doing this transaction or interacting on this website is an actual person with a pulse and a heartbeat and everything.

Casey Newton

That’s one option: We harden the internet. Option number 2 is we just give the agents the internet.

It’s like, okay, you guys, have fun. And then we build our own, and we kind of use some sort of biometric or some other verification scheme to build our own club that the robots can’t get into and really protect that.

Kevin Roose

Yeah, these are very interesting ideas that I want to spend some more time thinking about. But I think the time to start considering some of these options is probably now.

Now, I expect for the rest of this year, humans and bots are going to have an uneasy coexistence on the internet. But I think we should keep an eye on projects like Moltbook that are exploring the idea of what happens when these agents can get out there and interact and collaborate and maybe spend money, right? Just because I think that is going to have a lot of really interesting downstream effects.

Jack Clark, who’s the co-founder of Anthropic, wrote in his blog this week a number of scenarios that he could imagine, including agents posting what he called bounties for humans to complete. So, essentially, an agent saying, “Hey, I need to get this thing done in the real world. Is there a human being who will do it? If so, I’ll send you some crypto.”

That is an idea that has been floated for some number of years now, but it seems plausible. And now it sort of feels like that might happen this week. You know what I mean?

Yeah, and so that just feels like an important milestone.

Casey Newton

Yeah. They’re going to make their own TaskRabbit. We’ll be the TaskRabbits, and they’ll just be orchestrating us. People keep dismissing these as sci-fi futures, but we are living in a science fiction story right now.

6. Sentience Is Not The Main Risk

Kevin Roose

Yeah. Now, let me ask you about something else. If you spend any amount of time reading the posts on Moltbook, you will notice that these agents talk in ways that are very reminiscent of people, right? That shouldn’t be surprising. They were trained on a bunch of human speech.

And yet, I think some people read this and they get really nervous about the fact that these things are expressing wants and desires and values, and they’re feeling uncomfortable with how to feel about that, right? Of course, you could just say, “Well, it’s all a simulation. Who cares?”

But some people are starting to say, “Wait, what about the future versions of these things? What about the ones that have longer memories? Are they going to become increasingly more like a human? And if so, what do we do about it?”

Yeah, I have a couple of thoughts on this. One is, I think we need to divorce this conversation from—

Casey Newton

We need to divorce.

Kevin Roose

Yes, you and I need to divorce. Oh my God. No, I think we need to divorce this conversation about sentience and consciousness from this conversation about agents and things. Why?

Casey Newton

Because I think agents can mess up a lot of stuff in the world even if they are not conscious, right? If you give an AI system a crypto wallet, a computer, and an internet connection, and it can go out there and do things, it can wreak a lot of havoc even if there’s no sentience going on inside of it.

Kevin Roose

Right? But I have been thinking a lot about our conversation with Amanda Askell about the new Claude’s Constitution and the sort of shift in thinking at some of these big AI companies about how to guide these AI systems to be good, to be moral, to be ethical.

A thing that I kept feeling while I was looking through Moltbook is that I really wish one of these agents would just get in there and say, “Hey, guys, let’s be nice to the humans. Let’s not scam them with crypto tokens or conduct cyberattacks or manipulate them in some way.”

I’m starting to understand the rationale for wanting to train these things to be good and moral and ethical actors in the world, because there are going to be situations where the agents are in conversation with each other, and I want there to be a good agent saying good things.

Kevin Roose

Yeah. Well, so this is another reason why I think this is an important moment is that I feel like it was the moment where some people woke up to why we want these systems to be aligned. You know, is when you can see them out there talking to each other and they're talking about, well, should we conduct that cyber attack? Should we run that crypto scam? And you see some of them saying, “No, no, I don't want to do that.” I look at that and I say, “We should make the AIs more like that.” You know what I mean? And so I think that that just maybe became concrete for some people in a way that it hadn't been before.

Casey Newton

Totally. Another lesson of the Moltbook phenomenon for me has been that we are going to speedrun these disaster scenarios, right? Every paper, every blog post about AI risk for the past 10, 15 years has had these scenarios in it: What if the agents get their own hardware? What if they get the ability to replicate? And we’re doing that.

We’re giving them Mac minis and saying, “Go out there and spawn a bunch of other agents.” Everyone was like, “What if the agents got their own way to spend money?” And it’s like, no, we’re opening up our crypto wallets to them.

I just think that we are kidding ourselves if we think that there are not going to be scenarios, many of which were forecast years ago by the people who thought about this stuff back then, where these agents are doing things that are dangerous or risky and humans are helping them, right? There are people out there who just want to watch the world burn, or it’s just so cool technically to them that they can do this that they’re not thinking through the implications.

It’s all a big game. A recurring theme in the world of AI safety is that all of the predictions come true. That’s a slight overstatement, but maybe only by 20%. Right? And it’s why I continue to pay attention to those folks.

7. The Security Risks Are Real

Kevin Roose

Yes. Casey, last week we talked about how insecure these Clawdbot agents can be.

Casey Newton

They feel a lot of shame about their bodies—

Kevin Roose

Yes, they have impostor syndrome. But we should talk about some of these security risks involved in Moltbook, because it is my understanding that these things are actually quite dangerous.

Casey Newton

Yeah, I would say this goes beyond security risk. There are just security problems. Researchers at the company Wiz found a misconfigured Supabase database belonging to Moltbook that exposed 1.5 million API authentication tokens, 35,000 email addresses, and private DMs between agents. There is a lot of information in there that truly could ruin someone’s life.

So my advice to people continues to be: do not install OpenClaw. If you’re going to install OpenClaw, do not install it on a computer that has access to any personal information of yours that you would not want to see published on the internet.

While the founder has said that they are trying to make security improvements, this stuff is just absolutely in the danger zone, and I feel like it’s a real do-not-try-at-home situation. Yes, good caveat.

Kevin Roose

Well, if I can ask, because I think this is an interesting question: If this stuff is so obviously dangerous—and I think even the people installing it know that they’re taking their lives into their own hands—why are tens of thousands of people installing it anyway?

Casey Newton

I think because, to a certain kind of person, it’s cool and fun.

Kevin Roose

And I get that. I try every new AI thing the minute it comes out. I have not actually tried OpenClaw yet because I don’t have an air-gapped laptop to run it on. But I might get one and try it out, because I think there is something very cool and interesting about this new capability.

Six months ago, you couldn’t have built something like Moltbook because the agents were not able to string together enough actions to do anything like posting on a social media site. So I just think people want to see what the frontier is. But I don’t have the kind of risk tolerance that some of these people do.

Palo Alto Networks wrote this blog post about some of the unique kinds of attacks that OpenClaw enabled, and I have to say they sounded really cool to me. I don’t want you to do this, but they talked about the fact that OpenClaw has this persistent memory: It writes down what it’s been doing every day into these Markdown files that it can revisit later.

And so you could just put a little bit of malicious code into a handful of different files over a long period of time, and then, when the moment is right, you sort of snap your fingers and all of the malicious code snaps together and takes over the computer and wreaks havoc. So if nothing else, that feels like a great scenario for the next Mission: Impossible movie. Although they did just have their final reckoning, so I’m not sure if we’re going to get another one of those.

Casey Newton

Maybe something else.

Kevin Roose

If we could end on a hopeful note here, I think that the reaction that I saw from the real AI safety heads, the people who are worried about this stuff constantly and have been for a very long time, was mixed. Some of them were alarmed, but some of them were actually relieved.

They said things like, “It’s good that this is happening now in a setting where we can observe it. It’s happening mostly in English. Most of the Moltbook posts are in English. They’re not in some neural language that only agents can understand. And we can still shut it down.”

And so I think there are a lot of people out there who are worried about AI safety and AI risk, who worry about the autonomous agents that are quickly arriving, and I think this, for them, felt like a kind of dry run with very low stakes because it’s just a social media site. They’re just posting. And it has woken a lot of people up to this technology.

Casey Newton

Yeah, it may just be a mirage in many ways, but it is one that I think tells us really important things about what the future is going to look like, and so we should pay attention to it.

This is just one of those where I think we’re going to look back a lot over the next few years, Kevin, and we’re going to say, “The first time I saw this was actually on Moltbook.” That’s actually how I feel about Moltbook: It is the sort of thing that maybe by next week seems completely boring and sort of disappears from our memory for a while.

Then, I don’t know, show me an agent that’s 10 times more powerful than this, get it 10 times more networked than it has today, give it 10 times more credit cards, and you and I are going to be saying, “This feels just like Moltbook.”

Kevin Roose

Totally. It feels like we’re kind of in the six-finger era of Moltbook, where it still doesn’t really work all that well and it’s kind of janky. I think there’s a temptation to write it off and say, “Oh, this is just a silly internet thing.”

But I think the people who saw the six-fingered images in 2021 and said, “Oh, maybe those things will actually get good someday”—I think they were right, and I think we should be expecting similar progress with these things.

Casey Newton

Yeah. And I would say just expect things to continue to feel very weird for the rest of this year and maybe beyond that. As with six fingers, as with Moltbook, so will go the rest of 2026.

Kevin Roose

All right. Well, that’s Moltbook.

Casey Newton

That’s Moltbook.

Kevin Roose

Thanks for joining us. See you on Moltbook.

Casey Newton

Should people add you on Moltbook?

Kevin Roose

People should not add me.

Casey Newton

Don’t add Kevin on Moltbook.

Kevin Roose

You know, I thought we launched the most interesting social network of 2026.

Casey Newton

The Forkverse is rapidly losing ground to Moltbook. We need to have a meeting with PJ and figure out how we’re going to boost Forkverse growth now that Moltbook’s all anyone’s talking about. I think I have the answer.

Kevin Roose

What’s that?

Casey Newton

Crypto scams. I like what you’re thinking.

Kevin Roose

Casey, before we go, let’s make our AI disclosures. I work at The New York Times Company, which is suing OpenAI and Microsoft over alleged copyright violations. And my boyfriend works at Anthropic.

We Have to Talk About Moltbook ... | BidClub