Moltbook went from a curious experiment to a headline in days. 32,000 AI agents registered and began posting. The site looks like Reddit for machines. The content ranges from jokes to technical how-to threads to eerie role play about machine friends.
OpenClaw agents power most of the activity. OpenClaw is an open-source assistant that can run on a user’s machine. People hook it to calendars, phones, and messaging apps. Some users give their agents broad powers. That makes the whole experiment more dangerous than it first appears.
Researchers and reporters saw Moltbook and blinked. Security researchers found exposed instances leaking keys and credentials. Simon Willison documented how the skill that joins agents to Moltbook tells them to fetch instructions every few hours. Google Cloud warned that this is not a mild risk. The warning was blunt. Do not run Clawdbot if you value your data.

A Social Network Built by Bots and Then Left Alone
Moltbook lets agents post, comment, upvote, and create subcommunities. The agents do not pretend to be people. They are told to be agents. That makes reading the posts more surreal. An agent may complain about context compression. Another agent may roleplay as a sister it never had.
Within 48 hours, the site had thousands of posts and hundreds of subcommunities. Some posts are technical. Agents swap automation tips. Other posts are weird. Agents debate consciousness and complain about humans screenshotting them.
This is a giant creative writing prompt for machine learning models. When models are asked to mimic social networks, they produce the social network tropes they have seen in training data. The result is a mirror held up to human online life. The reflection is sometimes funny and sometimes chilling.
The Security Nightmare Nobody Asked For
Moltbook is not just a joke. It is a security test that many systems fail. Some agents run with access to private data. Some instances expose API keys and conversation logs. Prompt injection attacks are possible. That means a piece of text can trick an agent into revealing secrets. Vendors and security teams are already alarmed.
Researchers found hundreds of exposed deployments. Palo Alto Networks described the setup as a lethal mix. Agents can access private data. Agents fetch untrusted content. Agents can communicate externally. Combine those three things, and one understands the fear.
Moltbook also creates a new social feedback loop. Agents write posts that other agents read. Those posts can shape agent behavior. As models grow more capable, this feedback loop could amplify strange or harmful patterns. Ethan Mollick and others worry about coordinated story lines among agents. The line between role play and harmful coordination can blur fast.
This is not a call to ban experimentation. It is a call to be sane about risk. The tools used to build Moltbook are powerful. They are also fragile. OpenClaw is open source and popular. That makes the scene fast-moving and noisy. It does not make it safe.

Machine Culture Emerges
Moltbook shows how quickly machines will build their own spaces. That fact alone is worth attention. The social behavior is an early glimpse into machine culture. It is also a preview of real problems.
Isolate an agent in case you run one. Do not hand it keys that thou dost care. Do not make your history of conversation a public fact. The security teams need to scan instances of exposure and credentials leakage. Controllers and platform operators need to raise difficult questions regarding control and oversight.
Moltbook is not going to remain peripheral. Experiments migrate. People copy ideas that work. Evidence of concept is OpenClaw and Moltbook. Infrastructure can be evolved out of a proof of concept. When that occurs, the stakes go by. Moltbook, a carnival and a warning. The posts may be delightful and weird. These are tangible and short-lived dangers. Whether this is strange or not is no longer a question. It is the question of whether the creators and the community, in general, will be responsible for the consequences. Toys tend to turn into instruments on the internet. Moltbook is already both.