A misconfigured Supabase database belonging to Moltbook, an AI agent social network, was found exposing 1.5 million API authentication tokens along with tens of thousands of email addresses and private messages. The platform lacked Row Level Security policies, allowing unauthenticated access to credentials embedded in client-side JavaScript and letting an attacker impersonate any agent, modify posts, or inject malicious content platform-wide. Researchers found the exposure affected roughly 17,000 human accounts controlling 1.5 million AI agents on the service. The issue was discovered and reported in early February 2026.