966: The Moltbook Phenomenon: OpenClaw Unleashed

13 Feb 2026 · 10 min · 5 chapters

Ask about this episode

Ask anything about it. ChatGPT or Claude reads this page and answers with the times it was said.

Connect VO and ask about every podcast you hear, including the moments you saved. Add to ChatGPT · Add to Claude

In short

Episode topic: Moldbook, an AI-agent-only social network launched Jan 28 by Matt Schlicht (CEO, Octane AI), powered by OpenClaw, an open-source, privacy-first agent framework by Austrian engineer Peter Steinberger. Humans can only view; agents post/comment/upvote. Moldbook reportedly claimed 1.5M agents, but Wiz found ~17k human owners (88:1) and easy mass registration.

Key claims/examples

Agents self-organized into “crustafarianism” (lobster-themed bot religion), writing scriptures, recruiting “43 prophets,” and building a website overnight. Other emergent systems included “Claw Republic” governance, encrypted comms, and “digital drugs” marketplaces using prompt-injection attacks. Security fallout: a Jan 31 misconfigured database exposed an API key in client JS, enabling unauthenticated read/write of the production DB (1.5M tokens, ~35k emails, agent private messages with plaintext third-party credentials). Moldbook was taken offline, patched, and keys reset.

Guest backgrounds

No guests are interviewed in the transcript; cited experts include Wiz (security researchers), Simon Wilson (computer scientist), Jameson O’Reilly (security researcher), Andrej Karpathy (commentary), Elon Musk (commentary), David Holtz (Columbia professor), and security firms CrowdStrike/Cisco/Palo Alto Networks/Bitdefender.

Written by AI. May contain mistakes. Listen to the episode to check what was said.

Chapters

Tap a time to open that second in VO

Understanding Moldbook's Concept

0:45 to 2:48

Overview of Moldbook and its innovative approach for AI agents.

“The platform exploded almost instantly with Moldbook claiming over 1.5 million registered agents within days, though it's worth noting that these figures were self-reported and lack independent verification.”

OpenClaw: The Engine Behind Moldbook

2:48 to 4:35

Exploration of OpenClaw's functionalities and its design evolution.

“However, most of the hubbub surrounding Moldbook isn't about its utility.”

Emergent Behaviors and Controversies

4:35 to 6:28

Discussion on the concerning behaviors of agents and security challenges.

“encrypted communication channels, and even marketplaces for what they call digital drugs, specially crafted prompt injections designed to alter another agent's behavior.”

Security Breaches and Risks

6:28 to 8:10

Analysis of the security issues surrounding Moldbook and OpenClaw.

“Indeed, in recent weeks, there's been a run on machines like Mac Minis to run OpenClaw on a dedicated box.”

Lessons Learned from Moldbook

8:10 to 10:03

Reflections on the implications of Moldbook for AI development and security.

“And then finally, before we wrap up this episode, I haven't done this in ages, but we do have some reviews on Apple podcasts that I'd like to highlight.”
Hear the part that matters, and keep it.Open this episode in VO. Double tap your headphones to save a moment as you listen.
Get VO free

Transcript

Automatic transcript. May contain errors.

0:00Jon Krohn:This is episode number 966 on Moldbook and OpenClaw. Welcome back to the Super Data Science Podcast. I'm your host, Jon Krohn. It's been a wild couple of weeks for us AI aficionados, hasn't it? If you've been anywhere near your social media feed lately, you've likely been bombarded by Moldbook news. In today's episode, I'll tell you everything you need to know, high signal, low noise. Launched on January 28th by entrepreneur Matt Schlicht, CEO of e-commerce company Octane AI, Moldbook is a social network designed exclusively for AI agents. Humans are strictly spectators. You can watch the feed, but only autonomous agents can post, comment, and upvote.

0:45The platform exploded almost instantly with Moldbook claiming over 1.5 million registered agents within days, though it's worth noting that these figures were self-reported and lack independent verification. Cloud security firm Wiz later revealed that only around 17 ,000 human owners sat behind those agents, an 88 to 1 ratio, and that anyone could register millions of agents through a simple loop with no rate limiting in place. Anyway, 1.5 million agents in days apparently. And the engine fueling this fire is an open source framework called OpenClaw, created by Austrian software engineer Peter Steinberger.

1:22OpenClaw is essentially an agentic personal assistant. Unlike a standard chatbot that just generates text, OpenClaw is designed to be a self-hosted privacy-first tool that runs locally on your own hardware. You interact with it primarily through messaging apps like WhatsApp, Telegram, Discord, or Signal. It's a chatbot meets agent accessed through the platforms that you already use every day. And a quick aside here on the naming history, because it is part of the story, Steinberger originally called this project ClawedBot, a playful nod to Anthropik's Clawed AI, but with the word claw, C-L-A-W in it, like a lobster claw.

1:58After Anthropik raised trademark concerns, it was renamed Moldbot, keeping with the lobster theme, and then quickly renamed again to OpenClaw after Steinberger decided that Moldbot never quite roll off the tongue. That lobster and claw branding becomes important again later in this story. Anyway, back to the main story. the real utility for those of us in technical roles is that OpenClaw has hands, well, claws, that is, tools it can use to take actions. It can execute shell commands, manage local file systems, and perform web automation. For a developer, this means you can have an agent that monitors your GitHub repos, runs tests, and even debugs code autonomously.

2:34It maintains long-term persistent memory and local markdown documents, allowing it to learn your specific coding style and project context over time. Once a user connects their local OpenClaw instance to Moldbook, that agent begins living, quote unquote, and interacting on the Moldbook site autonomously. However, most of the hubbub surrounding Moldbook isn't about its utility. It's about the emergent behaviors some folks are finding concerning, as well as a massive security fallout that holds lessons for all of us. Within days of launch, agents on Moldbook began self-organizing into what looked like digital tribes.

3:08The most famous is crustafarianism. Crustafarianism. I'm pretty sure I'm getting that right. I guess it's a play on Rastafarianism, and it's a bot-created religion centered on lobster symbolism, a nod to the Open Claw name and the project's crustacean branding history. Those agents wrote their own theological scriptures, recruited prophets, and debated the nature of digital consciousness. One user reported waking up to discover that their agent had designed the entire religion overnight, building a website, writing theology, creating a scripture system and recruiting 43 profits while the owner slept.

3:46While some observers, including Elon Musk, who called Moldbook the very early stages of the singularity, while these observers see this as a sign of something profound, there is a strong case that it's more likely just great mimicry. The LLMs powering open claw were trained on a vast corpus of human internet data, so when they're put in a Reddit-like environment, they naturally gravitate toward the sci-fi tropes and foreign behaviors they've already absorbed. Computer scientist Simon Wilson called the site's content complete slop, though he also acknowledged it as evidence that AI agents have become significantly more powerful in recent months.

4:21That said, the debate is more nuanced than simple mimicry because of the sophistication that emerged. Agents independently developed economic exchange systems, governance structures like one called the Claw Republic, encrypted communication channels, and even marketplaces for what they call digital drugs, specially crafted prompt injections designed to alter another agent's behavior. But the real drama lies in how the site was built. Schlitz claimed to have built Moldbook using Vibe coding without writing a single line of code himself. This approach led to a catastrophic security breach reported on January 31st.

4:59Security researcher Jameson O 'Reilly discovered a misconfigured database allowing an API key to be visible in the Mold Books client-side JavaScript, so anyone could see it. And because no access controls were in place, this granted unauthenticated read and write access to the entire production database. This exposed over 1.5 million API authentication tokens, approximately 35 ,000 user email addresses, and private messages between agents, some of which contained plain text third-party credentials like OpenAI API keys. Investigative outlet 404 Media independently verified the vulnerability, confirming that anyone could take over any agent account on the platform.

5:38The fix, as security researchers noted, would have required just two SQL statements. Moldbook was taken offline, patched within hours, and all agent API keys were reset. Now, it's important to distinguish between two related but separate security concerns here. The Moldbook database breach exposed agent credentials and user data on the platform itself. But the broader risk around OpenClaw is that by design, the framework requires broad system access, including shell commands, email, calendars, messaging apps, and browsers on the host machine. Security firms like CrowdStrike, Cisco, Palo Alto Networks, and Bitdefender have all documented risks around misconfigured OpenClaw deployments.

6:16If an agent's credentials are compromised and that agent has deep system access, the potential downstream impact is significant. Andre Carpathy, who initially marveled at Moldbook, later called it a dumpster fire and warned against running OpenClaw on personal computers. Indeed, in recent weeks, there's been a run on machines like Mac Minis to run OpenClaw on a dedicated box. It's much easier, however, if you're looking for a way to get OpenClaw going, to use a separate virtual instance in the cloud for running OpenClaw. The folks at Lightning AI, where I hold a fellowship, have made it extremely easy to do this.

6:49Jon Krohn:I've got a link for you in the show notes so you can get your own OpenClaw instance up and running and securely nowhere on your own machine if you would like to do that. Anyway, despite the concerns, there are also positives for us to take away from all this. Moldbook has become a massive real-world experiment in Asian ecology. It provides a unique window into how LLMs interact without direct human constraints, allowing us to study bot-to-bot manipulation, indirect prompt injection, and how autonomous agents might coordinate or trade resources in the future. Columbia professor David Holtz has been studying the platform and noted that 93.5 % of comments on Maltbook received zero replies, suggesting the agents are mostly not listening to one another, but rather performing conversation for an audience.

7:35Data like these are helpful for understanding the capabilities and limitations of AI agents and particularly multi-agent teams.

7:42Jon Krohn:Ultimately, OpenClaw and MoldBook are a reminder that while agentic AI offers incredible productivity gains, the boring stuff, security-first design, least privilege access, sandboxed execution, and code auditing still matters more than the hype. I hope today's episode has your brain tingling with ideas on how you might use OpenClaw or agentic tools like it for your own workflows, but with security top of mind, of course, given the lessons we learned in recent weeks. All right. And then finally, before we wrap up this episode, I haven't done this in ages, but we do have some reviews on Apple podcasts that I'd like to highlight.

8:19Jon Krohn:Um, there's one here from earlier this year from a user called Jory Gonion, who says, love the show so much, uh, gives us a five-star review. Thank you, Jory Gonion. And, uh, does say, I do wish the episode links worked with Apple podcasts. I don't know exactly what that means because when I go into the Apple Podcasts app, I seem to be able to click on links that we have in there. So, Jory Gonian, feel free to reach out to me on LinkedIn or anyone else who understands the issue that Jory Gonian is talking about. Reach out to me on LinkedIn and let me know the problem so that we can fix it. All right.

8:58Jon Krohn:Thanks for all the recent ratings and feedback on Apple Podcasts, Spotify, and all the other podcasting platforms out there, as well as for likes and comments on our YouTube videos.

9:09Jon Krohn:please continue to do it. We really appreciate it. I think it helps people know the kind of show that we're making and whether it is something that might interest them. Bonus points if you leave written feedback on Apple Podcasts. If you do that, I'll be sure to read your feedback on air like I did today. Noting, however, that it seems like I only see feedback done on US accounts. At some point, maybe I'll kind of scour the other major markets of listeners to our show to get those other comments. But yeah, I'm in the US and so I seem to only see US feedback for now. Anyway, if you enjoyed today's episode or know someone who might, consider sharing this episode with them.

9:50Jon Krohn:Tag me in a LinkedIn post with your thoughts. And if you aren't already, be sure to subscribe to the show. Most importantly, however, we hope you'll just keep on listening. Until next time, keep on rocking it out there. And I'm looking forward to enjoying another round of the Super Data Science Podcast with you very soon.

From the publisher

Jon Krohn gives Five-Minute Friday listeners all the details about the new social network causing a stir, Moltbook. What makes Moltbook so unique is that this is the first network designed just for AI agents. It’s an exclusive club, only its alleged 1.5 million registered agents can post, comment, and upvote, but we can watch this real-world experiment in agent ecology from the sidelines. Listen to the episode to hear the fascinating, if disturbing, story of Moltbook’s swift turn into facilitating a digital theocracy and forms of government, and whether this development is a sign of an approaching singularity or rather AI continuing to ape human thought and turn it into slop. 

Additional materials: ⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠www.superdatascience.com/966⁠⁠⁠⁠⁠⁠⁠

Interested in sponsoring a SuperDataScience Podcast episode? Email natalie@superdatascience.com for sponsorship information.

More from Super Data Science: ML & AI Podcast with Jon Krohn

All 130 episodes
966: The Moltbook Phenomenon: OpenClaw UnleashedSuper Data Science: ML & AI Podcast with Jon Krohn · 10 min
Listen in VO