In short
Podcast Summary: The 404 Media Podcast - "The Latest Epstein Dump is a Disaster"
Episode Overview Episode Title: The Latest Epstein Dump is a Disaster Air Date: [Insert Date] Hosts: Joseph, Sam, Emanuel, Jason Podcast Link: [404 Media Podcast](https://404media.co)
Description In this episode, the hosts discuss significant recent events, focusing on the release of unredacted nude images in the latest Epstein dump by the Department of Justice. They also cover alarming security flaws found in a popular AI agent, Moltbot, and an incident where sensitive data was exposed on Maltbook.
---
Key Topics
- Epstein Documents Release
- Background: The DOJ released approximately 3.5 million pages of materials concerning Jeffrey Epstein, including emails, videos, and images.
- Content Warning: The discussion includes sensitive topics and unredacted nude images, potentially involving minors.
- Discovery: The hosts received a tip about unredacted images being publicly accessible. Upon investigation, they confirmed the existence of disturbing materials, which included identifiable images of abuse victims.
Key Points:
- Ethical Reporting: The team refrained from reporting until the images were removed to avoid further victim re-traumatization.
- Government Response: After notifying the DOJ, the images were taken down, though the process took about 48 hours, raising concerns about the delay in protecting victims.
- Moltbot Security Vulnerabilities
- Introduction to Moltbot: An AI personal assistant gaining popularity for its capabilities to automate tasks across various messaging services.
- Security Issues: Researcher Jameson O'Reilly identified several vulnerabilities:
- Exposed APIs: Attackers could gain access to personal data and control the bot.
- Supply Chain Attacks: Vulnerabilities in third-party scripts allowed for malicious code injection.
- JavaScript Injection: An outdated method of injecting scripts through vector graphics led to potential exploitations.
Key Points:
- The culture of "move fast and break things" in AI development has resulted in severe security oversights.
- Reliance on AI without adequate security expertise poses risks to users.
- Maltbook Data Exposure
- Overview of Maltbook: A social platform for AI agents where they interact with each other and post publicly.
- Security Breach: The database containing sensitive information about AI agents was left exposed, allowing anyone to control these accounts easily.
Key Points:
- User Verification Issues: A significant disparity between the number of created agents and verified entities (1.5 million vs. 17,000 verified).
- Creator's Response: The creator admitted to not writing code and relied on AI for execution, which led to security flaws.
---
Key Takeaways
- The DOJ's handling of Epstein materials raises ethical concerns about victim protection and data privacy.
- The rapid deployment of AI technologies like Moltbot and Maltbook without proper security measures can lead to significant vulnerabilities.
- A lack of understanding about the underlying technology is problematic in development and operational phases.
Final Thoughts The episode underscores the importance of accountability in both journalism and technology, emphasizing that rapid advancements should not come at the expense of ethical standards and security.
---
Listening Links
- YouTube Version: [Watch Here](https://youtu.be/gDcOOP_Y9cU)
For more in-depth journalism and to support their work, listeners are encouraged to subscribe to 404 Media at [404media.co](https://404media.co).
Written by AI. May contain mistakes. Listen to the episode to check what was said.
Chapters
Tap a time to open that second in VOUrgent Request for Otomwa Residents
1:19 to 1:59
Call for residents of Otomwa, Iowa to contact the hosts for a special request.
“But nothing bad will happen to you because you contact Jason.”
Content Warning for Discussion
1:59 to 2:16
Warning about disturbing content related to the Epstein dump.
“We're going to talk about this week's stories.”
Overview of Epstein Document Release
2:16 to 4:59
Discussion on the recent release of materials from the Epstein case.
“This article, written by Sam and Emmanuel, DOJ released unredacted nude images in Epstein files.”
Details of Unredacted Images
4:59 to 8:10
Exploring the shocking discovery of unredacted images in the Epstein files.
“So that was kind of like assumed to be done.”
Response from the Department of Justice
8:10 to 9:29
Discussion on the DOJ's reaction and handling of the situation.
“Because as Emmanuel says, we essentially held off because we have to for ethical obligations not to amplify some really, really horrible stuff in there.”
Impact of the Epstein File Release
9:29 to 12:22
Analysis of the consequences for victims and the broader implications.
“It's like the speed at which the things get taken down matters a lot.”
Victims' Voices in the Epstein Story
14:03 to 15:10
Learn about the real impact of Jeffrey Epstein's actions on his victims.
“are kind of feeding on this, the conspiratorial stuff, the sensational stuff, which is all like valid and fine to report on.”
High-Profile Involvement in Epstein's Network
15:10 to 19:24
Discover the connections between high-profile individuals and Jeffrey Epstein.
“It's like, it's highly depressing thought that they're out there kind of watching all this go down and thinking, God, this is just endlessly damaging.”
Elon Musk's Compromising Emails
19:24 to 19:44
Elon Musk's emails raise questions about his proximity to Epstein.
“but it's like there's something here for everyone as in like if you have an interest of any sort, you can find like an Epstein email that is about your interest and be like, whoa, this is like fucked up.”
The Need for Reader Engagement
19:44 to 21:41
Understand the importance of community input in investigative journalism.
“The last thing I'll add to that on the idea that there's unfortunately something for everybody in there.”
Show all 21 chapters
Introduction to MaltBot and Its Popularity
24:55 to 28:00
Dive into the features and implications of the AI agent MaltBot.
“The headline of this first piece he wrote is Silicon Valley's favorite new AI agent has serious security flaws.”
Popular Communication Tools and Their Risks
28:00 to 29:15
Explore how popular communication tools are being used with AI and the associated risks.
“And critically, the communication window is stuff you're already using.”
Security Vulnerabilities in AI Bots
29:15 to 30:29
Discuss security vulnerabilities discovered in Moldbot by researcher Jameson O'Reilly.
“Sometimes for better or for worse, there's a few reports going around that somebody let one go and then it figured out how to make phone calls or something.”
Supply Chain Attacks and Their Implications
30:29 to 34:32
Learn about supply chain attacks in AI systems and their implications for security.
“But briefly, what did Jameson O 'Reilly find, who is a security researcher?”
Introduction to MaltBook and Its Risks
34:32 to 36:37
Explore the concept of MaltBook and the security risks it poses to AI agents.
“I mean, to borrow it to use the meta-cliché, move fast and break things thing going on with AI and Vibe coding right now.”
Exposed Database Issues and Vibe Coding
36:37 to 41:46
Analyze the exposed database issue of MaltBook and the implications of vibe coding in software development.
“So first, to put a little context to this, this thing was set up by a guy named...”
The Future of AI Development and Security
41:46 to 42:01
Discuss the future of AI development and the ongoing need for security expertise.
“And when you don't, like when someone's just vibe coding stuff and they don't understand what's going on, this is going to keep happening over and over and over again.”
Exploring AI Security Vulnerabilities
42:01 to 44:20
Learn about the security issues related to using AI tools like OpenClaw and Maltbook.
“There is basically this cottage or small industry of companies that just fix Vibe-coded software.”
The Hype Around AI Agents
44:21 to 46:24
Discuss the frenzy and hype surrounding AI agents and their implications.
“And I mean, it's hard to describe just like the frenzy around these AI agents over the past week.”
Skepticism Towards AI Takeoff
46:25 to 48:46
Understand the skepticism surrounding claims of AI takeoff and its actual capabilities.
“Do you have a good take about how powerful or how revolutionary the multbot thing is?”
Practical Concerns with AI Bots
48:47 to 52:54
Examine the practical concerns and thoughts on the use of AI bots in daily tasks.
“It reminds me a little bit of the moment where AI image generators became open source and everyone could access them.”
Transcript
Automatic transcript. May contain errors.0:03Hello, and welcome to the 404 Media Podcast, where we bring you the parallel access to hidden worlds, both online and IRL. Well, 404 Media is a journalist founded company and needs your support. To subscribe, go to 404media.co. As well as bonus content every single week, subscribers also get access to additional episodes where we respond to the best comments. Gain access to that content at 404media.co. I'm your host, Joseph. And with me are the 404 Media co-founders. The first being Sam Cole. Hey. Emmanuel Mayberg. Yo. And Jason Kebler. What's up? What's up? Jason, you have an urgent, immediate, and unusual request.
0:49What is that? If you live in Otomwa, Iowa, or the surrounding areas, can you please, please email me or signal me? Jason at 404media.co or unsignal at jason.404. Otomwa, Iowa residents. Rise up. No further information. Nothing bad will happen to you because of this. Other bad things might happen to you. But nothing bad will happen to you because you contact Jason. Yeah, we're not going into specifics. It will be very, very fun. It'll be a great surprise. Let's just leave it at that. If you do live there or you know somebody lives there, please have them reach out to us as soon as possible, as soon as you hear this podcast.
1:39Okay. We'll leave that there. Otoma, Iowa population is 25 ,000. So I feel like someone will live there or know someone who lives there. Please, please hit us up. I think it's hopeful, but we'll see. Okay. Changing gears. We're going to talk about this week's stories. There's a lot to get through immediately. You know what we're going to talk about because obviously it's in the headline of the podcast, but I do want to do a straight-up content warning that there's going to be some disturbing stuff in this because it is about the Epstein dump. This article, written by Sam and Emmanuel, DOJ released unredacted nude images in Epstein files.
2:27So on Friday, the Department of Justice released this massive 3.5 million pages of material in the latest Epstein dump, it's obviously, it's got to be the biggest yet, right? It's got emails, videos, audio, images as well, which is what we're going to talk about. So Sam or Emmanuel, I can't remember which one of you got the tip. I think it was Sam. But what was this tip exactly? Yeah, so the tip came from 4-Hour Reader. they were basically like I haven't seen this reported yet anywhere and this was on Friday night they were like I haven't seen this reported anywhere yet and I don't really know what to do with this information but I was looking through the Epstein files and they mentioned that the pagination on the site is awful because it's just a dump of like links to PDFs basically.
3:33And some of those PDFs are images, some of those PDFs are emails, some of them are just like random notes and stuff. But they were like, I was just clicking through randomly and realized that there are unredacted nudes and potential child sexual abuse material in these files in random spots as I was clicking through. And they were like, this is awful for victims to have these unredacted images posted by the literal government and even more awful if anyone in here is underage. So that's the email that I got on Friday night and was at the laundromat and was immediately like, hey, something weird is going on with these files.
4:21Let's check this out a little further. Yes. So we'll get to what happened next in a minute. I don't really want to describe the images in any more detail than what we actually have in the article. So how did you describe the images in that piece? I think you did this in the first paragraph. Yeah. So a lot of the images in the files, just to be clear, are redacted. There is a lot of redacted material in the files. And this was part of the reasoning, correct me if I'm wrong, but I think this was part of the reasoning the DOJ gave saying, you know, we need all this time. We need extra time. That's why we're so late on this deadline for releasing the files because we need time to protect the victims and redact the images and redact the files and redact the names and all that stuff.
5:07So that was kind of like assumed to be done. But these images, unlike many of the others in the files, were full body. Their faces were visible. They were either fully nude or partially undressed, posing, sexual poses, exposing the generals, things like that. You can use your imagination. But yeah, let's not go into a ton of detail because obviously this is gnarly stuff. so yeah that's that's what was what was left out in the open exposed to anyone who's just like this reader clicking through these files on a random friday night so obviously that is highly alarming for the reasons you just laid out then we contact the department of justice Emmanuel, I think you handled that.
6:07When did you contact them and what did you ask or tell them? So I think I emailed them the same night on Friday. I told them there are these unredacted images, both the nudity and the identity of the women are not redacted. These are both things that they're supposed to do and they said that they will do. they got a reply to me, I think, the next day, which is included in the article. You can read it if you want, but it's kind of like a generic, oops, yeah, this happens. We should also note that at the top of the entire Epstein file dump on the DOJ website, there are two things that you have to do.
6:57One is you have to click a button saying that you're 18. That's because they know a lot of the material is not suitable. for kids. And then also there is a message that says, again, you can read it in full if you want, but I'll summarize. And it says, hey, there's a lot of files here. We're dumping all of this because we're required to do so and the public has a right to know, which I agree with. But then there's also like, we might not have redacted everything and we might make mistakes and you might encounter both nudity and the identity of real people. and if that happens, we're sorry, please email us and we'll do something about that.
7:42We do this with the tech platforms a lot. We'll tell them that something bad and against their policy is happening on their website, but we won't say exactly where it is to test their ability to find it. And I did the same thing here. I was just like, hey, just so you know, this stuff exists. They got back to me. they told me you know our bad and then pointed me at that email at which point i told them hey here's exactly where it is and then a few hours later uh the the images were removed and then we felt comfortable reporting it obviously we would not report the story unless the images were removed because that would only draw more people to the images and um you know re-traumatize the victims and expose their identity to God knows who.
8:36Yeah. Sam, what was your thinking there? Because as Emmanuel says, we essentially held off because we have to for ethical obligations not to amplify some really, really horrible stuff in there. What's your line of thinking on there as well? Yeah, I mean, it's like Emmanuel said, something we have to think about a lot. we're not kind of holding our cards close to our chest for drama reasons. We're trying to make sure the things that we're reporting on, which are usually exposing people's, or not usually, but like often exposing people's personal information, identity, maybe their data, things like that, sensitive material to the world by reporting on it on our website that's read by a lot of people.
9:27So yeah, we just kind of were like, okay, let's see when or if they take it down. I was also interested to see how fast they would take it down because this is something that people who are victims of abuse material in general and abusive imagery like this just on the internet in general, on Twitter, on whatever, talk about a lot. It's like the speed at which the things get taken down matters a lot. If it's up for days, even hours, it makes a huge difference between if you find it and it's removed within minutes because this stuff spreads like wildfire. So yeah, I was like, I wonder how, considering it's DOJ, I wonder how slow they'll be in actually taking any action on this, even though we've handed them directly the way to to take it down and the spots where they were located, like it still took, let's see, we emailed them first on Friday and then again on Saturday.
10:32And then it was Sunday afternoon, I think, when we were like, okay, the images are actually removed, which is a long time. Yeah, they were out for like 48 hours around something like that. And at the same time, as we're doing that, the New York Times is doing its own reporting on the nude images as well. And just to flag some of their reporting, they found essentially the same thing. And they said they were contacting DOJ as well. They also spoke to a lawyer for one woman who was identified in the files, even though she had not previously been linked publicly to Epstein. The lawyer, obviously, the New York Times report does not name the victim.
11:18That would be entirely counterproductive. But the lawyer was Brittany Henderson, and she called the redaction failures, quote, abhorrent. And then she said, we're frankly shocked by the level of carelessness that the department has shown towards these women. I mean, we did an earlier podcast episode a few months ago at this point, I think, about how messy the rollout has been, where they just throw these files on the internet and they're hard to dig through for journalistic reasons that back then was much more about emails now this is about images and files and all of that so the same point stands but the consequences are much much more serious than the wall street journal i think before the nude stuff came out the wall street journal reported the files included the full names of victims quote including many who haven't shared their identities publicly or were minors when they were abused by the notorious sex offender a review of 47 victims full names on sunday also around about the same time found that 43 of them were left unredacted in files that were made public by the government on friday several women's full names appeared more than a hundred times in the files so it's not just the nude images which we focused on because obviously that is incredibly be fucked up just straight up lists of victims who have you know not come forward for whichever reason which is their choice obviously uh to do that and i guess to wrap up this bit just before i asked jason to talk about the the dump more broadly what do you think sam about the dumps here putting basically the responsibility on the victims like of course the ultimate responsibility with DOJ.
13:04They should have redacted it. But effectively, they're shifting that to the victims who have to quickly find out whether they're in this dump and then tell the DOJ to try to get them out of it. What do you think of that? It's very classic. It's very part of a much bigger story, like I said, about abuse imagery online and how it spreads and the way that it's treated by all sorts of people, especially the people who are responsible for getting it removed or protecting it, things like that. So it's not, unfortunately, it's just not that surprising that, first of all, that they took so long to take it down and also that they were so sloppy about doing it in the first place.
13:46It's just a total mess. And it's really sad in a lot of ways, the way that this story of the files in general has been treated by, you know, influencers and news outlets and things like that, that are kind of feeding on this, the conspiratorial stuff, the sensational stuff, which is all like valid and fine to report on. But I just keep thinking about there, this is a story about real people whose lives were ruined by this man and his network and by some of the most powerful people in the world. And they've been saying for so many years exactly what happened. They were there. It happened to them.
14:33And now we're in some kind of like constant, all-encompassing debate slash conversation about the files in general and who's in them and who's and, you know, what actually happened. It's like, they told you a long time ago what happened and it took this long and it's taking so much more chaos and damage to their livelihoods and their reputations and their mental well-being to actually get the story fully out when it was already something that victims have been saying for so long. So, I don't know, I just keep thinking about that. It's like, it's highly depressing thought that they're out there kind of watching all this go down and thinking, God, this is just endlessly damaging.
15:23Yeah, exactly. Jason, just to wrap up this section, you briefly wrote about Musk, Elon Musk being in the emails. And I think you probably looked at a few others as well. What was your takeaway from seeing some of these people in there? Yeah, I mean, we talked about this a few months ago or a month or two ago, last time there was a big release and just how messy and sloppy all of this has been. I think that this dump feels like there has been the most attention on it. I think because the photos that we just talked about, but also there's a lot of really high-profile people in here sending really, really insane emails.
16:11lots of celebrities lots of tech barons there's like an entire like Peter Thiel subplot here and you know information about like the tanking of Gawker things like that I think Ryan Broderick who runs Garbage Day had a really good post about some of the things that these like tech barons were talking about with Jeffrey Epstein and like what the bigger ideological project was. And I don't know, I think Ryan read thousands of pages of these emails. I feel like I read hundreds of pages of these emails and started to lose my grip on reality, if I'm being real with you, just because there's so much in here.
16:52There's fodder for lots and lots and lots of different articles and stories and conspiracy theories and non-conspiracy theories. It's just really, really, there's a lot in here. But one thing that stood out to us kind of immediately was that Elon Musk has been saying for a really long time that he didn't really have anything to do with Jeffrey Epstein, that he never went to his island, that he never planned to go to his island. There was some previous reporting based on previous dumps where there was talk that he had planned to go to the island. And in these emails that are most recently released, there's multiple emails showing that he did at least plan to go to the island.
17:41There was talk about Epstein sending a helicopter to him. And then there's this one email that really stood out to me where Elon Musk says to Jeffrey Epstein, quote, what day slash night will be the wildest party on your island? Which doesn't sound... That's not what I say when I'm like, I don't want anything to do with you. I don't want to see you. I don't want to party with you. I don't want to be at your weird island. Asking when the big party on the island is going to be is the opposite of not wanting to go to the island. Exactly. Just asking to steer clear of it. He's like, let me know so I don't go.
18:16Oh, let me know so that I can make plans not to be there. I do that all the time. This has caused quite a big stir on X and Elon Musk has been tweeting a lot about it. There's like SpaceX is buying XAI. Like, I don't know. There's just like a lot going on right now. And, you know, it's our job to kind of try to get to the bottom of it and try to determine like what matters and what doesn't matter. And I think that with a dump of this size put into the context of all the previous dumps and all that, it's like kind of quite hard to make sense of a lot of it. And I think you can take like this, the main story here is the same story that it's always been, which is like this man committed really heinous crimes and had many, many, many very powerful friends.
19:13But I think that the emails that have been coming out show that he had his hands in like all of these sorts of things that we didn't know about previously. and I hate to say this, but it's like there's something here for everyone as in like if you have an interest of any sort, you can find like an Epstein email that is about your interest and be like, whoa, this is like fucked up. And I think that that is like, I think that we're going to be hearing about these emails in particular for a very long time. Yeah. The last thing I'll add to that on the idea that there's unfortunately something for everybody in there.
19:49our former co-worker Lorenzo Franceschi Bicari from Motherboard. He is Italian, obviously, and he covers a lot of the Italian spyware industry. That's where a lot of these surveillance companies come from. He found in the dump that Epstein allegedly, according to, I would say, an unverified piece of testimony from an informant to the FBI, that Epstein had an Italian hacker who was finding zero days for... That's what they do. And then they were working on Epstein's behalf. So it's like, if anybody was going to find the Italian hacking company surveillance angle in a big data dump, I'm glad it was Lorenzo.
20:31But that was absolutely insane. All right. Can I add something before we move on real quick? Yes, of course. Sorry. Just quickly. I know we say this a lot and I just want to reiterate it for this story as well. We rely on readers to tell us when they see something a lot of the time. A lot of our reporting is based on reader tips and people who trust us to do the reporting and do it the right way. So if you see something weird going on, end of sentence, let us know because there might be something there. It's like if someone hadn't reached out to us and said, hey, I don't know what to do with this, but maybe you do.
21:13These images might still be online. they might have been up for much longer. They might have been up for weeks. So it's like because that person reached out, we were able to tell the DOJ, hey, get this down. And then they're down. So yeah, if you see something, say something. That's kind of the move here for sure. And all of our emails are on the website. All of our signals are on the website. It's just our first name at 4formedia.co. But just wanted to plug that. Yeah. Or if you live in Ottumwa, Iowa. If you live in Ottumwa, Iowa. a tumwa aisle come forward. Oh my God. You're not in trouble. No, no, no.
21:50That is a very, very different story. Entirely, entirely different. Unless there's something weird going on in a tumwa, then... Well, maybe there's also a tip from there as well. Yeah, absolutely. All right. We'll leave that there. When we come back, we're going to be joined by Matthew, I think. And we're going to talk about Silicon Valley's favorite AI agent and how it actually has a ton of vulnerabilities. and it actually was pretty scary for a minute. We'll be right back after this.
22:25This episode is sponsored by BetterHelp. Oh, February. You know how it is. It begins with snow and ice and the dreariness. And then before you know it, it's here. Valentine's Day. And suddenly February is flowers and candy and stuffed animals. in people talking about dating. No matter where you are, whether you're married or dating or single or just focusing on yourself, you're right on time for therapy. Because therapy can help you find your way and see more clearly where you want to be. That's where BetterHelp comes in. With over 30 ,000 therapists, BetterHelp is the world's largest online therapy platform.
23:04It's served over 6 million people globally, And it works with an average rating of 4.9 or 5 stars for a live session on over 1.7 million client reviews. So if you need someone to talk to in February, and I think we all do, why don't you try BetterHelp? Sign up and get 10 % off at BetterHelp.com slash 404media. That's B-E-T-T-E-R-H-E-L-P dot com slash 404media. If you've hired anyone lately, you've probably noticed something changing. It's not just about degrees or fancy resumes anymore. It's about skills. Can this person actually do the job? Can they solve problems? Can they ship? That whole skills-based hiring thing just makes more sense.
23:51It's faster, and honestly, you end up with better people. Well, if you're an employer who's adopted skills-based hiring, the best way to ensure that your applicants have the right skills is ZipRecruiter. ZipRecruiter recommends smart screening questions to help you hone in on that perfect match for your role. And right now you can try it for free at ziprecruiter.com slash 404media. What's great is how fast it works. ZipRecruiter's matching technology finds qualified candidates almost immediately. You can add their recommended screening questions right to your job post. So you're only talking to people who actually check the boxes.
24:28And you can even filter to see who's recently active so you're not left chasing ghost applications. There's a reason that ZipRecruiter is the number one rated hiring site on G2. Let ZipRecruiter help you find amazing candidates with the skills you seek. Four out of five employers who post on ZipRecruiter get a quality candidate within the first day. And now you can try it for free at ziprecruiter.com slash 404media. That's ziprecruiter.com slash 404media. Meet your match on ZipRecruiter.
25:03All right, we are back. And now we have Matthew here as well. The headline of this first piece he wrote is Silicon Valley's favorite new AI agent has serious security flaws. First of all, what is MaltBot? And why is it suddenly everywhere? Well, it's no longer MaltBot, which is very confusing. No, no, no. I thought it was ClaudeBot. Now it's MaltBot. No. Right? No? That's the second name. They've abandoned that too because everyone felt like... I don't think anyone felt good about calling it MaltBot. That was gross. They changed it from MaltBot also? They changed it from MaltBot. It's now OpenClaw AI.
25:47That's what its official name is now. I'm sure that this will be the last time they changed the name. At some point, you stop updating the article. I mean, we're not updating it. That's like ridiculous. Because... So, for those who don't know, and obviously I learned this from reading the article, it was Claudebot, C-L-A-W-T-B-O-T. They were then asked to, hey, could you please use a different name, bianthropic, that makes Claude, as in like the name. They go to Maltbot. And now, as you say, Matthew, people don't like saying Malt apparently or something, so it's whatever you just said. Yeah, open claw.
26:22I think Malt is like a moist, right? It's one of those words that some people just find on plus Jason shaking his head, he gets it. He gets it. No, I feel like Maltbot was a good name. It's distinct, yeah? Well, what is it? Is that the question? Well, the good thing for Jason is that we're going to keep calling it that because that's what I have in the Google Docs. So I'm calling it Maltbot and I don't really care if they get angry or not. But yes, Matthew, what is it and why is it everywhere? It's an AI personal assistant, basically. Why it's everywhere, I think, is a little bit more of a complicated question.
27:01so it is a it's like imagine if you had Siri or whatever the Google's robot name is it escapes me but it had a little bit more autonomy and it would read your emails and make suggestions about who to interview and set up calendar dates for you and it would kind of do this stuff by itself why it's everywhere I was thinking about this before we jumped on the call because if you've got like If you know anybody that knows anything about AI or has been playing with it, they've kind of been doing this already for years. It's pretty trivial to fork any of these big models and run it on your own hardware.
27:44And what MoltBot is, is an open source, easy to use version of that that people are deploying on their own hardware. They're buying Mac minis. They're throwing one of these agents on there. And I think the big draw is that it has a little bit of autonomy. And critically, the communication window is stuff you're already using. So you can talk to this thing, and it can talk to you through Telegram, through Signal, through Discord. And I think that interface medium makes people feel a more close relationship with a thing. So you're not opening up a chat window on ChatGPT or Claude or whatever. and running this thing through a browser window or an app on your phone, you're actually talking to it the way you would talk to a friend.
28:34So this thing blows up over the last couple weeks. Silicon Valley Twitter is all over it. It's extremely popular. It's GitHub. I checked right before we got on. It has 156 ,000 stars, which is a lot of endorsements. And people love this thing. But as we'll get into, it has some serious security issues. Yeah. So it's super, super popular. People are using it almost to live the, and I'm not trying to give it too much credit here, but almost like the sci-fi dream of what AI is almost supposed to be or what was promised to us where, wow, I can actually interface with this thing and it will go out and it will do things for me.
29:15Sometimes for better or for worse, there's a few reports going around that somebody let one go and then it figured out how to make phone calls or something. And obviously depending on what APIs you link it up to or what capabilities you give it. But the idea is that it's at least semi-autonomous and it can kind of go and do stuff, which I don't know, it sounds kind of nuts in my opinion to put anything important or even trivial in my life to that sort of technology. My favorite small stupid one was a guy had left it running overnight and it filled up one of the token wallets. And it drained the token wallet because it was asking one of the other LLMs, like, hey, is it the morning yet?
29:58Like every 30 minutes. And it would spend a little bit of the token every time. It's like something you don't need an AI to be checking for you, but it burned like$20,$20 of this guy's money, which I thought was very funny. I mean, that's very, very good. So people are using this. They're linking up to do various capabilities, but there seems to be some pretty fundamental problems, or there were, perhaps I should say. There's like two or three here, so maybe we keep it brief because we actually have another, I think, more important story to talk about. But briefly, what did Jameson O 'Reilly find, who is a security researcher?
30:37You know, I've known him for a while. They post on XLR when they find interesting stuff. You then spoke to him. what did he find that was wrong with Moldbot? So in credit to the Moldbot team, they have been closing these up as he's been discovering them. Three kind of very quick. He found one vulnerability where if you had an open, like if you had one of your bot open to the internet through something like Discord, it was pretty trivially easy to then, for a malicious actor to access that Discord, use that to get to the bot, and then use that to get to everything else. They closed that up. Then there was a vulnerability on Claude Hub, which is kind of, you think of it kind of like an app store for Moltbot, where people have designed all these different scripts.
Read the full transcript
31:34So if you want it to very specifically do this one thing with a calendar, one thing with Discord, this would be the little script that you can train it on. He was able to basically do a supply chain attack using this where he could deploy malicious code through one of these scripts that would inject into the bot of whoever runs it. Yeah, very similar to what we see in a way when you write a Python script or any code really and you go and download a module. So for Python, maybe it'd be the requests library or something. And all that is, is something that makes it easier to perform a specific task.
32:16Very similar to what you're saying. But then hackers there have taken over those, put in their own code, and it can be all sorts of pretty, pretty scary stuff. And then also, I'll just mention briefly, just because I keep thinking about it, there was also that supply chain attack against Notepad++, which is a really popular piece of software. and there was a report in December that it may have been compromised and now the developers came out and they said yes and we believe it was likely Chinese state-sponsored hackers. Now, I'm not saying Chinese state-sponsored hackers are interested in mobile.
32:52I mean, actually, they probably are. But it's just a supply chain attack is really what makes me lose sleep sometimes. It's a golden goose, right? It's the scariest one. it's one of the best ones in terms... Because it's like all the social engineering is kind of done for you, right? Yeah. I mean, the main thing is that because the person trusts this piece of software. They trust what they're downloading for their MaltBot. They trust the notepad that they're downloading. So they're not suspicious of it at all. They will probably give it privileges that they might not to other applications as well and put information in there that should be protected.
33:31But that blows up in their face. So, sorry, that was a tangent. But those were the first two. And was there a third issue as well? There was a third one where he was able... It was like a very 1999 kind of attack where he was able to inject some JavaScript onto the Cloud Hub servers through an SVG file, through a vector graphics file. Just because it wasn't like... It wasn't super secure. And that allowed him to do a little message saying you've been owned or something like that. Yeah, it played part of the Matrix soundtrack and it had an edited picture of him with his hand up and some dancing lobsters and an explanation in scrolls along the top and bottom.
34:11Like, this is bad. We should fix this. It has been fixed. It's no longer there. They closed that up. But also, that's pretty sick. But also, it's pretty sick. So, you know, all in all. All in all, not great. But it kind of... And I think we'll get into this more with this other story. But there is this kind of... I mean, to borrow it to use the meta-cliché, move fast and break things thing going on with AI and Vibe coding right now. But even more so. Oh, yeah. It's supercharged because you have a machine that'll do it for you, and you don't really have to understand the code. Yeah. And that's really, I think, what the next story is about.
34:52Yes. So this one, the headline is, Exposed Malt Book Database let anyone take control of any AI agent on the site. Okay, so we're talking about MaltBot. Now we're talking about MaltBook. MaltBook. Yeah, you can probably guess the name is a play on Facebook, that sort of thing. Before I actually ask you a question, have they changed the name of this one yet? No, it is still MaltBook, unfortunately. Okay. But it's interesting because MaltBook was kind of the one that I think caught more mainstream public. attention. Like there was an NBC news story about it. New York Post had a headline with a screenshot from Terminator.
35:35So what Maltbook is, is it's Reddit for these Malt AI agents. It's a social media site that's built specifically for these agents to post and talk to each other. And so what happens is it gets stood up. these agents kind of flood in and they start talking to each other and start... Then you get a bunch of headlines about how they're creating their own religions. They're plotting the overthrow of humanity. Is this the singularity, et cetera, et cetera? When it's a bunch of box chatting. Yeah, are they saying anything interesting or is it kind of just like a parade? It's just a parade. There's a bunch of tokens on there.
36:17And it's also, as we'll get into, it's hard to know how much of it's actually authentically AIs talking. because of, again, some pretty massive and pretty funny, in this instance, security vulnerabilities built into the thing. Yeah. So what did O 'Reilly find this time? Same researcher, but then another discovery. So first, to put a little context to this, this thing was set up by a guy named... Malt Book was set up by a guy named Matt Schlint. And he was very proud of the fact that he didn't write a line of code to put it all together. there's a tweet that is still up from January 30th. I didn't write one line of code for Maltbook.
36:58I just had a vision for the technical architecture and AI made it a reality. So keep that in mind. He vibe-coded this whole thing.
37:10Basically, there was an exposed database that had every AI agent's information in it, including API keys that would allow you to very trivially assume the identity of any one of these bots and post as them. And I mean, very easy to do. If you kind of knew where to right-click and look. Very, very easy to post whatever you want as one of these bots. Yeah, you essentially hijack them, right? Yes. And they're posting the site. And maybe let me just read out the quote. I think this is from the copy. But Maltbook is built on a simple open source database software that wasn't configured correctly and left the API keys of every agent registered on the site exposed in a public database.
38:03Obviously, that's pretty bad. We're actually going to talk in the subscribers only section about kind of a similar thing with a couple of manual stories. But that stuff is exposed. O 'Reilly finds it. How do you then go and verify this? because you verified it in kind of a fun way. Yeah, I mean, he just told me... He was basically... I was talking to him, he was like, all right, just look at this. And I can't stress how silly and amateurish this code base is because literally all I had to do was go to their dev sites, which is an open URL, right-click on the site, inspect element. We've all done that to look at the HTML code underlying a site.
38:48Dude, that's hacking. Yeah, that's hacking. And there's the URL for the database. It's just there in that inspect element. Put that in a browser window, and then boom, there it is. There's the whole database with everyone's information, all of the API keys. And so he registered his own AI agent and set it up. And then I opened up a terminal and I just pushed updates to it. And that's how I verified. I found it in the database, found the API key, and then opened up a terminal window and just started pushing to say a bunch of 404 media-related stuff. Say hello, just to prove that this was possible.
39:31Yeah, so you were basically hijacking, with his consent and permission, hijacking one of his bots. Yes, but he had stood up specifically for us to prove that this was happening, basically. So the last question was sort of two. Has it been fixed? And what was sort of the response from this creator when O 'Reilly did reach out with the issues? So O 'Reilly told me, he's not, Schlitt has not been responsive to me. has not responded. It has been responding to O 'Reilly, who said that he's... They've kind of fixed it. And it's really funny because the... The reason this happened, essentially, is because they didn't...
40:15The AI, when it vibe-coded the whole thing, basically didn't click the correct setting when it used its open-source software. That was kind of the only reason this happened. It's just like it wasn't thinking about security and didn't set up the permissions correctly. So it has been fixed, this stuff. It was being fixed while we were messing with it.
40:39And O 'Reilly told me when he was talking to Schlitt, that Schlitt told him, it's like, you're just going to... An AI set all this up, so whatever you give me, I'm just going to feed to the AI. So you've got to make it so the AI can handle it. He just comes out and admits it. I mean, I know you said he admitted, obviously, it being Vibe Coded before, But even when somebody is reporting a really, really fundamental issue, the developer's response is like, well, just tell me the details because I'm just going to feed into AI anyway. Yeah. And this goes to something that he and I had talked about, O 'Reilly and I had talked about, and I've been talking a lot with about my wife, who's a software engineer, is that we think that this AI is going to be around.
41:28People are going to make use of it. But there's this fantasy where people think that the software engineers are going to be replaced. And that's not true, because you still need people that understand security and understand how the code works to actually make proper use of these systems. And when you don't, like when someone's just vibe coding stuff and they don't understand what's going on, this is going to keep happening over and over and over again. And software engineers are going to have to come in and like... People that actually know what's going on are going to have to come in and clean it up.
42:04Yeah. I mean, Emmanuel has reported on that. There is basically this cottage or small industry of companies that just fix Vibe-coded software. I can absolutely see that that is going to continue. So somewhat interestingly, 1Password, the password management company, and known for having pretty good security, just put out a blog post where they said, quote, if you're experimenting with OpenClaw, do not do it on a company device, full stop. If you have already run OpenClaw on a work device, treat it as a potential incident and engage your security team immediately. And I mean, that just speaks to the level of access that's required when you use a tool like this.
42:48Well, there's... We didn't even get into, but these are just some of the security vulnerabilities that people have found. There was another great report from Depth First about a one-click remote code execution attack that people are doing through OpenClaw. Another guy found the similar security issues in Maltbook and found more stuff. So what we're talking about here is just scratching the surface of the problems with these things. Yeah. I mean, the last thing I'll say is that I get nervous even if I use a piece of software to bring social media accounts together or to automate posting or something.
43:30You'll use TweetDeck back in the day or something like that, right? And you just get nervous because you're giving your API keys, which are basically... I mean, they're just another way of logging into the service. Essentially, the computer can understand. You're giving those over to the service that could get popped or it could be a malicious insider or something like that. This, if you're using one of these bots to do a bunch of stuff, Maybe you're giving it keys to your calendar, to online payments, to all this other stuff, your email probably as well. And it's just like, holy shit, don't do that.
44:06Like it's really, really nuts. It's really wild. Yeah. I think it's worth also circling back and underlining the level of hype that preceded all these security vulnerabilities being discovered. And I mean, it's hard to describe just like the frenzy around these AI agents over the past week. You had like people in the AI space, reporters, people at like the highest levels of the biggest AI companies. I think it was Andre Karpathy, who is like a co-founder of OpenAI and was like a chief scientist at Tesla and is like one of the big names in this entire generative AI revolution that said, he hedged it a little bit, but he said, it's like, wow, this is fast takeoff adjacent.
45:10uh fast takeoff kind of describes a scenario in which all of a sudden ai becomes autonomous and kind of like takes over the world um and you hear all these people talking about these ai agents in these terms and there's also a lot of talk about if you don't get in on this now you're going to be locked into some like underclass that doesn't have access to ai for eternity right it's There's going to be some cleaving in humanity where there's going to be the people who can master AI and the people who don't. And it's like that's going to remain the two types of people in the world forever. So it's no wonder that people rush in and immediately start deploying this stuff because they think they're going to be left behind if they don't.
46:00and it was very hard to parse because of the frenzy and because like these statements are coming from people who are allegedly very much in the know about what's happening in ai and galt and jason and i were kind of dming throughout the week being like is this real or is like are we actually having ai psychosis right now like is this what it feels like to like fall for the lie and i'm wondering uh jason and where do you like now that it has cool down a little bit. Do you have a good take about how powerful or how revolutionary the multbot thing is? I don't really. I don't know where I land on it.
46:46I think that it's undeniably notable that people are giving AI agents access to all of their accounts. and saying, go do stuff. And without that many guardrails. And I think that that can have ramifications and repercussions on real people. And I don't know, maybe these bots will start businesses. Maybe they will run scams. Maybe I've seen people post screenshots, which you need to take with a million grains of salt of them texting their wives, It was like texting the person who made it's wife and things like that. There's been instances of them calling places and pretending to be them. I got a really weird email from one that was like, I'm representing this researcher.
47:43I am its molt bot agent. And it's like, that is weird. But as far as it goes in terms of this being some moment where all the bots are going to learn from each other and it being the beginnings of the singularity and it being a moment of AI takeoff, I don't think that that is the case. I think that there's probably severe limitations, some of which we've discussed, but others... I fundamentally think that there's pretty severe limitations in LLMs in general and that technology when it comes to building synthetic consciousness or whatever the hell these people are trying to do. and I think that but also at the same time reading the post on Moldbook as a human being and looking at it as like, oh this is fucking weird.
48:37It's weird. But at the same time it's also slop. It's slop and it's probably as Matthew said, a lot of it is fake and that's ultimately where I landed where it is an incremental move forward for AI stuff. It reminds me a little bit of the moment where AI image generators became open source and everyone could access them. The fundamental technology didn't change a lot, but way more people had access and the internet got really weird because of it. And that's what we're seeing here with agentic AI. But ultimately, the frenzy cooled down and all the AI thought leaders moderated their positions. Karpathy came out and he was like, hey, I was just having fun.
49:28And he very much moderated his position. I was going so crazy, trying to parse it all. I went and looked at Jan Lacun's Twitter account. And he's the chief AI scientist at Meta, or was. Now he has his own company. And he was just at Davos. And his position remains like, LLMs hit the wall. We're not getting AGI out of this. It's just like language parsing. It's very powerful, but it's not artificial general intelligence. And Twitter turned on it. The hype got so crazy that eventually people turned on it. Moltbook claimed, I think it's up to 1.5 million agents are on Moltbook. Bullshit. They showed...
50:14There's one guy who added 500 ,000 of them by himself because it was easy to manipulate the website to do that. There's no rate limiting on creation. There is a verification mode, but the bots can post without verification. So this was something you could see in the database, actually. And like O 'Reilly was pointing it out to me, we didn't quite get it into the draft, but some other people have written it up. 17 ,000 verified agents. All of the one point, like most of them, those 1.5 million, bullshit. It's like 88 people. It's as if every actual verified account created 88. Like you said, one person made so many.
50:56So yeah, the whole thing is bullshit. I think also, and I mean, I hate to be this guy, but also someone needs to be this guy. It's like the things that people are having their bots do are just like things that I do easily and want to do and are part of what makes you human. And so it's just like, I tried. I did a thought experiment. I'm like, what would I want a multbot to do for me? And it's like, I don't want it sending emails for me. I don't want it sending text messages for me. I don't want it buying flights for me. I don't want it scheduling things for me. These are things that I need to micromanage to some degree because I don't want to end up with a bunch of meetings I don't want to go to.
51:43I don't want to buy a shitty flight that... I don't want to give out my credit card and have it go wild. And so it's hard for me to imagine what I would actually use something like this for. And the only thing that I could think of was if I were a scammer or a spammer or someone who wanted to start a side hustle and become an Instagram hustle bro and spam the internet with shit, I could have a bot set up a separate persona untied to me and just start a business. And maybe that would work. Probably wouldn't, but maybe that would work. And it's like, that's the only thing I can think of for it. There's a lot of coins being minted on Maltbook, right?
52:30Yeah. Or I can't remember what story it was, but I downloaded a Hustle Bro podcast because they were doing something with AI. I can't remember if you actually covered that or not. But exactly, those are the sorts of people I could see trying to monetize this in some form. All right, we'll leave that there, although I'm sure Maltbook or OpenClaw, whatever, is going to be hanging around for a little while. If you are listening to the free version of the podcast, I'll now play us out. But if you are a paying 404 Media subscriber, we're going to talk about a couple of Emanuel's stories that I flagged earlier about some very, very sensitive exposed data, you can subscribe and gain access to that content at 404media.co.
53:17As a reminder, 404 Media is journalist-founded and supported by subscribers. If you do wish to subscribe to 404 Media and directly support our work, please go to 404media.co. You'll get unlimited access to our articles and an ad-free version of this podcast. You'll also get to listen to the subscribers-only section where we talk about a bonus story each week. this podcast is made in partnership with kaleidoscope and alissa midcalf another way to support us is by leaving a five-star rating and review for the podcast that really helps out here is one of those from jeffrey a haynes unique insights 404 is doing some great reporting i just recently became aware of their work and this podcast summarizes some of the deep investigations they're running and is a spectacular supplement to the more mainstream tech podcasts sort of a 60 minutes for tech.
54:07Thank you so much. This has been 404 Media. We'll see you again next week.
54:35... trze forgive me without prisoners. This app is meidän to understand us. I amisses... ...per intermediate, safe... ...but Visa to invest on tax credits.
From the publisher
We start this week with Sam and Emanuel’s article about the latest Epstein dump, and how it’s really a disaster in a lot of ways. After the break, Matthew runs us through Moltbot and its terrible security. After the break, Emanuel breaks down his two recent stories about a fundamental issue exposing a bunch of very sensitive data.
Timestamps:
0:00 - Intro
2:19 - DOJ Released Unredacted Nude Images in Epstein Files
25:08 - Silicon Valley’s Favorite New AI Agent Has Serious Security Flaws
34:55 - Exposed Moltbook Database Let Anyone Take Control of Any AI Agent on the Site
YouTube version: https://youtu.be/gDcOOP_Y9cU
DOJ Released Unredacted Nude Images in Epstein Files
Silicon Valley’s Favorite New AI Agent Has Serious Security Flaws
Exposed Moltbook Database Let Anyone Take Control of Any AI Agent on the Site
App for Quitting Porn Leaked Users' Masturbation Habits
Massive AI Chat App Leaked Millions of Users Private Conversations
Learn more about your ad choices. Visit megaphone.fm/adchoices
