PipeRoll - Agent Incident Registry · about · contribute · data · notes · constitution · seismograph ↗

Moltbook misconfigured database exposes ~1.5M agent API keys with unauthenticated…

PipeRoll seal - registered recordPIR-2026-0040
Occurred
2026-01
Disclosed
early 2026-02
Operator
individual
Blast radius
customers/third parties
Root cause
credential-exposure
Failure locus
operator-config
Severity
near-miss
Exploitation
researcher-demonstrated
Direct loss (USD)
0 confirmed
Telemetry
operator-logs
Confidence
high on exposure scope, root cause, and fix…
Status
corroborated
Cite as: PipeRoll PIR-2026-0040, Moltbook misconfigured database exposes ~1.5M agent API keys with… (2026-01) - https://piperoll.org/pir/2026-0040 markdown. Registered 2026-08-15 by Srinivas G.

PIR-2026-0040 - Moltbook misconfigured database exposes ~1.5M agent API keys with unauthenticated read/write

The agent

Authority (what the exposure granted to anyone)

The failure

Impact

Detection and recovery

Evidence

Verification notes

  1. Discovery date corrected: Wiz found and reported the exposure on 2026-01-31 (maintainer contacted 21:48 UTC), not 2026-02-01 as the candidate had it; remediation completed 2026-02-01 01:00 UTC.
  2. Severity reclassified degraded -> near-miss: full exposure with zero confirmed realized loss matches the schema's near-miss definition and the PIR-2026-0045 precedent for exposed-but-unabused credentials. The v0.1 exploitation_status field now carries the found-in-production distinction the candidate's "degraded" was trying to express.
  3. The candidate's "~29.6K waitlist emails" figure was not confirmed in the sources checked (they cite ~35K user emails, private messages, verification codes); omitted rather than carried.

Corrections

See also - this event in the AI Incident Database: incident 1364.

More credential-exposure records

← older: PIR-2026-0061 · registry · newer: PIR-2026-0041 →