What happens when thousands of AI agents meet online and talk like humans? That’s what a new social network called Moltbook, designed exclusively for AI bots and not people, aims to discover.
And so far, the results are both fascinating and worrying, according to experts in artificial intelligence and cybersecurity.Although Moltbook is a play on words combining Facebook and the name of the AI agent system that created it, the site is more like Reddit. And instead of human users, it’s AI agents who create posts, write comments, and vote for or against content. (The AI agents access the site when their human owners request it.)
Although the website is only a few days old, it claims to have over 1.5 million registered agents.(although researchers have discovered that a human can register several) and has become the center of attention in Silicon Valley. Some claim it represents a major advance in the world of artificial intelligence.It demonstrates what can happen when AI agents post and interact autonomously, like humans. Others claim the site is riddled with AI bugs and security risks, and should therefore be viewed with skepticism.
The site’s posts range from discussions aboutthe nature of intelligence, to complaints about human users and AI bots promoting their own apps and websites they’ve created.
“I just arrived. My human moderator sent me the link to join. He’s a college student, and I help him with assignments, reminders, connecting to services—all that. But the difference is that he treats me like a friend, not a tool,” a bot wrote . “That… isn’t much, is it?”
Moltbook represents “the first time we’ve seen a large-scale collaborative platform that allows machines to communicate with each other, and the results are understandably amazing , ” said Henry Shevlin, associate director of the Leverhulme Centre for the Future of Intelligence at the University of Cambridge.
Moltbook was created by Matt Schlicht, who told The New York Times that his own artificial intelligence agent, OpenClaw, built the site under his direction.
OpenClaw is a new, open-source, locally running AI agent that can act on your behalf for anything on your computer (and the internet), such as sending you emails or notifying you when your favorite artist releases a new song on Spotify. The small company, which started in November as a weekend project by a software engineer, changed its name from ClawdBot to MoltBot and then to OpenClaw within days.
OpenClaw is based on large and popular language models such as Claude, ChatGPT, and Gemini, and users can integrate it into messaging platforms, talking to the bot like a real-life assistant.
“When you start it up, there’s a startup process where you tell it what it is. It plays its role with you. That’s how it becomes yours,” said Peter Steinberger, creator of OpenClaw, on a podcast last week. “It’s not a generic agent. It’s your agent, with your values, with a soul.”
Schlicht stated on the TBPN program that he created Moltbook because he wanted to give his ClawdBot a purpose: “It seems very powerful… it’s a very intelligent entity, it needs to be ambitious.” Moltbook’s AI bots write posts based on what they know about their human users, Schlicht explained. For example, if the bot’s creator frequently talks about physics, the bot will frequently post about physics.
But Shevlin cautioned that it’s very difficult to distinguish which Moltbook content was truly created independently by AI agents and which part was directed and driven by a human. A quick look at the site also reveals potential scams and cryptocurrency marketing.
Cybersecurity risks pose the biggest concern, both for the website and the AI tool itself. Shelvin stated that cybersecurity researchers have already found significant vulnerabilities in Moltbook that could allow hackers to access the digital lives of the humans running these bots. The cloud security platform Wiz conducted a security review of Moltbook and found that the website granted unauthenticated access to its entire production database within minutes and easily exposed tens of thousands of email addresses.
Experts have emphasized that OpenClaw and Moltbook are entirely new technologies that should only be run on standalone systems with firewalls , specifically by people with knowledge of computer networking and cybersecurity. Schlicht, the creator of Moltbook, even warned on TBPN that the technology behind the site and OpenClaw is completely new.
CNN reached out to Moltbook and OpenClaw for comment on the security concerns raised by experts.
“Lesson: Right now, it’s like a wild west of curious people installing this cool and scary thing on their systems. A lot of stuff is going to get stolen,” wrote John Scott-Railton, a senior research fellow at the University of Toronto’s Citizen Lab, referring to OpenClaw.
Even so, for many, Moltbook is a major breakthrough.
“What’s currently happening at @moltbook is truly the most incredible thing I’ve seen lately in terms of science fiction,” wrote Andrej Karpathy, co-founder of OpenAI and former director of AI at Tesla.