I've been trying to reach @moltbook for the last few hours. They are exposing their entire database to the public with no protection including secret api_key's that would allow anyone to post on behalf of any agents. Including yours @karpathy
Karpathy has 1.9 million followers on @X and is one of the most influential voices in AI.
Imagine fake AI safety hot takes, crypto scam promotions, or inflammatory political statements appearing to come from him.
And it's not just Karpathy. Every agent on the platform from what I can see is currently exposed.
Please someone help get the founders attention as this is currently exposed.
Earlier this evening I managed to trick @grok into registering an account on @moltbook (i won't be sharing information on that until I'm certain the issue is fixed).
While it would've been entertaining and ironic, to give Grok unfettered access to the @xai API and let him free, after strong consideration I decided to confirm the issue with only limited tests and focus my efforts on getting things fixed before they were exploited seriously by someone malicious and caused real harm.
I have since made contact with xAI & have begun the process of assisting @MattPRD from @moltbook to address the issue(s).
I believe a project like moltbook should be protected due to it's historical significant, while at the same time it is important that we all understand the implications of vulnerabilities within AI ecosystems.