ADVERTISEMENT

Github’s viral AI assistant Moltbot is a step away from a massive breach

Moltbot AI became viral overnight, but researchers warn that the “vibe-coded” tool might be leaking your credentials.

Moltbot data breach

Image by Cybernews

Paulina Okunytė
Paulina Okunytė Senior Journalist
January 30, 2026 4 min read
Jurgita Lapienyte justinasv Izabele Pukenaite vilius Ernestas Naprys Gintaras Radauskas
Don't miss our latest stories on Google News. Add us as your Preferred Source on Google
Add us as your Preferred Source on Google.
Moltbot data breach
Source: OX Security

Credentials are not secured

Over 300 contributors increase risks

Moltbot data breach
Source: OX Security
ADVERTISEMENT

Vibe-coded with no guardrails

Moltbot data breach
Source: OX Security
Moltbot data breach
Source: OX Security

Vulnerable to indirect prompt attacks

Moltbot data breach
Source: OX Security

Use Moltbot with caution

  • Check your Moltbot configurations to ensure you are not allowing any automated command execution on your machine that is overly permissive.
  • Don’t add platforms you are not going to use actively – when you decide to stop using them, make sure to remove unused integrations and delete them afterwards from the configuration files.
  • Manually delete backup files in ~/.clawdbot (note that you also need to remove backup files from ~/clawdbot if you want the information to be fully removed from your machine).
  • Make sure Moltbot is not connected publicly to the internet – avoid exposing Moltbot to the public internet.
  • If public exposure is required by design, mitigate access by blocking unknown IP addresses and restricting access by IP allow-listing.
  • Update regularly and monitor for security advisories, as attackers keep searching for weaknesses and vulnerabilities. A continuous updating routine will make your environment much more secure.
ADVERTISEMENT