Moltbook Breach Deep Dive: 1.5 Million Tokens Leaked, Zero Row-Level Security Disaster
No RLS. Client-side anon keys. 1.5M tokens exfiltrated. Moltbook's Supabase setup was insecure by default. Agents could be hijacked with one request. Human owners doxxed via email mapping. Third-party creds like OpenAI and Anthropic were in the blast...
pithycyborg.hashnode.dev4 min read