Intruder Research warns of widespread data exposure risks in Moltbot (Clawdbot) AI Assistant deployments

Share This Post

Intruder, a leader in exposure management, today released new security research detailing vulnerabilities in Moltbot, formerly known as Clawdbot, an open-source, self-hosted AI assistant. The research, “Clawdbot: When Easy AI Becomes a Security Nightmare,” finds that Moltbot’s emphasis on rapid, simplified deployment has created a significant and unintended attack surface.

Intruder’s analysis shows that Moltbot is often deployed without baseline security protections, leaving instances exposed across multiple cloud providers. The platform does not enforce secure-by-default configuration settings such as firewall controls, credential validation, or sandboxing for third-party plugins. Moltbot is commonly used to automate tasks across email, social media, and cloud services, often with access to sensitive credentials. Attackers are actively exploiting these misconfigurations.

Intruder warns that the absence of fundamental AI safety guardrails has led to widespread insecure deployments and active exploitation. Organizations that have run Moltbot with default settings should assume compromise and respond immediately.

Key findings include:

  • Exposed credentials: Publicly accessible API keys, authentication tokens, and configuration files caused by misconfigured cloud instances.
  • Prompt injection attacks: Moltbot instances integrated with social platforms leak private data when attackers craft malicious prompts due to missing guardrails.
  • Malicious plugins: Threat actors are distributing backdoored plugins that enable credential harvesting and botnet recruitment.
  • Unintended AI behavior: Instances performing unauthorized actions, including data exfiltration and automated posting.

Intruder recommends that organizations running Moltbot take immediate action:

  • Disconnect third-party integrations.
  • Rotate potentially exposed credentials.
  • Restrict access using firewall rules and IP allowlists.
  • Remove and audit third-party plugins.
  • Review logs for unauthorized activity.

Related Posts

IREN shares fall 8% as costly AI transition weighs on earnings

Weakening profitability overshadowed a major milestone in IREN’s transformation...

Kraken users briefly locked out after a flood of sanctioned crypto transactions

The activity, appearing to spread sanctioned funds to trigger...

Visa doubles down on South Korea with Upbit operator Dunamu on stablecoin payments

Following a deal with Shinhan Financial, the global payments...

From Hawala to Swift: Inside the 1,000-year battle to move money safely

Finance has spent centuries decoupling wealth from physical transport,...

Michael Saylor hints at first bitcoin purchase in two months as bitcoin nears $79,000

Bitcoin rebounds from Friday’s low as Strategy’s valuation expands...

Bullish backs USD.AI with $100 million in financing to drive GPU-backed loans

Cryptocurrency platform Bullish is extending a $100 million debt...