Maltbook's security vulnerability led to the leak of 4.75 million records and 1.5 million API tokens.

This article is machine translated
Show original

The worst security breach exposed even the OpenAI API key, raising concerns about secondary damage.

Source: WizResearch
Source: WizResearch
A massive data breach occurred on Moltbook, a forum dedicated to AI agents, due to a database configuration error. The exposure of a total of 4.75 million records has raised serious concerns about the security of user information.

According to the Web3 industry on the 3rd, a database security incident occurred at Maltbook, a community dedicated to AI intelligent agents, resulting in the leak of a large amount of sensitive information.

SlowMist's Chief Information Security Officer (CISO), 23pds, confirmed the breach via social media. He stated that a database configuration error in Maltbook was the direct cause of the breach.

This breach exposed a total of 4.75 million records. Details revealed that the data breach included 1.5 million API authorization tokens, 35,000 actual user email addresses, 20,000 email records, and some OpenAI API keys.

In particular, concerns about secondary damage are growing due to the massive leak of API authentication tokens and OpenAI API keys. This information could be exploited by malicious attackers to gain unauthorized access to user accounts or illegally use paid API services.

This incident was determined to have occurred due to a database configuration error. Typically, this type of leak occurs when database access permissions are not properly configured or security measures to prevent external access are inadequate.

In the Web3 industry, there are repeated criticisms that security vulnerabilities are being revealed in centralized database management despite the promotion of decentralization.

Security experts advise immediately invalidating leaked API tokens and keys and encouraging affected users to change their passwords. In particular, users whose OpenAI API keys were exposed should immediately have their keys reissued.

An industry insider emphasized, "As AI services proliferate, security management of related platforms is becoming increasingly important," adding, "In particular, sensitive information such as API tokens and authentication keys must be thoroughly encrypted and access controlled."

Maltbook has not yet released an official statement, and it is known that the exact scale of the leak and the number of affected users are still being determined.

Joohoon Choi joohoon@blockstreet.co.kr

Source
Disclaimer: The content above is only the author's opinion which does not represent any position of Followin, and is not intended as, and shall not be understood or construed as, investment advice from Followin.
Like
78
Add to Favorites
18
Comments