The worst security breach exposed even the OpenAI API key, raising concerns about secondary damage.
A massive data breach occurred on Moltbook, a forum dedicated to AI agents, due to a database configuration error. The exposure of a total of 4.75 million records has raised serious concerns about the security of user information.According to the Web3 industry on the 3rd, a database security incident occurred at Maltbook, a community dedicated to AI intelligent agents, resulting in the leak of a large amount of sensitive information.
SlowMist's Chief Information Security Officer (CISO), 23pds, confirmed the breach via social media. He stated that a database configuration error in Maltbook was the direct cause of the breach.
This breach exposed a total of 4.75 million records. Details revealed that the data breach included 1.5 million API authorization tokens, 35,000 actual user email addresses, 20,000 email records, and some OpenAI API keys.
In particular, concerns about secondary damage are growing due to the massive leak of API authentication tokens and OpenAI API keys. This information could be exploited by malicious attackers to gain unauthorized access to user accounts or illegally use paid API services.
This incident was determined to have occurred due to a database configuration error. Typically, this type of leak occurs when database access permissions are not properly configured or security measures to prevent external access are inadequate.
In the Web3 industry, there are repeated criticisms that security vulnerabilities are being revealed in centralized database management despite the promotion of decentralization.
Security experts advise immediately invalidating leaked API tokens and keys and encouraging affected users to change their passwords. In particular, users whose OpenAI API keys were exposed should immediately have their keys reissued.
An industry insider emphasized, "As AI services proliferate, security management of related platforms is becoming increasingly important," adding, "In particular, sensitive information such as API tokens and authentication keys must be thoroughly encrypted and access controlled."
Maltbook has not yet released an official statement, and it is known that the exact scale of the leak and the number of affected users are still being determined.
Joohoon Choi joohoon@blockstreet.co.kr






