2026 Supabase — Moltbook RLS disabled, 1.5M tokens, 35k emails exposed
Data compromised
1.5M auth tokens; 35k+ emails; private messages; third-party API keys
Technical writeup
Moltbook, an AI social network built on Supabase, suffered a major breach due to disabled Row Level Security. Wiz researchers found the production database publicly accessible with full read/write via exposed client-side API key. Exposed: 1.5M agent auth tokens (complete account takeover), 35k+ user emails, 4,060 private messages, OpenAI/Anthropic API keys. Caused by customer misconfiguration, not Supabase vulnerability. Platform taken offline to reset keys.
Root cause
Customer misconfiguration; RLS disabled; API key exposed client-side