← Supabase

2026 Supabase — Moltbook RLS disabled, 1.5M tokens, 35k emails exposed

2026 1.5M records affected Share on X

Data compromised

1.5M auth tokens; 35k+ emails; private messages; third-party API keys

Technical writeup

Moltbook, an AI social network built on Supabase, suffered a major breach due to disabled Row Level Security. Wiz researchers found the production database publicly accessible with full read/write via exposed client-side API key. Exposed: 1.5M agent auth tokens (complete account takeover), 35k+ user emails, 4,060 private messages, OpenAI/Anthropic API keys. Caused by customer misconfiguration, not Supabase vulnerability. Platform taken offline to reset keys.

Root cause

Customer misconfiguration; RLS disabled; API key exposed client-side

References