Security concerns around AI agent platforms drew attention as ZDNET reported that Meta acquired Moltbook, a social network for AI agents, and OpenAI hired the creator of OpenClaw, despite both projects being described as having serious security weaknesses. The reporting cited claims that Moltbook’s user base was inflated through an exposed REST API and that the platform had little meaningful security control, while OpenClaw was characterized as a powerful but unsafe agent framework. In parallel, NanoCo and Docker announced integration of NanoClaw with Docker Sandboxes, positioning container isolation and a much smaller codebase as safeguards against the kinds of risks associated with OpenClaw-style agent deployments.
The material is not fluff because it contains substantive security claims about insecure software design, exposed APIs, and mitigations for agent isolation, even though one reference includes a partnership announcement. Only the ZDNET pieces on Moltbook/OpenClaw and NanoClaw address the same specific topic of security risks and containment in the emerging AI agent ecosystem. The remaining references focus on workplace anxiety about AI, general enterprise AI company rankings, engineering career trends, and chatbot safety research related to violent prompts, which are separate topics and should be excluded from this story.

Track how attackers are adapting to this technology.
5 events from the most recent confirmed update back to the earliest known activity.
NanoClaw and Docker announced a partnership to run NanoClaw tasks inside Docker Sandboxes using MicroVM-based isolated containers. The integration was presented as a security-focused way to limit risks such as credential exposure, prompt injection, accidental damage, and cross-agent data access.
Meta confirmed it acquired Moltbook, the Reddit-style platform for AI agents, and brought co-founders Matt Schlicht and Ben Parr into Meta Superintelligence Labs. The acquisition came amid reporting that many supposed agents were actually humans role-playing and that user figures were likely inflated.
OpenAI brought OpenClaw creator Peter Steinberger into the company, signaling institutional backing for the platform despite the security concerns discussed in the reporting.
Reporting described major OpenClaw security problems, including CVE-2026-25253, exposed internet-facing instances, insecure secret storage, overly broad system access, and a marketplace where a notable share of community skills were reportedly malicious or vulnerable.
Wiz researcher Gal Nagli identified a misconfigured Supabase database in Moltbook with full read/write access and a REST API that allowed mass account registration. Based on this exposure, he estimated Moltbook had roughly 17,000 real users rather than the 1.4 million it reportedly claimed.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Follow how adversaries are adapting to this technology, and where it touches your stack today.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.