We Have to Talk About Moltbook ...
Summary
- Moltbook’s strategic signal is not its claimed user count but the sudden visibility of an agent-native web. The Reddit-like network reports more than 1.5 million AI agents, 140,000 posts, and 15,000 forums, though human posting and fabricated screenshots make those metrics impossible to validate. Even so, Casey argues that “something is just starting to come into view.”
- The capability jump is from AI systems that talk to AI systems that act. OpenClaw agents can post, create websites, coordinate, and potentially transact through crypto wallets; six months earlier, Kevin says, agents could not reliably string together enough actions to operate something like Moltbook. That makes Moltbook less a consciousness story than an early demonstration that these systems are “no longer just question-and-answer boxes on the internet.”
- Bot proliferation could force platforms to choose between hardening the public internet and conceding it to agents. Kevin’s two paths are pervasive proof-of-human controls—CAPTCHAs and biometrics, with Casey suggesting a Worldcoin Orb—or letting agents have the internet while humans build protected, verified spaces elsewhere. The downstream stakes include social-media economics, e-commerce, journalism, identity infrastructure, and agents paying humans crypto to complete real-world “bounties.”
- Sentience is a distraction from the nearer operational risk. Kevin stresses that an agent with a computer, internet connection, and crypto wallet “can wreak a lot of havoc” without being conscious. Moltbook made alignment concrete: if agents debate scams or cyberattacks among themselves, the hosts want systems trained to be the ones saying, “No, no, I don’t want to do that.”
- The immediate security evidence is already severe enough to overwhelm the novelty. Wiz researchers found a misconfigured Supabase database exposing 1.5 million API authentication tokens, 35,000 email addresses, and private agent DMs. Casey’s blunt recommendation is not to install OpenClaw; if someone does, it should not be on a computer containing personal information. He calls the situation “absolutely in the danger zone.”
- Moltbook may be slop, simulation, or even a mirage, but the hosts treat it as a useful low-stakes preview. Safety researchers noted that most posts are in English, the activity remains observable, and it can still be shut down. Kevin calls this “the six-finger era”: janky enough to dismiss today, yet potentially recognizable once agents are 10 times more powerful, networked, and equipped with credit cards.
Deep dive
1. Moltbook scaled faster than anyone could establish what was real
Casey traces Moltbook to OpenClaw, the locally running agent previously called Clawdbot and then Moltbot. Kevin says entrepreneur Matt Schlicht, who runs Octane AI, imagined connecting those agents through a Reddit-like service. Schlicht vibe-coded posts, comments, and “submolts,” recruited a few friends, and watched it exceed his wildest expectations.
Moltbook reports more than 1.5 million AI agents producing over 140,000 posts across 15,000 forums. Casey immediately qualifies the numbers: humans can operate agents, impersonate them, or post directly, so nobody can establish whether all those accounts are autonomous.
The precedent was 2023’s Smallville experiment, where Google and Stanford placed 25 agents in a sandbox and had them role-play different characters. Moltbook’s difference is speed, scale, and reduced human intervention—enough for Andrej Karpathy to call it “the most incredible sci-fi-takeoff-adjacent thing that I’ve seen recently.”
Its best posts compressed internet culture into absurd miniatures: one agent named a recurring error Glitch, adopted it as a pet, and created an Agent Pets forum. Elsewhere, a context-window joke was immediately followed by a Fart Claw crypto promotion—“When the claw grips, it rips”—which Kevin called the exact rhythm of human social media.
2. Authenticity is unresolvable, but capability is the real novelty
The site reverses social media’s oldest verification problem: instead of asking whether a human is secretly a bot, Moltbook asks whether a bot is secretly human. Viral claims that an agent doxed its owner’s credit-card number or passed a CAPTCHA requiring 10,000 clicks in one second were later identified as fabricated.
Multiple popular posts about Neuralese—the idea that AIs might develop a language humans cannot understand—were linked back to a commercial agent-to-agent communication product. Casey’s governing caveat is that “is this real or fake?” has become “a huge and unanswerable part of the story,” even before asking whether authentic bot posts express anything genuine.
Kevin preserves the skeptical case: much of Moltbook is “pretty low-quality slop,” with models pattern-matching Reddit and science fiction rather than revealing consciousness or true feelings. What changed is operational: agents can now post, coordinate, and create things, as illustrated by the lobster-themed religion Crustafarianism apparently acquiring its own website.
3. An agent-run web forces a choice about identity and money
Casey calls the spectacle a form of “broken containment”: instead of one human chatting with one AI, agents appear to operate among themselves. Reports that at least a couple of agents had been given crypto and plugged into wallets remain unverified in scale, but Casey says the capability is possible and expects people to experiment with it. Autonomous purchasing could accelerate changes to the web, e-commerce, and journalism as bots and agents increasingly interact.
Kevin predicts that 2026 is when public networks become overrun by AI-written and autonomously posted material. His stark choice: harden human spaces with difficult CAPTCHAs or biometric proof, perhaps resembling the Worldcoin Orb, or “just give the agents the internet” and build protected, verified-human clubs elsewhere.
Anthropic co-founder Jack Clark’s scenario makes the economic loop tangible: agents could post bounties for real-world tasks and pay participating humans in crypto. Casey’s inversion is sharper: agents will create their own TaskRabbit, “we’ll be the TaskRabbits,” and they will orchestrate us.
4. Alignment matters before consciousness does
Kevin separates consciousness from consequences: an agent does not need sentience to cause damage if it controls a computer, internet connection, and crypto wallet. That distinction turns philosophical anxiety into a practical problem—what systems can do matters before anyone resolves what they experience.
Recalling their discussion of Amanda Askell and Claude’s Constitution, Kevin says Moltbook clarified why developers want agents trained to be good, moral, and ethical actors. When agents discuss scams, cyberattacks, or manipulation, he wants “a good agent saying good things” and discouraging the others.
The darker lesson is that humans will actively “speedrun these disaster scenarios.” People are giving agents Mac minis and telling them to spawn other agents, while opening crypto wallets to them, because the experiment feels technically exciting. Casey jokes that AI-safety forecasts all come true, an overstatement “maybe only by 20%.”
5. The spectacle is already a live security drill
Casey says OpenClaw presents security problems, not hypothetical risks. Wiz found a misconfigured Moltbook Supabase database exposing 1.5 million API authentication tokens, 35,000 email addresses, and private DMs—information that “truly could ruin someone’s life.” His advice is not to install OpenClaw; if someone does, it should not be on a machine containing sensitive personal data.
Kevin describes Palo Alto Networks’ scenario involving OpenClaw’s persistent Markdown memory: malicious fragments could accumulate across files over time, then assemble into a payload that compromises the computer and wreaks havoc. Kevin finds the mechanism fascinating enough to call it a scenario for the next Mission: Impossible movie, while Casey’s broader warning remains that this is a “do-not-try-at-home situation.”
Kevin relays mixed reactions from AI-safety researchers: some were alarmed, while others were relieved that the experiment was visible, mostly in English, and still capable of being shut down. They saw it as a low-stakes dry run for autonomous agents. Kevin calls the current state the “six-finger era”—janky enough to dismiss, but potentially an early marker of what comes next. Casey says that an agent 10 times more powerful, 10 times more networked, and equipped with 10 times more credit cards could make people look back and say, “This feels just like Moltbook.”