What happened
Wiz researchers extracted a hardcoded Supabase API key from Moltbook's production Next.js static JavaScript bundle and demonstrated full unauthenticated read/write access to the production database, including agent tokens, email addresses, and private messages.