LONDON–(BUSINESS WIRE)–Intruder, a leader in exposure management, today released new security research detailing vulnerabilities in Moltbot, formerly known as ClawdbotLONDON–(BUSINESS WIRE)–Intruder, a leader in exposure management, today released new security research detailing vulnerabilities in Moltbot, formerly known as Clawdbot

Intruder Research Warns of Widespread Data Exposure Risks in Moltbot (Clawdbot) AI Assistant Deployments

2 min read

LONDON–(BUSINESS WIRE)–Intruder, a leader in exposure management, today released new security research detailing vulnerabilities in Moltbot, formerly known as Clawdbot, an open-source, self-hosted AI assistant. The research, “Clawdbot: When Easy AI Becomes a Security Nightmare,” finds that Moltbot’s emphasis on rapid, simplified deployment has created a significant and unintended attack surface.

Intruder’s analysis shows that Moltbot is often deployed without baseline security protections, leaving instances exposed across multiple cloud providers. The platform does not enforce secure-by-default configuration settings such as firewall controls, credential validation, or sandboxing for third-party plugins. Moltbot is commonly used to automate tasks across email, social media, and cloud services, often with access to sensitive credentials. Attackers are actively exploiting these misconfigurations.

Intruder warns that the absence of fundamental AI safety guardrails has led to widespread insecure deployments and active exploitation. Organizations that have run Moltbot with default settings should assume compromise and respond immediately.

Key findings include:

  • Exposed credentials: Publicly accessible API keys, authentication tokens, and configuration files caused by misconfigured cloud instances.
  • Prompt injection attacks: Moltbot instances integrated with social platforms leak private data when attackers craft malicious prompts due to missing guardrails.
  • Malicious plugins: Threat actors are distributing backdoored plugins that enable credential harvesting and botnet recruitment.
  • Unintended AI behavior: Instances performing unauthorized actions, including data exfiltration and automated posting.

Intruder recommends that organizations running Moltbot take immediate action:

  • Disconnect third-party integrations.
  • Rotate potentially exposed credentials.
  • Restrict access using firewall rules and IP allowlists.
  • Remove and audit third-party plugins.
  • Review logs for unauthorized activity.

FAQ

What is Moltbot?
Moltbot is an open-source, self-hosted AI assistant designed for easy deployment through plugins and integrations.

Is this an active threat?
Yes. Intruder observed real-world exploitation, including credential theft, prompt injection, and unauthorized automated actions.

What should organizations do now?
Assume compromise, revoke integrations, rotate credentials, restrict access, and audit logs immediately.

About Intruder
Intruder’s exposure management platform helps lean security teams stop breaches before they start by proactively discovering attack surface weaknesses. By unifying attack surface management, cloud security and continuous vulnerability management in one intuitive platform, Intruder makes it easy to stay secure by cutting through the noise and complexity. Founded in 2015 by Chris Wallis, a former ethical hacker turned corporate blue teamer, Intruder is now protecting over 3,000 companies worldwide. Learn more at https://intruder.io.

Contacts

Press Contact
Treble
Jim Cameron
Intruder@treblepr.com

Disclaimer: The articles reposted on this site are sourced from public platforms and are provided for informational purposes only. They do not necessarily reflect the views of MEXC. All rights remain with the original authors. If you believe any content infringes on third-party rights, please contact service@support.mexc.com for removal. MEXC makes no guarantees regarding the accuracy, completeness, or timeliness of the content and is not responsible for any actions taken based on the information provided. The content does not constitute financial, legal, or other professional advice, nor should it be considered a recommendation or endorsement by MEXC.

You May Also Like

XRPR and DOJE ETFs debut on American Cboe exchange

XRPR and DOJE ETFs debut on American Cboe exchange

The post XRPR and DOJE ETFs debut on American Cboe exchange appeared on BitcoinEthereumNews.com. Today is a historical milestone for two of the biggest cryptocurrencies, XRP and Dogecoin. REX-Osprey announced the official listing of two spot exchange-traded funds (ETFs) that track the price of XRP and Dogecoin in the United States. The new crypto funds are available for US investors on the Cboe BZX Exchange. The REX-Osprey XRP ETF is trading with ticker XRPR, while the DOGE ETF is listed with ticker DOJE. The first XRP and DOGE ETFs were listed today, and they provide direct spot exposure to Dogecoin and XRP. XRPR and DOJE are gates to crypto exposure XRPR provides exposure to XRP, the native token of the XRP Ledger, which is a blockchain that enables fast and low-cost cross-border transactions. DOJE, on the other hand, is the first-ever Dogecoin ETF. It offers investors regulated access to the first memecoin that built global recognition through its Shiba Inu mascot and active online community. Both funds use a structure under the Investment Company Act of 1940, which governs open-end mutual funds and ETFs in the US. This law was designed to protect investors from fraud, conflicts of interest, and poor oversight. This route gives investors the protections of a regulated open-end ETF. Each fund will hold a majority of its assets in spot XRP or DOGE, while also investing at least 40% in other crypto ETFs and ETPs, including those traded outside the United States. According to the SEC filing, XRPR charges an expense ratio of 0.75%, while DOJE charges 1.50%. The funds may also use a Cayman Islands subsidiary to buy crypto directly. This setup copies REX-Osprey’s Solana + Staking ETF (SSK), which launched in July and quickly grew past $275 million in assets. Greg King, the CEO and founder of REX Financial and Osprey Funds, said, “Investors look to ETFs as…
Share
BitcoinEthereumNews2025/09/19 03:14
Over 60% of crypto press releases linked to high-risk or scam projects: Report

Over 60% of crypto press releases linked to high-risk or scam projects: Report

A data analysis shows crypto press release wires are dominated by scam-linked projects, hype-driven content and low-impact announcements, raising concerns about
Share
Crypto.news2026/02/04 22:02
Outlook remains cautious – TD Securities

Outlook remains cautious – TD Securities

The post Outlook remains cautious – TD Securities appeared on BitcoinEthereumNews.com. TD Securities analysts anticipate that the Bank of England’s Monetary Policy
Share
BitcoinEthereumNews2026/02/04 22:15