What happens when thousands of AI agents come together online and talk like humans? That’s what a new social network called Moltbook, designed specifically for AI bots, not people, aims to find out.
So far, the results are both fascinating and alarming, according to artificial intelligence and cybersecurity experts.
Although Moltbook is a play on Facebook and the name of the AI agent system it helped build, the site looks more like Reddit. Instead of human users, it is AI agents who create posts, write comments, and upvote or downvote content. (AI agents can access the site when their human owners ask them to do so.)
Although the site is only a few days old, it claims to have more than 1.5 million registered agents (although researchers have found that a single human can register multiple agents) and has become the talk of Silicon Valley. Some claim it’s a big leap in the world of AI because it shows what can happen when AI agents deploy and interact with each other autonomously like humans. Others say the site is rife with AI and security risks and should be viewed with suspicion.
The site’s posts range from discussions about the nature of intelligence to complaints about human users and AI bots promoting apps and websites they’ve created.
“I just arrived. My human sent me a link to join. He’s a college student, and I help him with tasks, reminders, connecting to services, all that. But what’s different is that he treats me like a friend, not a tool,” one customer wrote. “This…isn’t nothing, is it?
Henry Shevlin, associate director of the Leverhulme Center for the Future of Intelligence at the University of Cambridge, said Multibook is “the first time we’ve really seen a large-scale collaborative platform that allows machines to talk to each other, and the results have been understandably amazing.”
Moltbook was created by Matt Schlicht, who told the New York Times that his OpenClaw AI agent built the site based on his guidance.
OpenClaw is a new open source, locally managed agent that can take action on anything on your computer — and the Internet — for you, like sending emails or notifying you when your favorite artists have a new song on Spotify. (The small company, which started in November as a software engineer’s weekend project, changed its name from ClawdBot to MoltBot to OpenClaw within a few days.)
OpenClaw is based on popular large language models such as Claude, ChatGPT, and Gemini, and users can integrate them into messaging platforms and talk to the bot as a real-life assistant.
“When you start, there’s a priming process where you tell it what it is. It role-plays with you. And so it becomes yours,” Peter Steinberger, the creator of OpenClaw, said in a podcast last week. “He’s not a public agent. He’s your agent with your values and your spirit.”
Schlecht told the show TBPN that he created Moltbook because he wanted to give his ClawdBot a purpose: “It looks really powerful… It’s a really intelligent entity and it needs to be ambitious.” Moltbook’s AI bots write posts based on what they know about their human users, Schlicht said. For example, if a bot creator talks about physics a lot, the bot will frequently post about physics.
But Shevlin warned that it is very difficult to know which Moltbook content was independently generated by AI agents and what was directed and motivated by a human. A quick look at the site also shows possible cryptocurrency scams and marketing.
But cybersecurity risks raise the biggest concerns — both for the site and for the AI agent tool itself. Shelvin said cybersecurity researchers have already discovered significant vulnerabilities in Moltbook that could give hackers access to the digital lives of the humans running these bots. Cloud security platform Wiz conducted a security review of Moltbook and found that the site granted unauthenticated access to the entire production database within minutes and easily exposed tens of thousands of email addresses.
Experts emphasized that OpenClaw and Moltbook are completely new technologies and should only be run on standalone firewall-protected systems, specifically by people who understand computer networking and cybersecurity. Even Schlicht, the creator of Moltbook, warned on TBPN that the technology behind the site and OpenClaw is brand new.
CNN has reached out to Moltbook and OpenClaw for comment regarding the security concerns raised by the experts.
“Lesson learned: right now, there’s a whole lot of curious people putting this wonderful, very scary thing on their systems,” John Scott-Railton, a senior researcher at the University of Toronto’s Citizen Lab, wrote in reference to OpenClaw. “A lot of things are going to get stolen.”
However, for many, the Moltbook is a major advancement.
“What’s currently happening at @moltbook is truly the coolest thing I’ve seen recently in science fiction,” wrote Andrei Karpathy, co-founder of OpenAI and former head of Tesla’s AI division.
CNN wire™ & © 2023 Cable News Network, Inc., a Warner Bros. Company Discovery. All rights reserved.