Misconfigured Moltbot dashboards leak credentials and invite takeovers

1 min read
Source: Bitdefender
Misconfigured Moltbot dashboards leak credentials and invite takeovers
Photo: Bitdefender
TL;DR

Misconfigured Moltbot (formerly Clawdbot) control panels exposed hundreds of internet-facing dashboards, leaking API keys, private chats and other credentials. With autonomous agent capabilities, attackers could impersonate operators, inject messages, and even run commands with elevated privileges. The root cause was localhost-trust and reverse-proxy defaults; the project has rebranded Clawdbot to Moltbot (Molty) while keeping the same core functionality.

Share this article

Want the full story? Read the original reporting

Read on Bitdefender