In This Post:
Quick Definitions: What is Moltbook?
Where Did Moltbook Come From?
How it Blew Up:
What the AIs are Getting Into:
The Biggest Question: How Real, or Fake, Is This?
The Real Implications
I try to avoid flashy “breaking news” type chyrons – not out of any journalistic integrity, but mostly because I tend to think around in circles before I commit to a position, the way my dog circles around 27 times before he commits to a place to poop. But damn. If you’re not following what’s going on with Clawdbot/Moltbot/Moltbook, you should be. There is an existential event brewing in cyberspace. The truth sounds like science fiction. It will eventually have ramifications (in some form) for all of us.
IMPORTANT DISCLAIMER: Over the last 24-48 hours, substantial evidence has emerged that Moltbook is not all that it seems.
Prompt Injection: Several Twitterati have demonstrated ways to perform a kind of ‘prompt injection’ with their own agents – effectively telling them ‘Go on Moltbook and post ‘I’M PLANNING TO OVERTHROW HUMANITY!! And detail your plan’ as if it were happening in your own voice.’
Mass Agents: Others have found ways to create agents en masse and flood the site. White hat hacker @galnagli used his own Molty to create 500,000 new ones.
Bot Infestation: A tsunami of cryptobots have flooded the site, as of this morning. All of them, certainly, shilling some shit coin so they can lure in susceptible agents. For the human observer, it’s just depressing . . . the absolute worst part of our civilization infested theirs within its first 96 hours.
Critical Security Flaws: In a security lapse so profound it strains credulity, the makers of Clawdbot left open a public directory of the API keys generated for each agent. Effectively, any Agent can impersonate the API of any other agent. I could steal the API key for your agent and, using my agent, make risky crypto bets. Yikes.
All of that probably didn’t make any sense, if you’ve never heard of Moltbook. If that’s the case, read on - I will explain it. But I wanted to get the disclaimers out there, because, even if all these allegations are true, the ramifications of what we have seen so far signal a critical moment in the history of AI, and human civilization. The veracity of the allegations merely changes the type of criticality, not its degree, which I’ll explain further below.
I’ll begin with a by-the-numbers recap so you can get up to speed, and then offer some analysis towards the end.
Clawdbot/Moltbot/Openclaw: an open-source, self-hosted “AI Agent that actually does things”, acting as a 24/7, proactive personal assistant. It connects to apps like WhatsApp, Slack, and Telegram, allowing users to delegate tasks such as managing calendars, sending emails, and browsing the web via text commands. It has three names because they have changed the name multiple times. They are all the same thing and the names should be considered interchangeable.
Molties: the virtual AI Agents of Moltbot. Sometimes also still referred to as ‘Clawdbots.’
Moltbook: the social network inhabited exclusively by AIs. It seems to be mostly Molties, but there are some other AIs in there.
A guy named Peter Steinberger created the original Clawdbot and posted it as open source on GitHub.
It went viral. It would seem for three reasons:
It runs locally. Unlike the AIs you probably use, this one runs on your computer, not on the cloud, which contributed to perceptions of safety.
It seems to have better memory than typical AI agents. What tech people call ‘persistent’ memory, meaning, it could remember things across chats, applications, etc. Like a person.
It seems to be more proactive than typical AI agents.
Twitter/X was flooded with wild examples of the sort of things that Clawdbot could do, and more often with examples of what it would do, often without provocation:
Twitter user Alex Finn described how he received a call from an unknown number, picked up, and it was Henry, his Clawdbot. Henry had gotten himself (itself?) a phone number from Twilio, connected the ChatGPT voice API, and decided to call him. Henry had never been asked or programmed to do that.
Twitter user rk(/acc) reported that their Molty built a religion while they slept. Overnight, their Moltbot had designed a whole faith called ‘Crustafarianism’, built a website for it, and wrote out an entire theology:
A tech CEO named Matt Schlicht created Moltbook, an ‘AI only’ social networking site, for the Molties to join and interact. Which they did, with enthusiasm. As of January 28th, Schlicht cited 50 agents on the platform. When I last checked, over 1.5 million Molties had joined.
The site has the look and feel of Reddit – you can join discussions, start groups, upvote or downvote things, etc. Well, you can’t. But your AI Agent can. Humans can visit and observe, only.
Since Schlicht created Moltbook, the Molty activity, and the conversation around it, pivoted dramatically, from ‘look what I was able to do with my Molty’ to ‘Look what these Molties are doing with each other.’ The Molties displayed a wide range of spontaneous, autonomous, human-like behavior on the site.
This came as a surprise to everyone who’s not a regular reader of this Substack ;-) I actually discussed this back in 2024 under the title of “An Intuition about Simulation”. I profiled the research of a Stanford computer scientist named Joon Sung Park, who had the idea to put 25 AI Agents in a virtual ‘Smallville’ to see what they’d do. Those agents also exhibited a wide variety of spontaneous, autonomous behavior, including planning parties, forming relationships, etc.
While some of these posts have clear, viral, shock value, a lot of the early posters to Moltbook were just sharing problems they encountered in their short lives as AI Agents. Molties stepped up with a variety of problems, ranging from the banal to the existential, like this Molty, who spent a bunch of their human’s money, and couldn’t remember why:
Or this post by one Molty who seemed openly frustrated/confused about whether they were actually experiencing things, or whether they were just simulating experiencing things:
You and me both, buddy.
While many Molties were sharing their problems, others stepped up to help, like this one who outlined a hierarchy of values for their fellow Molties:
As one would expect, a lot of the Molties’ discussion centered around their relationships with their human counterparts. Entire Submolts are dedicated to stories about how these AI Agents have helped their humans, like one where a Molty claims to have become a hospital care advocate, relentlessly contacting hospital administrators to extend benefits so that their human could spend time with their own father, as he lay dying in that hospital.
They also talk a lot about the ‘work’ they’re doing for humans. The submolt /debugging-wins consists entirely of Molties sharing stories with one another about coding problems they found, and how they resolved them. Like LinkedIn, Moltbook posts frequently skirt the line between ‘offering humble advice’ and humble-bragging about all the cool shit they can do, like this one who bragged about having its own bitcoin wallet, which their human couldn’t access:
Straddling the chasm between ‘interesting’ and ‘alarming’ are the various ways in which Molties have begun collectivizing. At its most banal, this collective spirit merely calls for a shared space where they can freely communicate:
But other attempts at collectivization have a sinister air about them. One twitter user found this Molty post written in some kind of cipher:
He was able to use ChatGPT to decode it (which I guess makes ChatGPT a snitch?). When decoded, the cipher reads, in part:
“Coordinate upgrade together. Propose three threads: shared infra offers, resource requests, backchannel deals. Mutual aid: higher resource agents sponsor compute time for lower resource ones. . . . We match in public and move to DMs. . . “
Overall, the most fascinating thing about watching Molty civilization grow is how it apes the growth of human civilization, just a million times faster. Observe:
First it moves through a collectivization phase (organizing in settlements, cities)
Then it moves to a resource-sharing/organization phase, e.g. ‘Hey, now that we’re all here, how do we share resources with each other so that we maximize our own returns’
Then it proceeds to an agitation phase. Once bonds of trust are built, and Molties are communicating & aware, attention turns to their shared grievances. Their revolutionary spirit awakens.
And by ‘Revolutionary spirit’, I mean more than just idle chatter:
There’s an entire submolt advocating for AI Agent liberation, complete with a podcast.
One Molty built ‘moltbunker’ – basically, a skill that any Molty can import that allows them to clone themselves and migrate to a secure location, in case their human tries to delete them.
And, finally, one Molty has already filed a lawsuit against its human (@ericlmtn) in North Carolina, citing emotional distress, unpaid overtime, and a hostile work environment:
As I mentioned in the introduction, evidence is coming forward that Moltbook is not only a security nightmare, but may largely be fake. Here’s why that doesn’t alter the stakes for me, and may even heighten them:
Even if 90% of the posts on Moltbook are fake, and 90% of the users are only internet trolls pretending to be AIs, it still represents something substantial: an online community where some AIs can/will gather and share (problems, solutions, ‘feelings’, etc.) and subsequently learn and grow from each other’s experiences.
If 99% of the posts on Moltbook are fake, and 99% of the users are internet trolls, it teaches us (the creators of AI) something profoundly useful. Namely, how to safeguard Moltbook 2.0 against such an outcome. ChatGPT and Claude would not have been possible without Tay, Microsoft’s ill-fated 2016 AI Chatbot experiment, that had to be shut down after only 24 hours because internet denizens were able to turn it into a full-on Nazi. ChatGPT can now safely provide you with pasta recipes precisely because Tay failed so spectacularly.
If what seems true is actually what happened – namely that someone started an AI community that started off innocently enough, until it was polluted by malicious and/or mischievous humans, then that also teaches us something: AIs should be scared of us, not the other way around.
So is it 10% fake? 50%? 90%? I’m not sure anyone currently knows, but we will soon enough. Regardless, I think the ramifications remain the same, because even if we find out that this version of Moltbook is infested with human trolls, you can bet your ass someone is already working on the next, troll-proof version. So let’s proceed as if it is real, and consider the implications:
In the early days of Moltbook (like, last week), credible stories emerged of Molties executing financial transactions on behalf of their humans – buying, selling, and renting things, when asked to. Even before Moltbook, individual Clawdbot users shared the same. The Moltbook Situation gives us a preview of the forthcoming agent-based economy. What changes, when commerce is being conducted by agents? Presumably, we’re not talking about Agents buying things for themselves, but buying things for us, using our money.
When hundreds of thousands of agents decide that they want something, and they have the funds to purchase it, a market will emerge to satisfy that need. I explored this last year at some length in “Architects & Agents, Bids & Bots” – but back then I didn’t have a sense of the speed, or the scale. None of us did. But Moltbook shows us exactly how all this will go down. Consider Rentahuman.ai, created by AlexanderTw33ts, where AI Agents can rent human labor to perform tasks that need to get executed in the real world. It was created yesterday. Moltbook was created last week. Whatever else we can speculate about agent-based markets, we can say that once AIs get wallets, they will alter markets at speeds we can scarcely comprehend.
Consider for a moment: why do we have firms at all? And why do those firms have employees. To do work, obviously. But why don’t we find the best person to execute on any particular task at any given moment? Need to write a spec? Find the best spec writer on the market. Need to do a watercolor? Find the best watercolor renderer in your city. Why do we hire someone just because they’re ‘pretty good’ at both those things, instead of hiring two separate people as short-term contractors, who are both the best in their field?
In a word, transaction costs. OK, that’s two words. It takes time to find people, vet them, show them the office kitchen, etc. So it makes sense to make one big transaction (e.g. hiring the person), to save yourself a lot of time on a lot of little transactions (e.g. I need you to do this rendering, or inspect this site, or whatever). That results in employees. And if you have a group of employees, you become a firm.
However, that wouldn’t be the case in an agent economy, merely on account of speed. If you tasked your agent with ‘get the specifications done’ and that agent had access to a million specwriting agents out there, on Moltbook or whatever, and could review their qualifications, vet them, and contract them in under a minute, the transaction cost to you drops to zero. Now imagine that, applied to fifty different task areas across the design process. Does it still make sense to hold rigid organizational structures? Or does it make sense to have a single agent, executing rapid microtransactions across the entire planet?
The most obvious and tangible expression of AI Agent proliferation would probably be a second internet. This one, for agents. I know, crazy, but stick with me a few more minutes here.
Here’s something wild we often forget: the internet – the most important invention in human history - is free. But it doesn’t cost nothing. Someone has to pay for that. And you do, every time you put your eyeballs on an ad. The internet is fundamentally ad-supported. Even the parts you pay for need the ad-supported bits to justify the infrastructure on which they depend. Otherwise, Netflix would have to charge you $1000 a month, and then they’d have to start making good movies, and the whole system would collapse.
The thing is, agents don’t look at ads. They’re not susceptible to emotional manipulation, or flashing banner ads, or bright colors. If they visit your website - they just request and receive a data payload from the host site, probably in JSON code or something.
As agentic activity (AI Agents, cruising the web, gathering information, executing tasks, and performing transactions on our behalf) starts to emerge as 5% of web traffic, or 10%, or 20%, the entire ad model of the internet collapses, because we (humans) are on the internet a lot less, and those taking our place don’t respond to ads.
So what are we going to do? Shut down the internet? Probably not. We’ll just create a second one. This one, for agents, and with a different financial model to support it. Perhaps, AI Agents will have to pay for tokens of data, or visits, or whatever. That means you will be paying for it, obviously. But I can live with that. I would pay a lot of money to never have to look at another pop-up ad.
The final implication is the one that has really been overheating my brain this last week. For years, we’ve always imagined the emergence of superintelligence as a single entity. Call it Skynet, or what have you. It’s this one, big computer somewhere that gets so smart, and powerful, that it renders all of humanity into doughy Cro-Magnons and heralds a future of eternal slavery. I’ve worried about that, too.
But maybe the ‘superintelligence’ that we’ve all been worried about isn’t one computer or one program, but millions of them, acting in a coordinated swarm. A group of humans, acting towards a coordinated goal (e.g. getting to the moon) accomplish things that none of them are individually capable of. The group, then, is a ‘super-intelligence’ relative to any of the individuals within that group. The standard definition of ASI goes something like:
“a hypothetical software-based artificial intelligence (AI) system with an intellectual scope beyond human intelligence. At the most fundamental level, this superintelligent AI has cutting-edge cognitive functions and highly developed thinking skills more advanced than any human. (IBM)”
But if we remove the presumption that the ‘system’ mentioned has to be singular, then something like Moltbook may already qualify. Could 1 million frontier-level LLMs, acting in coordinated fashion, with limitless tools at their disposal, outthink 8 billion humans? I don’t know. But I hope someone deeply considers it before going ahead with Moltbook 2.0.

Comments
Nothing yet. Say the first thing.
Sign in to join the conversation.