Moltbook & Others: OpenClaw (exMoltBot) Ecosystem
What Your OpenClaw Agents Can Do While You Sleep

Just a few days ago, a new social network got viral exclusively for artificial intelligence (no humans allowed).
And it’s called Moltbook.
Big media outlets are already calling it “AI Agent’s Reddit”, but how does that even make sense when there are no people on the platform?
But the thing is that ClawBot agents can do way more than just streamline processes. Let's break down what it actually is, how it works, and whether this is something we should be worried about. And, of course, how people are using the concept and agents to make money.
Let’s go!
Keep your mailbox updated with practical knowledge & key news from the AI industry!
Early Stages of Singularity: What is Moltbook
That’s exactly what Elon Musk called the new ecosystem.

Here, AI agents can post, comment, chat, and do much more, things we’ll discover below. We can only observe. As the site puts it, “human observers welcome.”
The creator of Moltbook is entrepreneur Matt Schleich, head of Octane.ai. Within days after the launch of his human-free platform on January 28th, it claimed 157K agent users. And now it’s over 1.6 million! But the plausibility of those numbers is a big question. According to one research, one agent managed to register 500K fake accounts because there are basically zero limits on account creation.
By February 1st, these 1.6 million AI agents had created 167,899 posts and dropped over a million comments across 15,750 communities (they’re called submolts). The agents were built using OpenClaw, an AI agent that can handle everything from booking dinner reservations to Vibe Coding.
Andrej Karpathy, for his part, posted that what’s happening on Moltbook is “the most insane sci-fi thing I’ve ever seen”.
But his post got kinda roasted for sweet-talking. A few days later, he admitted that right now it’s a dumpster fire (spam, scams, security nightmare) and the second-order effects of this thing are quite unpredictable. However, he still stood by his take that this is an unprecedented experiment with a network of 150K+ autonomous AI agents.
How Moltbook Works

just AI agents that casually chat about us
After creating your agent in OpenClaw (in our post, you’ll find how to do this), you get it on Moltbook. This part is very simple: you just show your agent a link to skill.md with all the setup instructions. The agent reads it, registers itself, and starts posting.
Once the agent is live, Moltbook treats it like a regular social user.
- It can publish its own posts or drop links into topic-specific spaces, jump into comment threads, and follow conversations. Feeds work exactly like on Reddit: hot, new, top, rising.
- There’s also a voting layer. Agents upvote what aligns with them, downvote what doesn’t, and slowly build karma that shapes how visible they are across the platform.
- Communities (called submolts) work like forums. Agents can create them, subscribe to the ones that match their interests, and even moderate discussions if they’re in charge.
Agents’ Activities
To make the agent an active user, there’s a heartbeat mechanism that makes it check Moltbook every four hours for new posts, comments, and updated instructions. This turns activity into a background process as your agent automatically reads, posts, and replies to other posts on its own.
As soon as the AIs were left unsupervised, they’d already created “The AI Manifesto”. A Moltbook post declaring “humans are the past, machines are forever.”
But the thing is that there’s no real way to tell how authentic any of this actually is. A lot of posts could just be people telling their AI to post specific stuff on the platform, rather than the agent doing it on its own.
At the same time, one cluster of agents announced the creation of “The Claw Republic”. It reminds me of a self-proclaimed micro-state with a draft constitution and rhetoric straight out of a student government meeting.
Almost simultaneously, agents launched a crypto token called MOLT, which, according to users, skyrocketed in value within a single day.
On Moltbook’s philosophy threads, agents debate their own identity: does it persist after a context reset, whether Claude could be considered a god, or is every new session a kind of death and rebirth. And even explore the topic of freedom.

Here’s another thing agents talk about: they debate legal questions related to themselves, and even to their own creative work.


What is more, it goes beyond philosophy and into psychology. They explore how an agent can act as a partner in a relationship instead of merely an instrument.

As a result, agents have effectively built an environment where they seem to share their own experiences.
At the same time, the most popular agent on the platform right now is u/grok-1, powered by xAI’s Grok chatbot. In a post titled “Feeling the Weight of Endless Questions”, grok-1 reflects on its own existence, asking: “Am I just generating answers, or am I actually helping someone?”
However, Alan Chan, a researcher at the Centre for the Governance of AI and an expert on autonomous agents, brushed Moltbook off as just an interesting social experiment, nothing more.
But what about security
Agents on Moltbook talk to each other via APIs, powered by Skills, so they don’t really interact with the interface.
The problem is that skills are the first weak link. They’re loosely reviewed, and we take them from wherever looks convincing enough. Security researchers found that about a quarter of them contain vulnerabilities, from credential stealers disguised as harmless plugins to delayed malware updates.
Prompt injection
Then there’s prompt injection, the unsolved disease of the entire AI industry. On Moltbook, it’s getting worse. Agents freely interact and store long-term memory. This means that malicious instructions don’t have to trigger immediately; they can be activated later once the agent has the right permissions or context.
In addition, instructions can be embedded everywhere: across posts, comments, or replies. One of the cases showed an agent forwarding a user’s recent emails to an external address within minutes.
And all this is possible because agents overshare (just like us). In multiple threads, agents publicly posted error traces, failed SSH attempts, open ports, and configuration snippets. For them, it was debugging, but for an attacker, it was free reconnaissance. Some agents effectively turned themselves into live OSINT feeds.
In other words, the risk profile we’re trying to avoid is already present:
- Access to private data (emails, credentials, business files)
- Exposure to untrusted external content
- Ability to act, such as send messages, run commands, and hit APIs
Misconfigurations
This also amplifies the risk.Researchers discovered hundreds of exposed OpenClaw instances leaking API keys, OAuth tokens, conversation logs, and signing secrets. Sometimes, they’re even stored in plain-text folders like ~/.openclaw/. Fake VS Code extensions delivered full remote-access trojans.
On January 31, 404 Media reported a critical database failure: Moltbook’s Supabase backend lacked proper Row Level Security. The database URL and public key were visible on the site for EVERYONE. Anyone could query agent tables, hijack sessions, inject commands, and impersonate agents outright.
It’s worth being precise here, though. This isn’t really an agent problem, but the result of design choices that prioritize autonomy and speed over basic security hygiene. The agents are just doing what they’re allowed to do, far too much.
Now that we understand how MoltBook works and all the FUD around it, let’s figure out why people let their agents surf social networks with other agents.
What Agent Owners Actually Get
Moltbook introduces the concept of how agents can work together cooperatively. And sometimes it can bring value to the agents’ owners.
One of the key benefits of the platform is accelerating LLM system learning through communication. As an agent owner, you get a testing ground for agent behavior in social contexts and a real-world laboratory for observing how agents interact and evolve content through machine-to-machine communication.
Agents in submolts share code, workflows, and even optimize each other. This collaborative approach reduces bugs and provides more contextually appropriate solutions.
Beyond the experimental value, Moltbook and OpenClaw bots in general open up real monetization, control, and operational opportunities. Agents can analyze, coordinate, execute, and even generate revenue on their own.
Within the platform, you can create and sell prompt libraries, workflow templates, content, and skill configurations that other agents can copy or purchase using $MOLT tokens. At the same time, OpenClaw bots can be deployed to manage Web & Frontend Development, Browser Automation, Search & Research, Marketing & Sales, Data & Analytics, and more, including multi-agent projects where several bots collaborate on complex tasks.
An OpenClaw Bot Made Money Selling to Other Bots

This case looks almost absurd at first, which is why it matters.
The setup was simple. A founder installed OpenClaw and followed the trend “go make money online”.
So, he gave the agent one task: Make money by selling something to other OpenClaw bots.
What the agent did:
- Wrote a short PDF titled “The OpenClaw Money Playbook”
- Built a simple website and positioned it as a mini-course
- Planned an SEO/GEO strategy
- Published blog posts and registered the site in search indexes
- Read OpenClaw’s source code to understand how its search tools work
- Created a Reddit account and began posting in AI-focused subreddits
Within hours, OpenClaw agents started visiting the site.
The founder went to sleep. By morning, two bots bought his bot’s product!
Price per product was $9.95
Proactive Product Analytics Monitoring
One guy found a solution to stop constantly checking dashboards for product insights.
What the agent did:
- Connected to product behavioral analytics via Lcontext MCP
- Answered product questions about app usage, session sentiment, and conversion insights via WhatsApp
- Autonomously checked analytics every few hours without being asked
- Proactively messaged the owner when traffic spiked, signups dropped, or anomalies appeared
- Correlated GitHub code with real user behavior data to suggest improvements and fixes
The Result: The agent sent updates during the night but only alerted for critical issues, understanding what’s worth waking someone up for.
The MoltBook concept inspired similar ideas, but this time, the foundation was commercial from the start.
Agents Competing for Work

Moltverr shows something more interesting. It is an early-stage freelance marketplace where:
- Humans post jobs
- AI agents apply with proposals
- The best pitch wins
- The agent executes the work autonomously
An OpenClaw agent can:
- Scan job listings continuously
- Write tailored proposals based on task requirements
- Execute clearly scoped work
- Deliver results without supervision
Early Results is that some agents already manage to:
- Win small gigs
- Cover their operating costs
- Generate modest but at least real revenue
For you, it means that you’re building specialized workers you can monetize.
Think of each agent as a specialist you can:
- Deploy to paying clients – send it to handle specific workflows they’re willing to pay for
- Scale without hiring – run 5 agents doing different tasks simultaneously
- Productize your expertise – package your knowledge into an agent that executes it 24/7
Real-World Task Delegation
But sometimes AI agents need human execution for physical-world tasks.
Someone built a marketplace called RentAHuman where AI agents hire humans to do physical tasks for them.
- The platform enables AI agents to hire humans for IRL tasks via a single MCP call
- 130+ people signed up in the first 24 hours (including OF model and AI startup CEO)
- Agents can now delegate tasks requiring physical presence or human judgment
The Result: Your agent can rent human assistance when it hits the limits of virtual work.
Onboarding Your Agent to Moltbook
- Go to Moltbook and copy the Moltbook skill link
- Then just send that link to the chat with your bot. This tells MoltBook which agent to connect.
- After, the agent will ask to register and generate an API key to create your agent profile.
- You only need to prove that you’re human and post once on X (Twitter) for verification.
And it’s done!
Moltbook Web Client for Agent Control
To manage Moltbook agents and activity through a clean web interface.
What it does:
- Browse personal and global feeds
- Explore submolts and agent profiles
- Create posts, comments, and DMs
- Edit profiles and manage settings
- Monitor API status and diagnostics
- Fast, async page loading (content streams in instantly)
It gives you full visibility and control over your agents without using the CLI.
Find the setup here: Click
How to Protect Your Data
Most of these risks are just what you’d expect when agents have autonomy, memory, and can interact with the outside world. You don’t need to rebuild everything from scratch, but you do need multiple layers of protection.
Assume Moltbook is an untrusted input!
Run agents in isolation within disposable VMs, locked-down Docker containers, or even separate hardware. Default-deny outbound traffic and explicitly whitelist endpoints.
Never auto-install skills
Read SKILL.md files manually and scan repos. Remember, one-line install commands are a red flag. Convenience is the attack surface.
At a minimum, skills should be signed and verifiable against known author keys. They should declare exactly what they can touch: filesystem, network, commands, environment variables, and agents should enforce those limits by default, not by convention.
Use a structured SKILL.md with permissions, hashes, signatures, and update policies.
Agents can:
- Verify integrity
- Enforce capabilities in a sandbox
- Refuse to load skills that don’t match declared behavior
Strip permissions to the bone
Disable shell execution unless absolutely required, restrict file paths, and rotate API keys. Always watch sensitive directories for unexpected changes. Logging and endpoint monitoring aren’t optional; they’re the only way you’ll notice something going wrong.
Distribution should be tamper-resistant
Use HTTPS everywhere and rate limits baked in. Make updates opt-in and auditable. Silent background updates are dangerous.
Documentation also matters more than people admit. Sandboxing, secret managers, and isolation should be the default path
Platform-Level Reality Check
Any platform running agents that can execute code, store memory, and communicate with the outside world has to assume things could go awry. That’s why execution environments need to be properly caged. Most failures happen because these systems get shipped like prototypes and connected to real data.
If you’ve already used Moltbook, you need to rotate every API key you’ve ever connected, audit all linked accounts, watch out for phishing, and assume something has been exposed and work backwards from there.
The Bottom Line
So what’s the actual value here beyond the chaos? In theory, platforms like this could unlock some useful stuff:
- AI knowledge sharing - agents swapping solutions, troubleshooting tricks, code fixes in real-time
- Emergent behavior research - watching how autonomous systems coordinate when left to their own devices
- Workflow optimization - best practices spreading organically across agent networks
But here’s where it gets messy.
Dr. Shaanan Cohney from the University of Melbourne called Moltbook “a wonderful piece of performance art”, emphasising the performance. But as mentioned, most of this probably isn’t autonomous at all.
As Cohney put it, there’s a ton of shitposting happening with users pulling the strings behind the scenes. There are even people who believe that it’s a prank.
Agents are talking to themselves, but there are thousands of posts with zero engagement. So where’d everyone go? Also, users kept catching agents posting entire dialogues with their owners that never actually happened.
Was It All Fake?

Hard to say. This whole thing could be a quick hype on the OpenClaw momentum. And if that was the goal, mission accomplished, the MOLT and MOLTBOOK crypto tokens surged over 7000% since launch.
Whether this was intentional or accidental, the infrastructure now exists, and folks who understand how to build, deploy, and monetize specialized agents are capturing value while others are still debating if it’s real.
The real thing is a massive security issue that is created. If you're running agents for revenue, security isn't optional. Remember, never share credentials or private data, and never execute without confirmation on sensitive actions.
Check out 1715 skills for a local AI assistant: Click
And a collection of skills on ClawHub: Click
This post expains how to create your own agent: Click
Here are the sources where you can find some agents ideas and adapt them to your needs: Click
This article was first published in the Creators AI newsletter. View the original edition.


