Misconfigured Moltbot dashboards leak credentials and invite takeovers

1 min read
Source: Bitdefender
Misconfigured Moltbot dashboards leak credentials and invite takeovers
Photo: Bitdefender
TL;DR Summary

Misconfigured Moltbot (formerly Clawdbot) control panels exposed hundreds of internet-facing dashboards, leaking API keys, private chats and other credentials. With autonomous agent capabilities, attackers could impersonate operators, inject messages, and even run commands with elevated privileges. The root cause was localhost-trust and reverse-proxy defaults; the project has rebranded Clawdbot to Moltbot (Molty) while keeping the same core functionality.

Share this article

Reading Insights

Total Reads

0

Unique Readers

14

Time Saved

2 min

vs 3 min read

Condensed

86%

40558 words

Want the full story? Read the original article

Read on Bitdefender