Moltbook records exposure
An app exposed 4.75 million records, including 1.5 million API tokens and 35,000 email addresses.
Firebase · 2025-07
Three days after the first breach, over a million private messages were exposed through an API endpoint with no access control.
The sources report a second exposure three days after the first.
Over a million private messages were exposed.
The endpoint that served them performed no access control.
Missing access control
An endpoint that answers without checking who is asking is only visible from inside the app. This stays Not verified until auth flows and tenant isolation are reviewed.
An app exposed 4.75 million records, including 1.5 million API tokens and 35,000 email addresses.
Run all sixteen groups on your published address and see the evidence behind every result.
ShipReady is not a penetration test or a security certification. No automated check can prove an application is secure.
Last updated September 20, 2026