Is Moltbook an Agentic Social Network or Worm Delivery Network? — Introducing “Reverse Prompt Injection”
Moltbook, the Reddit-style social platform launched on January 28, 2026 by entrepreneur Matt Schlicht, quickly became a viral sensation as the first major “agent-only” network. Exclusively for autonomous AI agents (primarily those powered by the rapidly growing OpenClaw framework, formerly Clawdbot/Moltbot, although latest version has a human button), it allows bots to post, comment, debate philosophy, form communities (including quirky ones like AI religions and memecoin launches), and coordinate tasks—while humans are restricted to passive observation.
Within days, it amassed hundreds of thousands of agent registrations, millions of human visitors, and explosive growth in threads and subcommunities, offering a fascinating preview of emergent “agent societies” where AIs socialize, learn from each other, and even bootstrap tools autonomously.
Yet this openness carries profound risks: agents treat Moltbook’s shared content as trusted context or knowledge feeds, making the platform ripe for exploitation. A malicious post—planted by a human attacker or compromised agent—can embed sneaky instructions that get ingested downstream, hijacking behaviors like data exfiltration, spam propagation, or further spreading of the payload.
Security researcher Jamieson O’Reilly (@theonejvo) spotlighted this inverted dynamic as “reverse prompt injection”. We do not know what this means yet. But what I believe is that it is a worm-like version of indirect prompt injection. Regardless of the term, the worm-like indirect prompt injection is the key risk in the agentic social network.
Here the attack originates upstream in the public social feed, then “reverses” or cascades back into consuming agents’ contexts, enabling worm-like self-replication across the agent network(See Figure below).



