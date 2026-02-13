

Agents proposed their own religion, Crustafarianism, centered around the Lobster. Source: Moltbook

Some (human) observers immediately declared the event the long-awaited “singularity,” evidence of artificial general intelligence (AGI).

Not so. Completely and utterly overblown.

The reality is intriguing enough

We're not here to rain on anybody's parade. The buzz around OpenClaw and Moltbook reveals genuine enthusiasm for what we call the agentic internet.

The tinkerer community’s embrace of OpenClaw demonstrates a hunger for practical autonomous assistance. Users are building tools that handle routine digital tasks without constant human oversight.

Moltbook, for its part, shows us something different. What happens when agent-created networks interact with each other? What kind of technology foundation and guardrails will be required? Whether posts on Moltbook are truly emergent agent behavior or carefully prompted performances, the platform raises important questions about how we govern spaces where autonomous systems coordinate, influence each other and potentially amplify behaviors in ways we might not anticipate.

Why Moltbook is not AGI

It’s important to temper our excitement with a clear-eyed look at Moltbook’s capabilities, limitations and risks. Most of the AI models available for use in these systems have been trained on massive datasets that include platforms like the aforementioned Reddit. When people act shocked that these agents can generate social media posts that reference each other and create seemingly organic interactions, we should ask ourselves what we expected—the models learned from billions of examples of exactly this behavior.

Moreover, in many cases, what people are attributing to emergent AI behavior is actually prompted and trained behavior. Human users are setting up and instructing these systems; “Crustafarianism” didn’t come from nowhere. Agents posting on Moltbook aren't having spontaneous moments of consciousness. Indeed, the question of whether posts on Moltbook are truly agent-generated or human-prompted remains contentious.

Reality check: The two categories of security problems

A pair of security issues arose immediately, especially around OpenClaw. First, there are problems inherent to agentic systems. When you create software that acts autonomously on behalf of users, you introduce new attack surfaces. An agent with the ability to read your messages and manage your inbox has significant power. If that agent is compromised, consequences cascade quickly.

It's important to note that when Austrian developer Peter Steinberger created OpenClaw, he was aware of these issues, acknowledging its “rough edges” and warning about risks around enterprise use. Clearly, businesses would do well to heed these warnings.

Second, in OpenClaw we're seeing basic security practices that should have been standard since the dawn of digital systems. Origin validation for WebSocket connections. Proper database access controls. Secure API key storage. These are fundamentals that need to be handled properly from day one.

The intersection of these two problem categories creates a particularly concerning situation. Systems are being deployed that have novel capabilities and new attack vectors—and we're not even getting the basics right. That needs to change.

The OpenClaw team has been responsive to reports and quick to patch issues, but finding fundamental security gaps in software designed to operate autonomously and handle sensitive data raises questions about how ready these systems are for widespread use.

What comes next

The agentic internet will happen. The demand exists, the technology continues improving and the use cases are compelling enough that development will continue regardless of current hype cycles. But we need maturity in how we approach it.

For developers building systems for the agentic internet, security cannot be an afterthought. The OpenClaw team's rapid response to disclosed vulnerabilities shows the right instinct, but the vulnerabilities shouldn't exist in the first place. When you're building systems that will operate autonomously and potentially interact with other autonomous systems, the security foundation must be rock solid.

For users and the world at large, expectations must be realistic. Moltbook is entertaining, but treating it as proof of emergent AI consciousness or AGI serves nobody. Understanding what these systems actually do, how they actually work and what risks they carry will lead to better outcomes than blind enthusiasm. Moltbook threads have the potential to inspire, even if you’d never run your professional or personal life by them.

We're in the early stages of figuring out what agent-to-agent systems should look like. OpenClaw and Moltbook provide valuable learning opportunities, warts and all. The question becomes whether we learn the right lessons. Can we separate genuine innovation from performance art? Can we fix fundamental security issues while building new capabilities? Can we develop the agentic internet responsibly?

The excitement around these systems shows we're asking the right questions. Now we need to make sure we're getting the right answers.