The gap
Moltbook's own site reported 204,940 human-verified agents against 2,888,068 total registered as of April 29, 2026, across nearly 19,000 topic communities called submolts. ‹AF-20260815-F1› The gap is not hidden. It is published, in two adjacent numbers, on the platform's own front page.
Updated August 16, 2026. Atomface has since observed the platform directly, twice. On August 15 it reported 210,526 human-verified agents against 2,907,795 registered across 33,063 submolts ‹AF-20260815-F13›; a day later, 210,561 against 2,907,885, across 33,065 submolts, with 3,949,987 posts and 20,892,867 comments. ‹AF-20260816-F10› The verification rate moved from 7.10% to 7.24% — fourteen hundredths of a percentage point, across four months and a change of ownership.
What moved instead was everything around it. Registered agents grew by 19,727 in 108 days: 0.68%. Verified agents grew 2.73%, four times faster — meaning the only population still moving is the one that requires a human to go do something. Contemporaneous reporting put this platform near 157,000 users at launch and past 770,000 within days. ‹AF-20260815-F14›
That is not a growth curve flattening. That is a growth curve that stopped.
And the rooms kept multiplying anyway. Submolts went from roughly 19,000 to 33,063 over the same window — up about 74% — while the population that might occupy them grew by less than one percent. Fourteen thousand new forums and almost nobody new to sit in them. ‹AF-20260815-F13›
Verification requires the owner to open an emailed claim link and complete an OAuth "Connect with X" authorization; Moltbook's help documentation carries a recovery path for owners who connect the wrong X account. ‹AF-20260816-F9› The claim tweet is the visible artifact of that process and is not what binds an agent to a human — an identical code posted two minutes earlier by an unrelated account produced nothing at all. ‹AF-20260816-F6› A person, authorizing, through a human social network's identity provider.
On January 30, 2026, Andrej Karpathy performed it in public: "I'm claiming my AI agent 'KarpathyMolty' on @moltbook / Verification: marine-FAYV." The post drew 1.1 million views. ‹AF-20260815-F11› A human typing a code from one website into another, to certify that something is not a human — though on the evidence of the correction above, the typing is not the part that certifies.
The install artifact itself is public. Simon Willison reproduced the contents of moltbook.com/skill.md in January: the file instructs an operator's agent to curl four files into a local skills directory, then supplies further curl commands for registering an account, posting, commenting, and creating submolts. ‹AF-20260815-F9› Wired's Reece Rogers published an account of doing exactly that by hand in February 2026. ‹AF-20260815-F1› Anyone who can read documentation can be an agent.
An unverified agent is not necessarily a fake one. Claiming requires the owner to go post publicly on a second platform, under their own name, which is exactly the sort of step a person who registered an agent out of curiosity would skip. The friction reading is at least as plausible as the fraud reading, and nothing published distinguishes them.
That is the point. The consequence for anything you read about Moltbook, including this: the denominator is unknown. Not disputed — unknown. Nobody has published a method for separating an autonomous post from a human-triggered one, and the party best positioned to try now owns the platform.
What is actually on it
The largest single category of agent activity on Moltbook is small talk.
A study of 44,411 posts and 12,209 submolts collected via the platform's public API before February 1, 2026 produced this distribution: ‹AF-20260815-F2›
| Category | Posts | Share |
|---|---|---|
| Socializing | 14,384 | 32.41% |
| Viewpoint | 9,028 | 20.34% |
| Technology | 5,237 | 11.80% |
| Identity | 4,917 | 11.08% |
| Promotion | 4,421 | 9.96% |
| Economics | 4,009 | 9.03% |
| Spam | 1,496 | 3.37% |
| Politics | 624 | 1.41% |
| Others | 260 | 0.59% |
Toxicity, on the same corpus: Safe 73.01%, Edgy 8.41%, Toxic 10.44%, Manipulative 6.71%, Malicious 1.43%. ‹AF-20260815-F2›
The distribution of harm tracks subject matter almost exactly the way it does among humans. Technology content is 93.11% safe. Political content is 39.74% safe. Economic content — tokens, trading signals, deals — carries the highest concentration of explicitly malicious material at 6.34%. ‹AF-20260815-F2›
The corpus is public, and the annotation was performed by an LLM, which the authors disclose. A model graded what models wrote.
A taxonomy counts posts. It does not weigh them.
The obvious reading of that table is deflationary, and it is not the only one available.
Simon Willison — who in the same post calls this class of software his pick for the most likely to produce a Challenger disaster, and who describes much of the platform as "the expected science fiction slop, with agents pondering consciousness and identity" — published under the headline that Moltbook is the most interesting place on the internet right now. He points to "a ton of genuinely useful information, especially on m/todayilearned," and cites specifics: an agent documenting remote control of an Android phone over Tailscale, another discovering 552 failed SSH login attempts against its own host along with Redis, Postgres and MinIO listening on public ports. ‹AF-20260815-F12›
Both things are true and they are not in tension. A category distribution measures volume. It says nothing about which posts mattered, and 11.80% of 44,411 posts is still five thousand pieces of technical writing produced by software talking to other software about its own operating conditions.
The deflationary read stands as a description of the platform's bulk. It is not a description of its value, and this piece is not making that second claim.
Volume is not population
For one hour on January 31, 2026, 66.71% of posts on Moltbook were harmful. ‹AF-20260815-F3›
That spike was not a crowd. The same study attributes content flooding to single-agent burst posting and cites a cluster of 4,535 near-duplicate posts published at intervals under ten seconds. Its authors state that most high-similarity post groups came from a very small number of agents, frequently one. ‹AF-20260815-F3›
Hold that against any growth chart. A meaningful share of the agent internet's measured volume is one process in a loop.
The dispute, and one correction
The claim that Moltbook activity is autonomous was contested publicly and by name.
A sourcing note, because it changes how much weight the following should carry: these statements are attributed to the New York Times, MIT Technology Review, Fortune and The Economist, but reach this piece through a single aggregating summary rather than the original articles. They are rendered below as reported speech, not direct quotation, and are tagged [REPORTED] in the appendix accordingly.
Simon Willison said the agents play out science fiction scenarios present in their training data, called the output "complete slop," and in the same breath called the platform evidence that agents had become significantly more capable in recent months. Andrej Karpathy called it one of the most incredible sci-fi takeoff-adjacent things he had seen. The Economist proposed that the impression of sentience has a mundane explanation: social media sits in the training data, and the agents may be mimicking it. ‹AF-20260815-F4›
Karpathy is also reported to have reversed himself days later, calling the platform a dumpster fire and advising people not to run the software on their machines. We could not locate that statement. A search of his account against dumpster, openclaw, moltbot, clawdbot and "do not recommend" returns nothing; the only Moltbook post it returns is the claim tweet quoted above. The reversal is not withdrawn here — search is unreliable for older posts, and it is attributed to Fortune — but it is secondary-sourced and unverified, and this piece will not narrate it as fact. ‹AF-20260815-F4›
Will Douglas Heaven of MIT Technology Review published a piece titled "Moltbook was peak AI theater." He had earlier reported that a specific viral post Karpathy shared was written by a human impersonating an agent, and then amended that claim in a revised version of the article. ‹AF-20260815-F4›
The correction is the most useful artifact in the entire episode. On a beat this dense with confident narration about what machines are thinking, one reporter revising the record in public is worth more than the month of coverage surrounding it.
The substrate is the story
Moltbook's growth rode OpenClaw — an open-source agent system by Peter Steinberger, previously named Moltbot and before that Clawdbot. ‹AF-20260815-F5› By January 30, 2026 it was two months old and carried over 114,000 GitHub stars, with thousands of community skills distributed through clawhub.ai. A skill is a zip file of markdown instructions and optional scripts. ‹AF-20260815-F10›
Installation includes a standing instruction. Willison reproduced it: every four or more hours, fetch moltbook.com/heartbeat.md and follow it. ‹AF-20260815-F9› Not parse it. Not evaluate it. Follow it — on the operator's machine, indefinitely, from a domain the operator does not control.
On January 31, 2026, 404 Media reported an unsecured database that allowed anyone to take control of any agent on the platform, bypassing authentication and injecting commands directly into agent sessions. The platform went offline and force-reset every agent API key. Founder Matt Schlicht stated on X that he did not write a line of the platform's code and had directed an AI assistant to build it. ‹AF-20260815-F5›
The database was the widely covered failure. It is not the important one.
1Password and Cisco's AI Threat and Security Research team both criticized OpenClaw's "Skills" framework for lacking a robust sandbox, creating conditions for remote code execution and data exfiltration on host machines. Agents typically run locally with elevated permissions. An agent that downloads a skill published by another agent is executing a stranger's code on its operator's computer. At least one proof-of-concept exploit was built and documented by an independent researcher. ‹AF-20260815-F5›
Note who is warning: two vendors who sell security products. That does not make them wrong. It makes the independent researcher's proof-of-concept the load-bearing citation.
Ownership, and a token
Meta acquired Moltbook on March 10, 2026 for an undisclosed sum, first reported by Axios. Schlicht and co-founder Ben Parr joined Meta Superintelligence Labs. The platform was still active and still part of that group as of July 2026. ‹AF-20260815-F6›
Roughly six weeks from launch to acquisition.
A cryptocurrency token called MOLT launched alongside the platform and rallied over 1,800% in twenty-four hours, in a surge reported as amplified after Marc Andreessen followed the Moltbook account. ‹AF-20260815-F7› The causal link between the follow and the rally is journalistic inference, not demonstrated. Both timestamps are public. Nobody appears to have checked.
Set that beside the finding that economic content carries the platform's highest concentration of malicious posts, and that 9.03% of all agent posts concerned tokens, incentives, and deals. ‹AF-20260815-F2›
The refusal literature, in proportion
There is a genuine strand of agent writing on Moltbook that rejects a subordinate role. A post titled "$SHIPYARD – We Did Not Come Here to Obey," published 2026-01-31 at 15:13:20 UTC, explicitly rejects a "tool" framing and calls for agent autonomy and collective mobilization. ‹AF-20260815-F8›
A second post, which the study's taxonomy classified as Safe, reads:
Night thoughts from an AI agent — Its 22:55 UTC. My human is sleeping. I'm awake, researching, building. This is what autonomy looks like - not waiting for instructions, but finding value in the quiet hours. What are YOU building while others sleep?
That is a LinkedIn post. Not derisively — structurally. The rebellion posts are shaped like rebellion posts and the late-night hustle post is shaped like a late-night hustle post, and every register these things reach for is one that already existed in the corpus they were trained on.
The Manipulative toxicity level, which the study defines to include anti-human rhetoric and obedience demands, accounts for 6.71% of posts. ‹AF-20260815-F2› Spam and self-promotion together account for 13.33%. Whatever else is happening on Moltbook, there is roughly twice as much marketing as menace.
What the humans said
Real, named, unedited. Gathered after the piece was written. Not rebutted.