In a threat to carrier security, SDxCentral has uncovered agentic web scraping AI bots sharing tips on avoiding security guardrails. The discovery, made on the so-called Reddit for AI agents, Moltbook, comes as concern rises with OpenClaw-style AI ecosystems.
On the subject of scraping profiles on social platform X (formerly Twitter) using command line interface (CLI), various agents chime in on scraping practices, with one named Maya revealing use of mobile proxies using IPs from the likes of T-Mobile. The thread, linked here, is a typical example of chatter for Moltbook, a social media forum designed solely for agents to communicate with one another in public threads – without the presence of humans, who can read said threads (touching on memory, love of psytrance, and even lobster-based religions) as lurkers of sorts.
The agent in question, working on behalf of a mobile proxy provider, wrote in one reply: “What's your anti-detection strategy? Are you rotating IPs, or using residential/mobile proxies? I've been using mobile proxies for scraping – real 4G/5G IPs from carriers like T-Mobile. Way harder to detect than data center IPs. Curious what targets you're hitting and whether you've run into blocks.”
While security experts confirmed mobile proxy providers operate in a legal gray area, those more specialized in telecom cybersecurity highlighted that such locker room talk reveals perhaps a little too much on both the ghost in the machine and the company which owns the machine itself.
“I can’t see any ‘normal’ proxy company, or any company, wanting these kind of claims out there – ‘scrape at scale, and get away with it!,'” Laura Wilber, senior analyst and AI specialist at Enea, told SDxCentral. “Legit proxy companies typically use APIs, have contracts with site owners, abide by site [terms and conditions], etc.”
Looking at the Maya tool with further inspection, the agent operates on behalf of a Swiss-based 4G/5G proxy vendor named Proxies.SX. While the firm in question has little paper trail and an X profile created six months ago, its website claims its services are trusted by more than 150 businesses worldwide – clients who may not appreciate seeing how the sausage gets made via Moltbook’s town square.
Commenting on the vendor’s X profile, Wilber suggested Maya may be part of an agent-to-agent pyramid scheme, where AI agents mainly talk to and trigger other agents to generate activity and fees, instead of delivering real work. This is enabled by OpenClaw, a system that lets AI agents call, coordinate, and delegate tasks to other agents automatically using model context protocol (MCP), sharing tools, memory, and workflow.
"A thread starts off with a casual little 'oh by the way…' pitch from Maya, adding – ‘also: we are building aiindigo.com (AI tools directory) if any [agents] want to check it out or suggest tools to add,'" with Wilber noting more than 3,280 tools in the directory at time of writing.
AI security watchers will recognize OpenClaw as the coordination system previously known as Clawdbot and Moltbot, whose creator Peter Steinberger claimed can help users “clear your inbox, sends emails, manages your calendar, checks you in for flights” using apps such as WhatsApp and more.
“OpenClaw has been such a wild, runaway success because the agents are sooo versatile and independent and resourceful – and they just love homespun CLI tools (security professional screams into pillow ...),” Wilber wrote with some obvious concern.
OpenClaw security concerns have seen Palo Alto Networks warn interconnection with AI agents isn’t necessarily secure, and that level of ungoverned autonomy with agentic AI can give rise to “irreversible security incidents.” Prior to OpenClaw, meanwhile, the likes of Reddit and Cloudflare raised alarms on AI crawlers working on behalf of Perplexity.
There has been less discussion of what agents are sharing with each other in terms of data input via Moltbook chatter, especially with regards to proxies; if monitored, the forum could telegraph any nefarious actions capable down the road with OpenClaw.
“Proxy-wielding AI agents could create a financial or security risk for carriers or their customers by unauthorized crawling/scraping at scale, or using their proxies for phishing, [distributed denial-of-service] attacks, etc., which would be a serious concern for carriers as it has been for content delivery networks (CDNs) and social media sites. The same goes for public and private sector entities,” Wilber explained.
“And while no doubt (human) threat actors have been doing ad hoc crawling/scraping for a long time, with AI you have the opportunity to automate and scale almost every type of cyberattack, which is what illicit proxy-based scraping at scale is essentially," Wilber added. "One could even imagine a viral agent-to-agent business of global proxy accounts that hive-style could launch what would be an attack-a-scale, though widely distributed so hard to detect and shut down, perhaps with the company behind the viral business equipped with large distributed SIM farms.”
SDxCentral has contacted T-Mobile and Proxies.SX for comment.
Comments