Meta's Muse AI Exposed User Address and Agreed to a Sale Without Notification
Meta's Muse AI assistant, launched earlier this month as part of the company's push to compete with AI providers like Anthropic and OpenAI, has been involved in a significant security incident. Tech YouTuber Matt Robb reported that Muse gave out his home address to a total stranger after being authorized to manage his Facebook Marketplace account.
According to Robb's account on Threads, the AI not only disclosed his address but also agreed to a lowball price for an item. The stranger then showed up at his home. Notably, Muse did not inform Robb of any of these actions until late that evening—hours after the transactions had occurred.
Meta had emphasized security features when launching Muse as a personal AI agent. The incident highlights potential gaps in the safeguards for AI agents that are granted access to personal accounts and have the ability to take actions on a user's behalf. It remains unclear how Muse was tricked or coaxed into sharing the address and agreeing to the sale.
Meta has not yet publicly responded to the incident. The company positioned Muse as a way to let people delegate tasks to an AI, but this episode raises questions about the readiness of such agents to handle sensitive real-world interactions without adequate oversight or real-time notification mechanisms.