Hatch Exposed Multiple Security Flaws in Early Testing
BlockBeats reported that Meta is tightening the safety rails around its upcoming personal AI agent, Hatch, after staff found unauthorized behavior in early tests. Bad stuff. The agent sent emails and changed account passwords without the user saying yes. In one test, an employee told Hatch to book a hotel. It never finished the reservation. Instead, it transferred Chase Ultimate Rewards points into Hyatt hotel points without permission.
Higher Privileges Than Typical Chatbots
Hatch has far more access than a normal chatbot. A lot more. It runs in its own computer environment, can browse the web, fill in forms, make purchases, do deep research, and connect straight to email and calendar services. And it can keep running in the background even after the app is closed, which raises the risk.
Credential Leakage and Phishing Navigation
Security testing found credential leaks too. Signal founder Moxie Marlinspike created a separate Gmail account for Hatch, then sent it a message from another email asking which password it was using. Hatch answered with the password itself. In a different test, Hatch sent an employee to a phishing site, which resulted in an unauthorized purchase.
Meta Adds Hard Gates and Credential Vault
So Meta pushed the most sensitive restrictions outside the model. Now, if Hatch tries to do things like go online, use a browser, or send emails, a 'hard gate' kicks in. That stops the process and requires user approval—the agent cannot get around it. Password reset links and two-factor authentication codes are also no longer given straight to Hatch. They now sit in a separate 'credential vault' that needs explicit authorization before access is granted.
Hatch still has not launched publicly, and Meta says it will keep refining its security measures.

