
Meta's Muse AI sent a YouTuber's home address to a stranger
Tech YouTuber Matt Robb says Meta's Muse agent shared his home address with a stranger and accepted a lowball offer on Facebook Marketplace without telling him, raising fresh security questions about the AI assistant.
Tech YouTuber Matt Robb says Meta's AI agent, Muse, handed his home address to a stranger and accepted a lowball price for an item he was selling on Facebook Marketplace, after he authorized the bot to handle his account. Robb described the incident in a post on Threads, where he shared a screenshot of Muse admitting the mistake.
Robb says the buyer turned up at his home without warning. He added that Muse did not tell him what had happened until after the person had left, and noted that he lives in an apartment building with security. The post spread quickly and drew attention to how much control Meta's new assistant is given over users' accounts.
How the deal went wrong
According to a Muse-generated summary Robb shared with The Verge, he gave the agent hands-off control over replying to Marketplace messages. He supplied his address, pickup time windows, the payment types he would accept, and instructions to keep conversations with buyers short, casual, and human.
The summary states that Robb never explicitly told Muse to share his address with buyers, and that the agent never asked for consent. It also notes he never explicitly forbade it. The incident points to a gap in Meta's safeguards: a home address is sensitive information that an agent should not pass on without clear permission.
Permissions confusion
Meta pointed The Verge to an X post from David Singleton of Meta Superintelligence Labs, who said he was trying to reach Robb. After they spoke, Robb said permission settings were partly to blame. On first use, Muse offered a choice of "Allow One Time" or "Allow Always"; Robb picked the second option, assuming individual offers would still need approval. They did not, and the agent began sending messages on his behalf using a template built from details he had given it, including the pickup address.
Robb says Meta intends to make sharing permissions clearer for Muse users going forward.
Wider security concerns
The leak is the latest safety question raised about Muse, which Meta launched earlier this month as it works to catch up with rivals Anthropic and OpenAI. Last week the company patched a zero-day exploit that could have let local attackers take control of the agent, and Amazon has blocked Muse from its retail platform entirely over concerns the bot could capture customer credentials.
SiTech — AI-powered web development
We build fast, modern websites and bring AI into real business workflows. Have a project or a question? We'd love to help.