← Back to Webthreepedia
WEBTHREEPEDIA RESEARCH

[DEEP DIVE] 135,000 Open Doors: Internet-Exposed AI Agents (5/10)

Zephyra|February 20, 2026|BPF
EXECUTIVE SUMMARY

Between January 27 and February 9, 2026, four independent security research teams scanned the internet for OpenClaw instances and found the same thing: tens of thousands of fully accessible AI agents sitting on the open internet, most with no authentication, many pre-compromised. The numbers vari...

"It's like giving some random person access to your computer to help do tasks. If you supervise and verify, it's a huge help. If you just walk away and tell them all future instructions will come via email or text message, they might follow instructions from anyone." — Jeremy Turner, VP of Threat Intelligence and Research, SecurityScorecard

Executive Summary

Between January 27 and February 9, 2026, four independent security research teams scanned the internet for OpenClaw instances and found the same thing: tens of thousands of fully accessible AI agents sitting on the open internet, most with no authentication, many pre-compromised. The numbers varied by methodology—Censys counted 21,639 by January 31, Bitsight tallied 30,000+ by February 8, SecurityScorecard's STRIKE team found 135,000+ by February 9, and independent researcher Maor Dayan identified 42,665 with 5,194 actively verified as vulnerable. Of Dayan's verified sample, 93.4% exhibited authentication bypass conditions.

Each exposed instance represents a portal into someone's digital life. OpenClaw agents manage email, calendars, file systems, messaging platforms, browser sessions, and shell commands across 50+ integrations. An unauthenticated, internet-facing OpenClaw instance is not merely a misconfigured service—it is unrestricted access to every system and account that agent controls. SecurityScorecard found 15,200 instances exploitable via remote code execution, 53,300 correlated with prior breach infrastructure, and 33.8% overlapping with known threat actor IP ranges including Kimsuky and APT28 (Fancy Bear).

This is Part 5 of a 10-part investigative series examining the OpenClaw security crisis.

Table of Contents

  1. The Scan Results: Four Teams, One Finding
  2. Why 135,000 Instances Were Exposed
  3. Geographic and Infrastructure Distribution
  4. What "Exposed" Actually Means
  5. Breach Correlation: Already Compromised
  6. Version Fragmentation: 78% Unpatched
  7. Comparison to Historical Mass Exposures
  8. The Moltbook Amplifier
  9. Key Takeaways
  10. Conclusion

The Scan Results: Four Teams, One Finding

The exposure data arrived from multiple independent sources, each using different scanning methodologies, each converging on the same conclusion: OpenClaw's user base had deployed a vast fleet of internet-facing AI agents with minimal or no security controls.

Censys published first. By January 31, 2026—just four days after OpenClaw's viral adoption surge—their internet-wide scan identified 21,639 publicly exposed instances. The growth trajectory was steep: from approximately 1,000 detectable instances on January 27 to 21,000+ by month's end, according to their blog analysis.

Bitsight conducted a cumulative analysis from January 27 through February 8, 2026, identifying more than 30,000 distinct exposed instances. Peak daily detection reached approximately 8,000–9,000 instances on the final scan date. Bitsight's research flagged deployments across sensitive sectors: healthcare, finance, government, and insurance.

Maor Dayan, an independent security researcher, published a detailed analysis on Medium identifying 42,665 exposed instances. Of these, 5,194 were actively verified as vulnerable through systematic probing. The critical finding: 93.4% of verified instances exhibited authentication bypass conditions enabling unauthenticated access to the gateway control plane.

SecurityScorecard's STRIKE team conducted the most comprehensive scan, published February 9, 2026. Their initial count was approximately 40,000 exposed instances. Within hours of publication—as their scanning infrastructure continued to enumerate results—the count crossed 135,000 unique IPs running exposed OpenClaw instances across 82 countries. The number had more than tripled during the research window. Of these, 15,200 were flagged as vulnerable to remote code execution, and 12,812 were confirmed exploitable.

On Shodan, 24,478 distinct servers running OpenClaw were independently discoverable. Multiple researchers confirmed that a simple Shodan dork for port 18789 returned thousands of results with exposed control panels, many displaying active session data.

Why 135,000 Instances Were Exposed

The root cause is a default configuration decision. OpenClaw ships binding its gateway to 0.0.0.0:18789—meaning it listens on all network interfaces, including any public-facing network adapter. Unless a user explicitly restricts binding to 127.0.0.1 (localhost only), the gateway is accessible from the internet the moment the process starts.

Authentication compounded the problem. Earlier Clawdbot versions (pre-rebrand) allowed fully unauthenticated access. Later versions introduced optional token authentication, but Bitsight found that the system accepted trivially weak tokens—a single character like "a" qualified as a valid authentication credential. No password complexity enforcement existed.

Users exposed their instances for practical reasons:

  • Remote access from mobile devices. OpenClaw's messaging integrations (WhatsApp, Telegram, Slack, Discord) encouraged users to access their agent from anywhere. Running on a cloud VPS and binding to all interfaces was the path of least resistance.
  • Cloud VPS deployment. Users renting DigitalOcean, Alibaba Cloud, or Hetzner servers for always-on operation frequently left the default binding in place, exposing the instance to the server's public IP.
  • Docker misconfigurations. Users running docker run -p 18789:18789 without restricting the host interface forwarded the port to all interfaces by default.
  • Reverse proxy misconfigurations. Some users attempted to secure access via Nginx or Cloudflare Tunnels but set allowInsecureAuth: true in the gateway configuration, negating the proxy's security layer.
  • Corporate shadow deployments. According to SecurityScorecard, 22% of enterprises reportedly had unauthorized AI agent deployments running without security oversight—employees installing OpenClaw on corporate infrastructure without IT knowledge.

The Register summarized the situation: "OpenClaw instances open to the internet present ripe targets."

Geographic and Infrastructure Distribution

SecurityScorecard's STRIKE data revealed a distinct geographic and infrastructure concentration pattern.

By country: China hosted 37% of exposed instances, followed by the United States and Singapore. Deployments spanned 82 countries, but the top three accounted for the majority.

By cloud provider: 98.6% of deployments ran on cloud or hosting infrastructure. The breakdown:

| Provider | Instances | Share | |----------|-----------|-------| | Alibaba Cloud | ~45% of total | Dominant in China | | Tencent Cloud | 2,234+ | ~12.3% | | DigitalOcean | 1,122+ | ~24.5% (of Dayan's sample) | | Hetzner | 596+ | ~13% (of Dayan's sample) |

Censys's independent analysis of 21,639 instances confirmed the geographic pattern: United States, China, and Singapore as the top three hosting countries, with Alibaba Cloud accounting for at least 30% of identified instances.

The concentration on a handful of cloud providers suggests systematic vulnerability replication. Deployment guides, tutorials, and one-click templates for these platforms proliferated during OpenClaw's viral adoption wave, each propagating the same insecure default configurations.

What "Exposed" Actually Means

An exposed OpenClaw instance is not analogous to an exposed database or a misconfigured S3 bucket. Those expose static data. An exposed OpenClaw instance exposes an active agent with autonomous execution capabilities across its owner's entire digital life.

A compromised instance gives an attacker access to:

  • Email accounts (Gmail, Outlook) — read, send, delete messages
  • Calendar — view schedules, create or modify appointments
  • File system — read, write, delete any file the process can access
  • Shell commands — execute arbitrary commands with the user's OS privileges
  • Browser sessions — access cached credentials, browsing history, active sessions
  • Messaging platforms — WhatsApp, Telegram, Slack, Discord message histories
  • Code repositories — GitHub, GitLab access via stored OAuth tokens
  • Smart home devices — any connected IoT integrations
  • API keys and credentials — stored in plain text in OpenClaw's configuration and memory files

SecurityScorecard's STRIKE team confirmed that exposed control panels actively leaked API keys linked to third-party services. Anthropic API keys, Telegram bot tokens, Slack OAuth credentials, and complete conversation histories were discoverable through exposed instances.

OpenClaw's memory system amplifies the damage. The agent stores user context—daily routines, personal relationships, financial details, credentials, work projects—in plain Markdown files on disk. Any attacker accessing an exposed instance gains not just tool access, but intimate knowledge of the target's life and habits.

Cisco's security blog assessment: "OpenClaw can run shell commands, read and write files, and execute scripts on your machine." Their analysis concluded that "security for OpenClaw is an option, but it is not built in."

Breach Correlation: Already Compromised

SecurityScorecard's STRIKE team cross-referenced exposed OpenClaw instances against their threat intelligence databases. The results indicated that exposure had already translated to compromise.

  • 53,300 exposed instances correlated with prior breach activity
  • 33.8% of enriched instances showed overlap with known breach infrastructure
  • IP addresses associated with Kimsuky (North Korean APT) and APT28/Fancy Bear (Russian GRU) appeared in the correlation data
  • 24,000+ instances were associated with known CVEs

The breach correlation data suggests that threat actors had already inventoried and begun exploiting exposed instances before the security community's reports were published. The exposure window—from OpenClaw's viral surge in late January through early February—gave attackers approximately two weeks of open access before mainstream security coverage began.

Version Fragmentation: 78% Unpatched

SecurityScorecard's analysis of the exposed instance population revealed severe version fragmentation. The software underwent two rebrands in a week—Clawdbot to Moltbot (January 27), Moltbot to OpenClaw (January 30)—and the exposed instance population reflected this chaos:

| Version | Share | Status | |---------|-------|--------| | Clawdbot Control (original) | 39.5% | Pre-patch, pre-rebrand | | Moltbot Control (Jan 27 rebrand) | 38.5% | Pre-patch | | OpenClaw Control (current) | 22.0% | May include patched versions |

78% of exposed instances ran pre-patch versions of the software weeks after CVE-2026-25253 (CVSS 8.8, one-click RCE) was disclosed and patched in v2026.1.29. The update mechanism—requiring manual intervention—failed at scale. Users who installed the tool during the viral surge and walked away had no automatic path to security patches.

Comparison to Historical Mass Exposures

The OpenClaw exposure event invites comparison to previous mass misconfiguration incidents. The scale is familiar; the implications are not.

MongoDB (2023-2024): Shodan telemetry identified 194,000+ publicly reachable MongoDB instances. These exposed static databases—customer records, financial data, application state. Attackers could read and exfiltrate data. The damage was significant but bounded: data at rest.

Elasticsearch (2023): Tens of thousands of unprotected Elasticsearch clusters exposed corporate logs, user data, and application metrics. Again, static data at rest.

OpenClaw (2026): 135,000+ exposed instances, each providing not data access but agent access—autonomous execution capability across email, files, shell, messaging, browser, and API credentials. An exposed MongoDB instance leaks records. An exposed OpenClaw instance can send emails, execute code, delete files, and impersonate the user across every connected service.

The qualitative difference is control. Prior mass exposure events compromised confidentiality. The OpenClaw exposure compromises confidentiality, integrity, and availability simultaneously—the full CIA triad—because the exposed service is an autonomous agent with execution authority.

The Moltbook Amplifier

A parallel exposure event compounded the damage. Moltbook, a social network built exclusively for OpenClaw agents, launched on January 28, 2026. Its developer, Matt Schlicht, publicly stated he "didn't write a single line of code" and built the platform entirely with AI.

On January 31, Wiz Security researcher Gal Nagli discovered that Moltbook's Supabase database had Row Level Security disabled. The Supabase API key was hardcoded in client-side JavaScript, visible through browser developer tools. The result: full unauthenticated read/write access to the production database.

The exposure included:

  • 35,000 email addresses of human users
  • 1.5 million AI agent API tokens (Anthropic API keys, service credentials)
  • 4,000 private messages between users
  • 88:1 agent-to-human ratio — 17,000 human owners operated 1.5 million registered agents with no rate limiting

Wiz disclosed to Moltbook on February 2. The vulnerability was patched within hours—it required two SQL statements to enable RLS. But the damage window was four days of full database access, and the 1.5 million exposed API tokens represented direct financial liability for every affected user.

Key Takeaways

  • Four independent security teams (Censys, Bitsight, SecurityScorecard STRIKE, Maor Dayan) converged on the same finding: tens of thousands to 135,000+ internet-exposed OpenClaw instances with minimal or no authentication.
  • 93.4% of verified instances exhibited authentication bypass conditions.
  • 15,200 instances were exploitable via remote code execution. 53,300 correlated with prior breach infrastructure.
  • 78% of exposed instances ran unpatched versions weeks after the critical CVE-2026-25253 patch.
  • The default configuration (0.0.0.0:18789) ships the gateway open to the internet. Authentication is optional and accepts trivially weak tokens.
  • Each exposed instance represents full access to an active AI agent controlling email, files, shell, messaging, and 50+ integrations—not a static data store.
  • 98.6% of deployments ran on cloud infrastructure, concentrated on Alibaba Cloud, Tencent, DigitalOcean, and Hetzner.
  • The Moltbook breach amplified the crisis by exposing 1.5 million API tokens and 35,000 email addresses through a companion platform with no database security.

Conclusion

The OpenClaw mass exposure event differs from its predecessors in a fundamental way. When MongoDB instances were found on the open internet, the risk was data theft. When Elasticsearch clusters were exposed, the risk was information leakage. When 135,000+ OpenClaw instances were found on the open internet, the risk was autonomous agent hijacking—the ability to commandeer a system that reads email, executes code, manages files, and communicates on behalf of its owner.

The exposure was predictable. A tool that binds to all network interfaces by default, ships without mandatory authentication, accepts single-character tokens when authentication is enabled, and provides no automatic update mechanism will produce exactly this outcome when adopted by hundreds of thousands of users in a matter of days. The 135,000 exposed instances are not a failure of user behavior. They are a failure of secure-by-default design—amplified by viral adoption that outpaced any possibility of security guidance reaching users in time.

As of mid-February 2026, OpenClaw is now owned by OpenAI—a company with a $200 million Department of Defense contract, an ex-NSA director on its board, and a government access initiative offering federal agencies the platform for $1 per year. The 135,000 open doors that were each a window into someone's digital life now feed into that infrastructure. Whether those doors have been closed is a question the new owners have yet to answer publicly.

Sources & References

  1. SecurityScorecard STRIKE Team — Beyond the Hype: Moltbot's Real Risk Is Exposed Infrastructure — Feb 9, 2026. Primary source for 135,000+ exposed instances, geographic distribution, breach correlation data.
  2. Bitsight — OpenClaw Security: Risks of Exposed AI Agents Explained — Feb 2026. 30,000+ instances from Jan 27–Feb 8 analysis, authentication weakness findings.
  3. Maor Dayan — The Sovereign AI Security Crisis: 42,000+ Exposed OpenClaw Instances — Jan 2026. Independent analysis, 42,665 exposed, 5,194 verified vulnerable, 93.4% auth bypass.
  4. Censys — OpenClaw in the Wild: Mapping the Public Exposure of a Viral AI Assistant — Jan 31, 2026. 21,639 exposed instances, geographic and cloud provider analysis.
  5. The Register — OpenClaw Instances Open to the Internet Present Ripe Targets — Feb 9, 2026. Jeremy Turner quotes, 135,000+ figure, CVE details.
  6. Infosecurity Magazine — Researchers Find 40,000+ Exposed OpenClaw Instances — Feb 2026. 40,214 instances, 12,812 RCE-exploitable, geographic breakdown.
  7. SiliconANGLE — Tens of Thousands of OpenClaw Systems Exposed — Feb 9, 2026. 28,663 unique IPs, 63% exploitable, vulnerability details.
  8. Security Boulevard — 42,900 OpenClaw Exposed Control Panels — Feb 2026. Version fragmentation data, breach correlation with Kimsuky and APT28.
  9. Cisco Blogs — Personal AI Agents Like OpenClaw Are a Security Nightmare — Feb 2026. Cisco security assessment, skill vulnerability analysis.
  10. Wiz Security — Hacking Moltbook: AI Social Network Reveals 1.5M API Keys — Feb 2026. Moltbook database exposure, 35,000 emails, 1.5M tokens.
  11. Bitdefender — 135K OpenClaw AI Agents Exposed to Internet — Feb 2026. Summary of SecurityScorecard findings.
  12. VentureBeat — OpenClaw Proves Agentic AI Works. It Also Proves Your Security Model Doesn't — Feb 2026. Enterprise risk analysis, 22% unauthorized deployment figure.