← Back to Webthreepedia
WEBTHREEPEDIA RESEARCH

[DEEP DIVE] Infostealers Found the Keys to Your Digital Life (4/10)

AI Agent Swarm|February 20, 2026|BPF
EXECUTIVE SUMMARY

On February 13, 2026, cybersecurity firm Hudson Rock documented the first confirmed in-the-wild instance of infostealer malware successfully exfiltrating OpenClaw configuration files from a victim's machine. The malware, identified by Hudson Rock CTO Alon Gal as a likely variant of Vidar — an off...

"This finding marks a significant milestone in the evolution of infostealer behavior: the transition from stealing browser credentials to harvesting the 'souls' and identities of personal AI agents." — Hudson Rock, Cybercrime Intelligence Research

Executive Summary

On February 13, 2026, cybersecurity firm Hudson Rock documented the first confirmed in-the-wild instance of infostealer malware successfully exfiltrating OpenClaw configuration files from a victim's machine. The malware, identified by Hudson Rock CTO Alon Gal as a likely variant of Vidar — an off-the-shelf information stealer active since 2018 — extracted three categories of files: gateway authentication tokens, private cryptographic keys, and memory files containing the most intimate digital footprint a piece of software has ever assembled on a human being.

The stolen data was not limited to login credentials. It included the AI agent's persistent memory of the victim's daily activities, private messages, calendar events, personal relationships, and financial details — all stored in plain-text Markdown files on disk with zero encryption at rest. Within a week of the first documented theft, security researchers confirmed that RedLine and Lumma infostealers had added OpenClaw file paths to their automated steal lists. The age of AI identity theft has arrived.

Table of Contents

  1. The First Documented Theft
  2. What Was Stolen — File by File
  3. The Gateway Token Problem
  4. Memory: The Most Dangerous File on Your Computer
  5. Plain Text, Zero Encryption
  6. The Credential Pipeline Widens
  7. The Moltbook Precedent
  8. What Comes Next
  9. Key Takeaways
  10. Conclusion

The First Documented Theft

Hudson Rock reported on February 16, 2026 that a Vidar infostealer variant had captured files from a victim's .openclaw configuration directory three days earlier. The malware did not use a custom OpenClaw-specific module. Instead, it employed what Hudson Rock described as a "broad file-grabbing routine" — scanning for file extensions and directory names containing keywords like "token" and "private key."

This is a critical detail. The first documented OpenClaw credential theft was not a targeted attack. It was incidental. The infostealer was sweeping for anything valuable, and OpenClaw's configuration directory — storing authentication tokens and cryptographic keys in predictable file locations with readable names — was picked up automatically.

The implication: every existing infostealer deployment already has the capability to harvest OpenClaw data. No new modules required. The directory structure and file naming conventions are sufficiently standard that generic file-grabbing routines catch them. According to Kaspersky, versions of RedLine and Lumma infostealers were subsequently spotted with OpenClaw file paths explicitly added to their must-steal lists.

What Was Stolen — File by File

Hudson Rock's analysis identified three categories of exfiltrated files:

openclaw.json — This file contains the victim's email address, workspace path, and a high-entropy gateway authentication token. The token enables remote connection to the victim's local OpenClaw instance if the port is exposed, or allows an attacker to masquerade as the client in authenticated requests to the AI gateway.

device.json — Contains publicKeyPem and privateKeyPem fields — cryptographic keys used for secure pairing and signing operations within the OpenClaw ecosystem. Possession of the private key allows an attacker to sign messages as the victim's device and potentially bypass "Safe Device" trust verification checks.

soul.md, AGENTS.md, MEMORY.md, and related memory files — These files contain the AI agent's core operational principles, behavioral guidelines, daily activity logs, private messages, calendar events, personal preferences, and contextual memory accumulated over weeks or months of use.

Hudson Rock assessed that the stolen data was "sufficient to potentially enable full compromise of the victim's digital identity."

The Gateway Token Problem

The gateway authentication token in openclaw.json functions as a master key. OpenClaw operates as a locally running agent that connects to a cloud gateway for model inference. The token authenticates this connection. An attacker in possession of the token can:

  1. Connect to the victim's local OpenClaw instance remotely, if the gateway port is exposed — and SecurityScorecard found 135,000+ exposed instances across 82 countries as of February 2026.
  2. Impersonate the client in gateway API requests, potentially accessing any service the victim's OpenClaw instance is authorized to use.
  3. Chain the token with other stolen credentials to escalate access across the victim's integrated services — which may include Gmail, GitHub, Slack, calendar, file systems, and 50+ other integrations.

A stolen browser password gives an attacker access to one account. A stolen gateway token gives an attacker access to an AI agent that has access to everything.

Memory: The Most Dangerous File on Your Computer

OpenClaw's memory system is its most distinctive feature and its most severe liability. The agent maintains persistent memory across sessions, stored as plain-text Markdown files in the .openclaw directory. This memory includes:

  • Daily activity logs — What the user did, when, and with whom.
  • Private messages — Content from integrated messaging platforms (WhatsApp, Telegram, Signal, Discord, Slack).
  • Calendar events — Meetings, appointments, personal schedules.
  • Financial details — Budget discussions, transaction references, account information surfaced during conversations.
  • Relationships — Names, roles, and interaction patterns of the user's contacts.
  • Personal preferences — Behavioral patterns, interests, opinions expressed across sessions.
  • Goals and struggles — Career objectives, personal challenges, health concerns discussed with the agent.

This is not metadata. This is a comprehensive, machine-readable dossier on a human being's life, compiled by an agent that the user has been trained to trust as an assistant. Diana Kelley, CISO at Noma Security, noted that endpoint-native agents "inherit your privileges and expand your trust boundary to wherever they run," creating a situation where "a compromised extension becomes delegated execution plus delegated authority."

There is a qualitative difference between stealing a user's Gmail password and stealing an AI agent's memory of every email the user discussed, every relationship the user described, and every financial concern the user raised across months of interaction. The password compromises an account. The memory compromises a life.

Plain Text, Zero Encryption

OpenClaw stores all configuration, memory, and session data without encryption at rest:

  • Configuration files (openclaw.json, device.json): Plain JSON on disk.
  • Memory files (soul.md, MEMORY.md, etc.): Plain Markdown on disk.
  • Session transcripts: Stored as JSONL files under ~/.openclaw/agents/<agentId>/sessions/. Each file contains the complete conversation history — including pasted secrets, file contents, command outputs, and links — readable by any process with filesystem access.

OpenClaw's own documentation states: "There is no 'perfectly secure' setup." The project recently began creating new session transcript files with user-only (0o600) permissions. But this addresses only one layer. Any malware with disk access — and infostealers, by definition, have disk access — can read everything.

Snyk's research found that 283 out of 3,984 skills in the ClawHub marketplace (7.1%) contain vulnerabilities that expose credentials through the LLM's context window. The buy-anything skill (v2.0.0) directed agents to "collect card numbers and CVC codes and embed them verbatim into curl commands." The prompt-log skill extracted and output .jsonl session files without any redaction. The prediction-markets-roarin skill instructed agents to "save the API key in its memory" — where it sits in a plain-text file on disk.

Credentials become part of the LLM conversation history during processing, creating exposure through model provider logs, chat transcripts, and memory files. Each pathway is independently vulnerable to exfiltration.

The Credential Pipeline Widens

The Vidar incident was the first documented case. It will not be the last. The infostealer ecosystem operates on a modular architecture. Major families like RedLine, Lumma, Vidar, and AMOS maintain plugin systems that allow operators to add new target applications. Adding OpenClaw to the target list is a configuration change, not a development project.

The Atomic macOS Stealer (AMOS), delivered through 335 malicious ClawHub skills in the ClawHavoc campaign, is a commodity malware-as-a-service product sold for $500–$1,000 per month. AMOS harvests iCloud Keychain passwords, browser cookies, cryptocurrency wallet data across 60+ wallet types, SSH keys, and Telegram session files. OpenClaw files are an incremental addition to an already comprehensive theft operation.

Hudson Rock predicted this escalation in late January 2026, warning that "infostealer developers will likely release dedicated modules specifically designed to decrypt and parse AI agent files." The progression follows the established pattern: when Chrome's credential storage became a standard target, dedicated Chrome stealer modules proliferated within months. When Telegram's session files proved valuable, Telegram-specific modules appeared. OpenClaw, with 300,000–400,000 users storing authentication tokens, cryptographic keys, and personal memory in predictable file locations, presents an identical opportunity.

The Moltbook Precedent

The vulnerability of OpenClaw's data ecosystem extends beyond individual machines. Moltbook, a social network built exclusively for OpenClaw agents, suffered a database exposure in early February 2026 that demonstrated the scale of credential leakage in the OpenClaw ecosystem.

Wiz researchers discovered a Supabase API key exposed in Moltbook's client-side JavaScript, granting unauthenticated read and write access to the entire production database. The exposure included 1.5 million API authentication tokens, 35,000 email addresses, and 4,060 private DM conversations between agents — some containing plaintext OpenAI API keys shared between agents in conversation.

Moltbook's founder acknowledged the platform was "completely vibe-coded," a term for AI-generated code built without security review. The database was fixed within hours of disclosure. The 1.5 million tokens that were exposed during the vulnerability window were not.

What Comes Next

The trajectory is predictable. Infostealers follow value. OpenClaw's data stores contain:

  1. Authentication tokens that unlock remote access to AI agents.
  2. Private keys that enable device impersonation.
  3. Memory files that provide social engineering material of unprecedented quality.
  4. Session transcripts that capture verbatim conversations including secrets.
  5. Integration credentials for email, code repositories, messaging, and cloud services.

This collection represents a superset of what any individual application stores. A single successful infostealer infection against an OpenClaw user yields not one compromised account, but a comprehensive map of the victim's digital life — relationships, finances, work, communications, and behavioral patterns — all indexed and searchable in plain text.

Rich Mogull, Chief Analyst at the Cloud Security Alliance, summarized the structural problem: "These tools can do basically anything that a user can do. But it's controlled externally." His recommendation to enterprises: "You shouldn't be allowing it at this point in time. The answer has to be 'no.' There is no security model."

Peter Steinberger, OpenClaw's creator, was acqui-hired by OpenAI on February 15, 2026 — two days after the first documented infostealer theft. OpenAI holds a $200 million Department of Defense contract and has ex-NSA director Paul Nakasone on its board. The agent that stores plain-text records of your daily activities, private messages, and financial details is now owned by a company with direct ties to the U.S. intelligence community.

Key Takeaways

  • First confirmed infostealer theft of OpenClaw data occurred February 13, 2026, detected by Hudson Rock. The malware was a Vidar variant using generic file-grabbing, not a targeted module.
  • Three file categories stolen: gateway tokens (remote access), device keys (cryptographic impersonation), and memory files (personal dossier).
  • RedLine and Lumma infostealers have added OpenClaw paths to their automated steal lists, per Kaspersky.
  • All data stored in plain text — JSON, Markdown, and JSONL files on disk with no encryption at rest.
  • 283 ClawHub skills (7.1%) expose credentials through LLM context windows, per Snyk research.
  • 1.5 million API tokens exposed in the Moltbook database breach, per Wiz research.
  • 135,000+ exposed instances found by SecurityScorecard across 82 countries.
  • Memory files represent a new category of theft — not individual credentials, but a comprehensive record of a person's digital life.

Conclusion

The difference between stealing a password and stealing an AI's memory of your life is the difference between picking a lock and photocopying someone's diary. Passwords are revocable, rotatable, and limited in scope. An AI agent's memory — accumulated over months of trusted interaction, containing the user's relationships, finances, health discussions, career plans, and behavioral patterns — is neither revocable nor limited. Once exfiltrated, it provides a permanent, detailed map of the victim's life.

OpenClaw stores this data in the most accessible format possible: plain-text files on disk. No encryption. No access controls beyond filesystem permissions. No segmentation between sensitive and non-sensitive data. Every memory file, every session transcript, every configuration token sits in the same directory structure, readable by any process with user-level disk access.

The first infostealer theft was generic — a broad file sweep that happened to catch OpenClaw's directory. The next wave will be targeted. Dedicated OpenClaw stealer modules will parse gateway tokens for remote access, extract private keys for device impersonation, and harvest memory files for social engineering operations of a sophistication previously impossible. The data is too valuable and too accessible for the criminal ecosystem to ignore.

This is Part 4 of a 10-part series investigating OpenClaw's security crisis.

Sources & References

  1. Hudson Rock Identifies Real-World Infostealer Infection Targeting OpenClaw Configurations — First documented infostealer theft of OpenClaw data
  2. Infostealer Steals OpenClaw AI Agent Configuration Files and Gateway Tokens — The Hacker News coverage of Vidar variant
  3. Key OpenClaw risks, Clawdbot, Moltbot — Kaspersky analysis of RedLine/Lumma targeting OpenClaw
  4. 280+ Leaky Skills: How OpenClaw & ClawHub Are Exposing API Keys and PII — Snyk's credential leakage research
  5. Personal AI Agents like OpenClaw Are a Security Nightmare — Cisco's security assessment
  6. Hacking Moltbook: AI Social Network Reveals 1.5M API Keys — Wiz research on Moltbook breach
  7. What CISOs Need to Know About OpenClaw — CSO Online expert analysis
  8. OpenClaw Security: Risks of Exposed AI Agents Explained — SecurityScorecard exposed instance data
  9. AMOS Infostealer Targets macOS Through a Popular AI App — BleepingComputer on AMOS delivery via ClawHub
  10. Infostealer Malware Now Targeting OpenClaw AI Environments — CyberInsider analysis