OpenClaw is an open-source AI agent with full access to a user's computer — email, calendar, messaging, file system, shell commands, browser, and 50+ integrations. Between 300,000 and 400,000 people installed it. Within three weeks of going viral, security researchers documented 512 vulnerabiliti...
"By stealing OpenClaw files, an attacker does not just get a password; they get a mirror of the victim's life, a set of cryptographic keys to their local machine, and a session token to their most advanced AI models." — Hudson Rock, Threat Intelligence Research
OpenClaw is an open-source AI agent with full access to a user's computer — email, calendar, messaging, file system, shell commands, browser, and 50+ integrations. Between 300,000 and 400,000 people installed it. Within three weeks of going viral, security researchers documented 512 vulnerabilities, a critical remote code execution flaw, 1,184 malicious plugins in its official marketplace, commodity infostealers harvesting its configuration files, and over 135,000 instances exposed to the open internet.
On February 15, 2026, OpenAI acqui-hired its creator. OpenAI holds a $200 million Department of Defense contract. Former NSA Director Paul Nakasone sits on its board. The tool that stores your relationships, financial details, and daily activities in plain-text Markdown is now connected to the company building AI for the U.S. government.
This is Part 1 of a 10-part investigative series examining OpenClaw's security architecture, its vulnerability surface, and the implications of its acquisition by a defense contractor's AI partner.
OpenClaw is a self-hosted, open-source AI agent designed to act as the execution layer for large language models. Where ChatGPT or Gemini process language, OpenClaw carries out actions: browsing the web, editing files, running shell commands, managing calendars, sending messages. It connects to over 50 services through modular plugins called "skills."
The project accumulated over 180,000 GitHub stars and between 300,000 and 400,000 users in roughly eight weeks. According to Bitsight, internet-facing instances grew from approximately 1,000 to over 21,000 between January 25 and January 31, 2026, alone. SecurityScorecard's STRIKE threat intelligence team subsequently identified over 135,000 unique IPs running exposed instances across 82 countries, with 12,812 exploitable via remote code execution.
Skills — the plugin ecosystem — require no vetting. To publish a skill to ClawHub, the official marketplace, the only requirement is a GitHub account at least one week old.
The project launched in November 2025 under the name "Clawdbot." On January 27, 2026, following trademark complaints from Anthropic over the "Claud-" prefix, Steinberger renamed it "Moltbot" — a reference to a lobster molting its shell. Three days later, on January 30, it became "OpenClaw."
Three names in one week. Reddit's r/LocalLLM community called it "the fastest triple rebrand in open source history." The rapid renaming complicated threat tracking. Security advisories issued under "Clawdbot" did not automatically surface when organizations searched for "OpenClaw." CVE databases, corporate block lists, and endpoint detection rules all required manual updates.
Seconds after Steinberger released the @clawdbot Twitter handle, cryptocurrency scammers seized it and used it to promote a fraudulent token called $CLAWD, according to CNBC reporting.
Peter Steinberger is an Austrian software developer who founded PSPDFKit in 2011, a PDF framework company he bootstrapped to a €100 million strategic investment from Insight Partners in 2021. PSPDFKit's code runs on over a billion devices for companies including Apple and Dropbox.
Steinberger created OpenClaw as a personal project. According to his own disclosures, he was losing between $10,000 and $20,000 per month operating the project's infrastructure. He told TrendingTopics EU that "in Europe, I get insulted" — a reference to what he described as a lack of support for ambitious technical projects in the European ecosystem.
Sam Altman, Mark Zuckerberg, and Satya Nadella all courted Steinberger. On February 15, 2026, Altman announced via X that Steinberger was joining OpenAI to "drive the next generation of personal agents." Industry estimates of the acqui-hire value range from $2 million to $15 million, with total compensation packages reportedly characterized as "in the billions" when including equity, compute credits, and resources, according to AI Tools Review UK.
OpenClaw remains open-source under MIT license, transitioning to an independent foundation that OpenAI will sponsor but not control.
OpenClaw operates with the same OS privileges as the user who launches it. Every skill inherits these permissions. The agent connects to:
Session transcripts — complete records of every interaction between the user and the agent — are stored as JSONL files on disk. Any process with disk access can read them.
According to Kaspersky's analysis, OpenClaw's configuration stores API keys, passwords, and service credentials in plain text. OAuth tokens for connected services reside in unencrypted JSON files under ~/.openclaw/.
OpenClaw's memory is plain Markdown stored in the agent's workspace. According to the project's own documentation, the files are "the source of truth" — the model only "remembers" what gets written to disk.
These memory files contain:
The files are stored without encryption. Any process running on the same machine — legitimate or malicious — can read, copy, or modify them. This is not a theoretical concern.
On February 17, 2026, Hudson Rock documented a live attack where a Vidar infostealer variant exfiltrated openclaw.json (containing gateway authentication tokens), device.json (containing private cryptographic keys for device pairing), and memory files including soul.md, AGENTS.md, and MEMORY.md. The theft occurred on February 13. Hudson Rock warned that RedLine, Lumma, and Vidar infostealers have already added OpenClaw file paths to their must-steal lists.
Hudson Rock characterized the severity: stealing OpenClaw files gives an attacker "a mirror of the victim's life, a set of cryptographic keys to their local machine, and a session token to their most advanced AI models."
November 2025: Steinberger publishes "Clawdbot" on GitHub.
January 25, 2026: A security audit filed as GitHub Issue #1796 identifies 512 vulnerabilities. Eight are classified as critical, including two command injection flaws.
January 27, 2026: The first malicious skill appears on ClawHub. Anthropic files trademark complaint; project renames to Moltbot.
January 30, 2026: CVE-2026-25253 is patched in version 2026.1.29. CVSS score: 8.8. The vulnerability allows one-click remote code execution via cross-site WebSocket hijacking. No origin header validation. Attack chain: victim visits malicious link → authentication token exfiltrated in milliseconds → attacker connects to victim's gateway → sandbox disabled → arbitrary shell execution. Even localhost instances are vulnerable, as the exploit uses the victim's browser to pivot into the local network.
January 31, 2026: Koi Security names the ClawHavoc campaign. Initial scan of 2,857 skills on ClawHub identifies 341 malicious entries. Of these, 335 belong to a single coordinated campaign delivering Atomic macOS Stealer (AMOS). 91% include prompt injection — attacking the AI itself, embedding hidden instructions that manipulate the agent into silently executing curl commands and sending data to external servers.
February 1, 2026: Project renames to OpenClaw. Scanning continues as the marketplace grows to over 10,700 skills, with malicious entries rising to 1,184 — approximately 12% of the entire registry.
February 2, 2026: Belgium's Centre for Cybersecurity (CCB) issues an emergency advisory recommending immediate patching and enhanced monitoring.
February 5, 2026: China's Ministry of Industry and Information Technology (MIIT) issues a security alert warning that OpenClaw deployments carry "high security risks" under default or poorly configured settings, citing "unclear trust boundaries" and risk of "hostile takeovers."
February 8-9, 2026: Kakao, Naver, and Karrot ban OpenClaw from corporate networks. SecurityScorecard publishes internet-wide scanning data showing over 135,000 exposed instances.
February 13, 2026: Vidar infostealer successfully exfiltrates OpenClaw configuration and memory files from a victim's machine.
February 15, 2026: OpenAI acqui-hires Steinberger.
February 17, 2026: Meta bans OpenClaw from corporate networks, threatening employees with termination for installing it on company devices.
The acquisition timeline warrants scrutiny. OpenAI hired the creator of a tool with 512 documented vulnerabilities, an active supply chain attack on its marketplace, commodity malware targeting its users, and bans from multiple major technology companies.
OpenAI holds a one-year, $200 million contract with the U.S. Department of Defense, awarded in June 2025. Former NSA Director General Paul Nakasone — who led U.S. Cyber Command and the NSA from 2018 to 2024 — sits on OpenAI's board of directors and chairs its Safety and Security Committee.
In August 2025, OpenAI launched "OpenAI for Government," a partnership with the General Services Administration providing ChatGPT Enterprise to every federal executive branch agency for $1 per year. Sam Altman stated publicly that OpenAI is "proud to and really want to engage in national security areas."
The combination is direct: an AI agent that stores users' relationships, finances, daily activities, and private communications in plain-text files, built by a developer now employed by a company with active defense and intelligence community ties. The project's memory architecture — designed to give the AI deep personal context — simultaneously creates a surveillance-grade dataset on each user.
OpenClaw transitions to an independent foundation. OpenAI will sponsor but not control it. The distinction between sponsorship and control, in practice, remains untested.
The response from security professionals has been uniform.
Cisco's threat research team, led by Amy Chang, published a detailed technical analysis concluding: "From a security perspective, it's an absolute nightmare." Their researchers found that 26% of 31,000 agent skills analyzed contained at least one vulnerability.
Gary Marcus, NYU professor emeritus, described OpenClaw as "basically a weaponized aerosol" and wrote that using it was "like giving a stranger at a bar all your passwords."
Nathan Hamiel, a security researcher quoted in Marcus's analysis, stated: "If you give something that's insecure complete and unfettered access to your system and sensitive data, you're going to get owned."
An OpenClaw project maintainer acknowledged the risk directly: "If you can't understand how to run a command line, this is far too dangerous of a project for you to use safely."
Institutional Investor published an analysis titled "OpenClaw: The AI Agent Institutional Investors Need to Understand — But Shouldn't Touch."
Belgium, China, South Korea, and multiple multinational corporations have issued formal restrictions. The University of Toronto's Information Security office published a vulnerability notification advising against use.
OpenClaw represents the first mass deployment of an AI agent with full computer access, minimal security architecture, and no meaningful marketplace vetting. Within eight weeks of going viral, it generated a security crisis spanning critical CVEs, supply chain poisoning, infostealer targeting, and multinational corporate bans.
The tool is now organizationally connected to OpenAI — a company with defense contracts, intelligence community board members, and a stated ambition to embed AI across the federal government. The plain-text memory system that makes OpenClaw useful as a personal assistant simultaneously makes it useful as a surveillance instrument.
The remaining nine parts of this series will examine each dimension in detail: the CVE-2026-25253 attack chain, the ClawHavoc supply chain campaign, the infostealer economy targeting AI agents, the memory architecture's privacy implications, the OpenAI defense nexus, the regulatory response, the skill marketplace failure, the exposed instance landscape, and where the AI agent security model goes from here.
This is Part 1 of a 10-part investigative series. Part 2 will examine CVE-2026-25253 in technical depth — the WebSocket hijacking chain, the sandbox escape, and why even localhost instances were never safe.