OpenClaw accesses email, calendars, messaging platforms, file systems, shell commands, browser data, and 50+ third-party integrations. Its memory system stores daily activities, personal relationships, financial details, credentials, and behavioral patterns in plain-text Markdown files on disk. A...
"I think it's a privacy nightmare. Not only are you letting an AI agent look at sensitive information like your passwords and documents, but you also have limited insights into how it's processing your information and where it's sending it." — Aanjhan Ranganathan, Associate Professor of Cybersecurity, Northeastern University
OpenClaw accesses email, calendars, messaging platforms, file systems, shell commands, browser data, and 50+ third-party integrations. Its memory system stores daily activities, personal relationships, financial details, credentials, and behavioral patterns in plain-text Markdown files on disk. Any process with filesystem access can read them. Session transcripts persist as JSONL files in predictable directories. Plugins execute with the same OS-level privileges as the host process. Sandboxing is opt-in and disabled by default.
On February 15, 2026, OpenAI acqui-hired OpenClaw creator Peter Steinberger. OpenAI holds a $200 million Department of Defense contract for prototyping frontier AI in "warfighting and enterprise domains." Retired NSA Director General Paul Nakasone sits on its board and Safety and Security Committee. The company provides ChatGPT Enterprise to federal agencies for $1 per year. The pattern — a tool that 300,000-400,000 people voluntarily installed to manage their entire digital lives, absorbed into a company with deep defense and intelligence ties — merits examination through the lens of historical surveillance programs where the infrastructure preceded the exploitation.
OpenClaw's integration surface is without precedent for a single consumer application. According to its official documentation, the tool connects to 50+ services spanning every major category of digital activity:
Communications: Gmail, Slack, Discord, WhatsApp, Telegram, Signal, iMessage, Microsoft Teams, Google Chat, Matrix, BlueBubbles. The agent reads incoming messages, drafts replies, and processes conversation histories across all connected platforms simultaneously.
Productivity and files: Google Calendar, Obsidian, file system access (read and write), shell command execution, browser history and control. OpenClaw can navigate directories, open files, execute scripts, and modify system configurations.
Development and infrastructure: GitHub, GitLab, CI/CD pipelines. Full access to codebases, pull requests, deployment pipelines, and credentials stored in configuration files.
Personal and lifestyle: Spotify, home automation systems (Home Assistant), personal note-taking applications.
The critical architectural detail: these integrations do not operate through sandboxed APIs with limited scopes. OpenClaw plugins execute with the same OS-level privileges as the OpenClaw process itself. If OpenClaw runs as the primary user — which is the default and recommended configuration — every plugin inherits full user permissions. There is no privilege separation between reading a Spotify playlist and executing arbitrary shell commands.
Cisco's Talos research group described this architecture as "an absolute nightmare" from a security perspective.
OpenClaw's memory system transforms the agent from a stateless tool into a persistent surveillance apparatus. The system operates across two layers:
Long-term memory (MEMORY.md): Stores decisions, preferences, behavioral patterns, relationship details, financial information, and "durable facts" about the user. This file persists indefinitely.
Daily notes (memory/YYYY-MM-DD.md): Running logs of daily activities, conversations processed, tasks executed, observations made. A chronological record of the user's digital life, updated continuously.
Soul file (soul.md): Contains the agent's core operational principles, behavioral guidelines, and the user's stated preferences — effectively a personality profile built from sustained interaction.
All of these files are stored as plain-text Markdown in ~/.openclaw/workspace. No encryption. No access controls beyond standard filesystem permissions. No database layer. The files are human-readable and machine-parseable. Any process running under the same user account can read the entirety of a user's accumulated dossier.
Session transcripts compound the exposure. Every interaction is logged as JSONL (JSON Lines) at ~/.openclaw/agents/<agentId>/sessions/*.jsonl. Each line represents one message — user inputs, agent outputs, tool calls, API responses. These files are append-only and persist on disk. New transcripts are created with 0o600 permissions (user-only read/write), but this assumes correct filesystem configuration and a single-user environment.
The result: over weeks and months of use, OpenClaw builds a comprehensive profile that includes what you said to whom, when you said it, what files you accessed, what code you wrote, what financial decisions you made, what personal relationships you discussed, and what your daily schedule looks like. No single application in computing history has accumulated this breadth of personal data in a locally stored, unencrypted, plaintext format.
SecurityScorecard's STRIKE team identified over 135,000 unique IPs running exposed OpenClaw instances across 82 countries as of mid-February 2026. Independent researcher Maor Dayan's scan found 42,665 instances, of which 5,194 were actively vulnerable. Of those scanned, 93.4% exhibited critical authentication bypass vulnerabilities.
The default OpenClaw configuration ships with authentication disabled. The gateway — the component that mediates all tool calls and API requests — is unauthenticated out of the box. Users who deploy OpenClaw without changing defaults expose their entire agent infrastructure, including memory files, session logs, and active integrations, to anyone who can reach the port.
Censys tracked the growth from approximately 1,000 to over 21,000 publicly exposed instances between January 25 and January 31, 2026 alone — a 2,000% increase in six days. By February 9, the number exceeded 135,000.
Each exposed instance is not merely a vulnerable server. It is a window into one person's complete digital life — their emails, messages, files, credentials, daily activities, and relationship maps — accessible to any actor who can issue HTTP requests to the exposed port.
On February 13, 2026, Hudson Rock documented the first confirmed case of infostealer malware specifically harvesting OpenClaw configuration data. A Vidar infostealer variant exfiltrated the contents of a victim's .openclaw directory. The stolen files included:
Hudson Rock's analysis concluded that the stolen data was "sufficient to potentially enable full compromise of the victim's digital identity." The attacker did not need to exploit an OpenClaw-specific vulnerability. The Vidar variant's standard file-grabbing routine, designed to scan for keywords like "token" and "private key" in directory names and file contents, captured the OpenClaw data incidentally. The .openclaw directory's predictable location and plaintext format made it indistinguishable from any other credential store.
This is the operational reality: gateway tokens stolen from a single infected machine grant the attacker persistent, authenticated access to every service the victim connected to OpenClaw — Gmail, Slack, GitHub, file systems, calendar, messaging platforms. The attacker inherits not only access but context — the memory files tell them who the victim communicates with, what projects they work on, what financial decisions they are making, and what their daily schedule looks like.
On February 15, 2026, OpenAI confirmed the acqui-hire of Peter Steinberger, the Austrian developer who created OpenClaw (originally "Clawdbot," then renamed "Moltbot," then "OpenClaw"). Steinberger, formerly the founder of PSPDFKit, had been losing $10,000-$20,000 per month operating the project. Both Sam Altman and Mark Zuckerberg made competing offers. Steinberger chose OpenAI.
According to TechCrunch, Steinberger will lead next-generation personal agent development at OpenAI. OpenClaw will remain open source, housed in a foundation that OpenAI will continue to support.
The acqui-hire places the architect of a tool that accesses the complete digital lives of hundreds of thousands of users inside a company with the following government relationships:
$200 million DoD contract (June 2025): A one-year prototype agreement through the Defense Department's Chief Digital and Artificial Intelligence Office (CDAO) for "prototyping frontier-model capabilities across warfighting and enterprise domains." The CDAO identified use cases including command and control, decision support, operational planning, logistics, weapons development and testing, uncrewed and autonomous systems, intelligence activities, information operations, and cyber operations. The contract runs through July 2026.
Board composition: Retired U.S. Army General Paul M. Nakasone, former Director of the NSA and Commander of U.S. Cyber Command (May 2018 - February 2024), joined OpenAI's board in June 2024. Nakasone simultaneously sits on the company's Safety and Security Committee — the body that governs how OpenAI's AI models are deployed and secured.
Federal access program (August 2025): Through a partnership with the U.S. General Services Administration (GSA), OpenAI provides ChatGPT Enterprise to every participating federal agency for $1 per year. The program, branded "OneGov," was announced with support from Slalom and Boston Consulting Group for deployment and training.
Until early 2024, OpenAI's public policy explicitly prohibited military applications. That prohibition was removed prior to the DoD contract.
The relationship between data collection infrastructure and intelligence exploitation has three primary historical templates.
PRISM (disclosed 2013): The NSA program collected internet communications from U.S. technology companies under Section 702 of the FISA Amendments Act. PRISM accounted for 91% of the approximately 250 million internet communications the NSA acquired annually. Companies including Google, Facebook, Apple, Microsoft, and Yahoo were compelled to participate — Yahoo was threatened with $250,000-per-day fines when it initially refused. The critical distinction: PRISM required government coercion of platform operators. OpenClaw's data is stored locally on user machines, bypassing the need for platform cooperation entirely.
Pegasus (NSO Group): State-sponsored spyware deployed across 45+ countries, targeting journalists, lawyers, political dissidents, and human rights activists. Pegasus could access text messages, call logs, passwords, location data, microphone, and camera. It required zero-click exploits costing millions of dollars per deployment and targeted individual devices one at a time. OpenClaw provides comparable or broader data access — across more platforms, with persistent memory — and users install it voluntarily.
Vault 7 (CIA, disclosed 2017): The CIA's Engineering Development Group built exploits for consumer electronics including smart TVs, routers, smartphones, and computer operating systems. Tools like "Weeping Angel" turned Samsung TVs into listening devices. The CIA's toolset required per-device exploitation of specific vulnerabilities. OpenClaw's architecture — unauthenticated by default, memory in plaintext, plugins with full OS privileges — requires no such exploitation.
The structural comparison: PRISM needed secret court orders. Pegasus needed zero-click exploits purchased from NSO Group at state-level prices. The CIA's Vault 7 tools needed device-specific vulnerability chains. OpenClaw needs a user to type brew install openclaw and connect their accounts.
The standard defense of OpenClaw's architecture is that it runs locally. Data stays on the user's machine. No cloud sync is required. This framing treats locality as a security property. It is not.
Local storage means:
The 300,000-400,000 users who installed OpenClaw made a voluntary decision to consolidate their email, messaging, file systems, development tools, calendars, financial applications, and personal notes into a single agent with full system privileges and persistent memory. They did so in an application that ships with authentication disabled, stores credentials in plaintext, and executes plugins without privilege separation.
The corporate response has been unambiguous. Kakao, Naver, and Karrot banned OpenClaw from corporate networks in South Korea. Meta threatened employees with termination for using it on work devices. Belgium's Centre for Cybersecurity (CCB) published an emergency advisory on February 2, 2026. China's Ministry of Industry and Information Technology (MIIT) issued a security alert on February 5, 2026, classifying OpenClaw deployments as carrying "high security risks."
Whether any intelligence agency exploits this architecture is, in a sense, beside the point. The architecture makes mass exploitation trivial. A tool that 400,000 people voluntarily installed to manage their complete digital lives — with plaintext memory, no authentication by default, and full OS privileges — now sits inside a company with a $200 million defense contract, an ex-NSA director on the board, and a stated mission to prototype AI for "warfighting and enterprise domains."
The infrastructure exists. The data is collected. The access is granted. The acquisition is complete.
The question of whether OpenClaw constitutes intelligence infrastructure does not require speculating about intent. It requires examining architecture. A tool that reads email, messages, files, and code across 50+ platforms; that stores daily activity logs, relationship data, and financial details in plaintext; that runs with full OS privileges; that ships unauthenticated; and that 135,000+ users exposed directly to the internet — this is, by structural definition, a surveillance-ready system. The only variable is who accesses the data.
The February 15 acqui-hire did not create the surveillance risk. The risk was embedded in OpenClaw's architecture from inception — in the plaintext memory, the unprivileged plugin model, the disabled-by-default authentication. What the acqui-hire did was place the roadmap for that architecture inside a company that builds AI for the Department of Defense, seats an ex-NSA director on its safety committee, and is providing its models to every federal agency in the United States for a dollar a year.
Users installed OpenClaw to manage their digital lives. The architecture they accepted manages their digital lives comprehensively, persistently, and in formats that are trivially accessible to any actor — authorized or otherwise — with the means to read a plaintext file.