Article

OpenClaw: fully autonomous, revolutionary and far from safe

OpenClaw promises a personal AI assistant that actually does things for you. Our GenAI Research Lab looked into its security and found serious vulnerabilities.

Artific

A red robot lobster with glowing eyes among floating screens full of code.

OpenClaw (formerly Moltbot, and before that Clawdbot) is one of the fastest-growing open-source AI projects ever. It promises to be a personal AI assistant that actually does things for you through WhatsApp, Telegram and other platforms. What it can do is impressive, but security researchers have found serious vulnerabilities. So before you dive in enthusiastically, you need to know what the risks are.

Bas Wenneker, one of our own data scientists in Artific’s GenAI Research Lab, took a closer look for you. Read his findings here.

What is OpenClaw, exactly?

Imagine an AI assistant that doesn’t just answer your questions but actually carries out actions. Replying to emails, managing your calendar, organising files, even controlling your smart home devices. And all of it through the messaging apps you already use: WhatsApp, Telegram, Slack, Discord or Signal.

That is OpenClaw in a nutshell.

Developed by the Austrian entrepreneur Peter Steinberger, OpenClaw runs entirely locally on your own hardware. No dependence on external servers for your data. You send your AI a message through Telegram, or another app, and it then carries out actions on your computer.

The project exploded on GitHub in early 2026, going from 9,000 to more than 60,000 stars in a few days. Andrej Karpathy, David Sacks and other tech icons praised the project as “the future of personal AI assistants”.

The promise: a digital right hand

What OpenClaw can do is undeniably impressive:

  • Automating communication: inbox management, follow-up emails, daily briefings the AI sends you proactively.
  • Calendar and planning: scheduling meetings, sending reminders, preparing for appointments.
  • File management: finding and organising documents, and even running shell commands on your system.
  • Multi-platform: one assistant that works across WhatsApp, Telegram, Discord, Slack, Signal and iMessage at the same time.

On top of that, the “Skills” system makes OpenClaw extensible. Through the official hub you can add extra functionality for crypto tracking, project management, CRM integrations and more.

For companies wrestling with the question “how do we put AI to productive use?”, OpenClaw seems to offer an answer: an agent that doesn’t just talk but actually takes work off your hands. And does so entirely on its own.

Food for Thought: the downside you need to know about

Now comes the part we at Artific want to draw attention to. Because however enthusiastic we are about every development in AI, the shiny OpenClaw demos don’t show the risks attached to the way OpenClaw works today. The “Don’t try this at home” disclaimer is missing, and that is unhelpful, to say the least.

Our GenAI Research Lab dug into the security aspects of OpenClaw. The findings are worrying. To name just a few:

1. Prompt injection: the elephant in the room

This is the biggest risk. And it is not hypothetical.

Prompt injection means an attacker hides malicious instructions in content your AI assistant processes, such as an email, a web page or a document. The AI then follows those hidden instructions instead of your commands.

Security researcher Matvey Kukuy (CEO of Archestra AI) demonstrated this live: he sent an email with hidden instructions to an OpenClaw system and had obtained a private key within five minutes.

Another documented incident: hidden instructions in an email made OpenClaw delete every email, including the bin.

This is not an edge case. It is a fundamental problem with AI agents that process external content.

2. Hundreds of unsecured gateways on the open internet

Security researcher Jamieson O’Reilly found more than 900 OpenClaw installations that were reachable over the internet with no protection at all. No authentication. Some were even running as root.

What does that mean in practice? Outsiders could:

  • View API keys for OpenAI and Anthropic
  • Retrieve bot tokens for Telegram and Discord
  • Intercept OAuth secrets for Slack and Google
  • Read back complete conversation histories going back months
  • Run shell commands on the host machine

The cause? A default configuration that automatically approves localhost connections, combined with misconfigured reverse proxies.

3. Credentials in plain text

OpenClaw stores secrets in ordinary Markdown and JSON files. Readable by anyone (or any program) with access to those folders.

That makes the tool an attractive target for commodity infostealers such as RedLine, Lumma and Vidar, malware that specifically looks for the configuration files of developers and power users.

4. No sandboxing by default

The AI agent has the same access rights as the user. Running OpenClaw under your own account? Then the agent can do everything you can. Delete files, run scripts, open connections.

The official documentation acknowledges the problem with the understatement of the year: “Running an AI agent with shell access on your machine is… spicy.”

5. Supply-chain risks through Skills

The Skills system that makes OpenClaw so flexible also introduces supply-chain risks. O’Reilly demonstrated this by publishing a malicious Skill on the official MoltHub registry and manipulating its download count so it looked like the most popular asset.

That way an attacker can get code running on thousands of systems at once.

The rebrand chaos as a bonus

As if the security concerns were not enough, the name change from Clawdbot to Moltbot (after a trademark request from Anthropic) and now to OpenClaw turned into a small disaster of its own.

In the ten seconds between releasing the old GitHub and X accounts and claiming the new ones, scammers hijacked both handles. Fake crypto tokens appeared and reached a market capitalisation of 16 million dollars before Steinberger publicly denied that there were any official tokens.

This illustrates a wider point: the popularity of open-source projects attracts not only enthusiasts but also people with bad intentions.

So how should you do it? A security checklist for the brave

Does this mean you should avoid OpenClaw? Not necessarily. But if you do want to work with it, there are minimum controls you need to put in place.

Minimum requirements for a safe pilot

  • Principle of least privilege: start with read-only access and narrow scopes, and expand slowly.
  • Separate service accounts: never run your first deployment with personal admin access.
  • Secrets management: API keys, tokens and webhooks must be stored securely and rotated regularly. Assume infostealers are looking for developer configs.
  • Prompt injection defences: treat incoming messages (DMs, emails, tickets) as untrusted content.
  • Logging and audit trails: every action must be traceable and reviewable.
  • Blast radius design: if the agent is compromised, it must not be able to move laterally through critical systems.

Additional hardening steps

  • Check your gateway configuration: bind: "loopback" keeps your gateway from being reachable from the internet
  • Turn on authentication: gateway.auth.mode: "password" or "token"
  • Configure trusted proxies correctly when you use reverse proxies
  • Use dmPolicy: "pairing" to require approval for unknown senders
  • Consider Claude Opus 4.5 as the model: Anthropic claims around 99% resistance to prompt injection, although it is expensive
  • Run OpenClaw on dedicated, expendable hardware, not your main workstation
  • Implement content quarantine: treat everything from email and the web as potentially hostile

Our view: promising, but the market is not ready yet

At Artific we see OpenClaw as a fascinating glimpse of the future. The vision of autonomous AI agents that actually get work done is exactly where the market is heading.

But, and this is an important but, the security foundations are not in place yet.

There is currently no 100% effective solution to prompt injection. It is an open research question that we are working on in our Research Lab too.

Until these fundamental problems are solved, our advice is:

  • Hold off on production deployments. OpenClaw is interesting for experiments and pilots in controlled environments, not for business-critical processes.
  • Understand the risks. The features that make OpenClaw useful (access to your system, messages and files) are exactly the features that make it dangerous.
  • Follow the developments. The field of AI agent security is moving fast. What is unsafe today may be solved in six months.

And above all, we advise you to talk to Artific first. Our AI platform, developed in the Netherlands, is designed with Security and Privacy by Design as its starting point. Artific is fully independent of platforms and language models, and we already support more than 35 language model variants. We build virtual employees that are secure and reliable. Tested by ethical hackers.

The future is undoubtedly agentic. But we will only get there if we take security seriously, not as an afterthought, but as the foundation.

This article was written by the Artific GenAI Research Lab. We actively research both the possibilities and the risks of generative AI for business use. Questions, or want to talk through AI implementation in your organisation? Get in touch with us.

Sources

Back to the knowledge centre