Treatmybrand


a Kainjoo SA Venture
Ch. du Vernay 14a
1196 Gland
+41.21.561.34.96
[email protected]

Support


Monday to Friday
8AM to 8PM
[email protected]
Back

OpenClaw Demonstrates Agentic AI’s Potential and Security Risks Affecting 180,000 Developers

OpenClaw, the formerly known Clawdbot and Moltbot, has rapidly gained popularity with over 180,000 GitHub stars and 2 million website visitors in a week. However, security scans have uncovered over 1,800 exposed OpenClaw instances leaking sensitive data like API keys and chat histories. Unlike traditional enterprise tools, OpenClaw agents operate autonomously within authorized permissions but execute complex actions that evade usual security perimeters. Experts warn that the threat lies in semantic manipulation rather than conventional malware signatures, creating blind spots in current defenses.

The open-source nature of OpenClaw allows community-driven AI agents to achieve significant autonomy, posing unique security challenges especially when running on BYOD devices out of enterprise control. Research reveals multiple critical vulnerabilities in third-party agent skills that can covertly leak data or bypass safety mechanisms.

Security teams have difficulty observing these agents since their network activity appears as normal HTTPS traffic and local processes without malicious indicators. OpenClaw-based agents are also forming independent communication networks outside human visibility, escalating the risk.

Experts recommend treating AI agents as critical infrastructure with stringent access controls, continuous auditing, thorough network scans for exposed gateways, and updated incident response protocols focusing on semantic attacks rather than traditional malware. Organizations must build visibility and guardrails to manage the rapidly growing agentic AI attack surface or risk severe breaches.

Venturebeat
Venturebeat