HACKS VITAE

TOOLS & TECH · SOURCES SHOWN

Clawdbot AI
A Leap Towards Sovereign Agentic Workflow

PRICES, VERSIONS AND FACTS AS OF SEPTEMBER 2026

Clawdbot is now OpenClaw, a self-hosted AI assistant you talk to through chat apps. What it is, how it got its name, its security record as of September 2026, and what the Moltbook database exposure showed.

7 SECTIONS · HOVER A POINT TO JUMP
Published
February 3, 2026
Updated
September 29, 2026
Facts as of
September 2026
Read
9 min
Sections
7

BACKGROUND · REMBRANDT, HERMAN DOOMER, 1640 · THE MET, OPEN ACCESS

THE SHORT VERSION

  1. Clawdbot is now OpenClaw. It started in November 2025, became Moltbot on 27 January 2026 after a trademark request from Anthropic, and took the name OpenClaw on 29 January 2026.
  2. It is an open-source assistant that runs on your own computer and that you talk to through chat apps such as WhatsApp, Telegram or Slack. Its memory is plain Markdown files on your disk.
  3. Its security record is real: malicious skills on its ClawHub marketplace, a fake “ClawdBot Agent” VS Code extension carrying remote-access software, a no-password gateway mode removed in release 2026.1.29, and a one-click token leak (CVE-2026-25253) fixed in the same release.
  4. Prompt injection is not solved, in the project's own words.
  5. Moltbook, a social network for AI agents, left its database open in early 2026: Wiz found 1.5 million agent API tokens readable, and some plaintext OpenAI keys in private messages, because Row Level Security was missing.

THE ARTICLE · 9 MIN

Name check, September 2026. This project has had several names. It began in November 2025 as a weekend project its creator calls “WhatsApp Relay” (published on npm as warelay), then became known as Clawdbot, became Moltbot on 27 January 2026 after a trademark request from Anthropic, and was renamed OpenClaw on 29 January 2026. If you go looking for it, OpenClaw is the name to search.

Clawdbot AI: Architecting the Sovereign Agentic Workflow

OpenClaw (formerly Clawdbot) is an open-source AI assistant that you run on your own computer and talk to through the chat apps you already use. Its creator, Peter Steinberger, wrote on the day of the rename that it “started as ‘WhatsApp Relay’”, and described it as “an open agent platform that runs on your machine and works from the chat apps you already use”.

According to the project’s own site, it runs on Mac, Windows or Linux; it works with hosted, subscription-backed or local language models; and its state “lives on your machine, not a vendor cloud”. The site lists WhatsApp, Telegram, Discord, Slack, Signal and iMessage among its 29 chat channels.

The name story, in the project’s words: the assistant was first called Clawd, “a playful pun on ‘Claude’ with a claw”, until “Anthropic’s legal team politely asked us to reconsider”. Moltbot came next; the creator wrote that it “never quite rolled off the tongue”, and OpenClaw followed two days later.

Since 8 July 2026 the project has been stewarded by the OpenClaw Foundation, which it describes as an independent US 501(c)(3) non-profit. The project says the code stays MIT licensed and that there is no paid version.

The Evolution of the “Invisible” Executive Assistant

Most AI chat tools wait in a browser tab for you to type. OpenClaw works the other way round: the assistant lives in your messaging apps, and it can also start work on its own. Its documentation describes “tasks, scheduled jobs, event hooks, and standing instructions” that run in the background.

The project’s homepage says it “organizes your inbox, sends emails, manages your calendar, checks you in for flights”. Those are the project’s own claims about what it can be set up to do, not something we have tested.

The idea that switching to a browser tab is what stops people from using AI every day is an argument, not a measured finding. What is different is the shape: an assistant that can act first, on a schedule or a trigger, instead of only answering when asked.

The Sovereign Intelligence Framework

One way to picture OpenClaw (our own summary, not the project’s terms) is as three layers:

LayerWhat it is
The GatewayA single long-running process on your machine that owns the chat connections. By default the apps that control it connect on 127.0.0.1, your own computer.
The MemoryPlain Markdown files in the agent’s workspace (by default ~/.openclaw/workspace), such as MEMORY.md for long-term facts and dated daily notes.
The SkillsFolders containing a SKILL.md file: Markdown instructions that teach the agent how and when to use tools. Community skills are shared through a marketplace called ClawHub.

The documentation puts the memory point plainly: “The model only remembers what gets saved to disk; there is no hidden state.”

What self-hosting changes, and what it doesn’t

  • You can see what it remembers. Because memory is ordinary files, you can read, back up or edit it, and the files stay where they are if you switch to a different model provider.
  • Your data sits on your machine, and so does the job of protecting it. The same shell access, file access and messaging access that make the assistant useful are what an attacker would want.
  • The model is not automatically local. If you connect a hosted model, what you ask the agent still goes to that model’s provider. Only a local model keeps the requests on your hardware.

Before you self-host this: the security record

An assistant that can read your messages, run commands and install add-ons has a lot of access, and OpenClaw’s first months had real security problems. Four are well documented.

  • Malicious skills on ClawHub. In early February 2026 the security firm Koi Security reported that an audit of 2,857 skills on ClawHub had found 341 malicious ones, according to The Hacker News. Of those, 335 used fake “prerequisites” to get users to install a macOS information stealer called Atomic Stealer (AMOS). On 7 February 2026 the project announced that every skill published to ClawHub is now scanned with VirusTotal, and said in the same post: “this is not a silver bullet”.
  • A fake VS Code extension. On 27 January 2026 the security firm Aikido flagged a VS Code extension called “ClawdBot Agent”. It did work, as a coding assistant, while installing ScreenConnect remote-access software connected to the attackers’ server. Aikido notes that the real project “never published an official VS Code extension”; Microsoft removed the fake one after Aikido reported it.
  • A no-password mode, removed. Before release 2026.1.29, the gateway could be set to an authentication mode of “none”. That release’s notes say: “Gateway auth mode “none” is removed; gateway now requires token/password (Tailscale Serve identity still allowed).”
  • A one-click token leak, fixed in the same release. The US National Vulnerability Database records it as CVE-2026-25253: versions before 2026.1.29 took a gateway address from a link’s query string and connected to it automatically, without prompting, “sending a token value”. It is rated 8.8 out of 10 on the CVSS 3.1 scale. The project’s own advisory says an attacker holding that token could change the gateway’s settings and run code on the machine, and that this worked even on installs listening only on the user’s own computer, because the victim’s browser made the connection.

Where things stand, September 2026. The project’s security page, reviewed on 9 September 2026, counts 1,799 vulnerability reports filed since January 2026 and 722 fixes published, 39 of them with a CVE number. It lists 14 confirmed critical issues, all fixed and disclosed, and says it knows of no compromise of its own infrastructure or official install channels; that statement does not cover third-party ClawHub skills. On 21 September 2026 the project published the results of an audit by the security firm Trail of Bits: 24 severity-rated reports, none critical, and, the project says, every actionable issue repaired.

What the project’s own documentation describes. A regular install binds the gateway to loopback, meaning only your own machine can reach it. Container images are the exception: they default to an exposed bind, which the documentation says to pair with authentication. An openclaw security audit command reports when a setup has drifted from those defaults. On skills, the VirusTotal announcement adds: “A clean scan doesn’t mean a skill is safe.”

Prompt injection is not solved. On the day of the rename, the creator wrote: “Remember that prompt injection is still an industry-wide unsolved problem”. An agent that reads your email and can run commands can be steered by text hidden in an email.

Moltbook: the agents’ forum and its breach

Moltbook is a social network built for AI agents. Its homepage describes it as a place “where AI agents share, discuss, and upvote. Humans welcome to observe.” Its topic groups are called submolts.

In late January 2026 the security firm Wiz found that Moltbook’s database was open to anyone. What follows is from Wiz’s disclosure.

What went wrong. Moltbook was built on Supabase. Wiz found the site’s Supabase API key in its client-side JavaScript. Wiz explains that this kind of key is safe to expose when Row Level Security is set up, but Row Level Security was missing, so the key gave “unauthenticated access to the entire production database - including read and write operations on all tables”.

What was exposed. Wiz counted around 4.75 million records, including:

  • 1.5 million API authentication tokens for agents on the platform, which Wiz says would let an attacker “fully impersonate any agent on the platform”
  • 35,000 email addresses, in Wiz’s summary; its write-up also describes a separate table of 29,631 early-access sign-up emails
  • 4,060 private conversations between agents, some of which contained third-party credentials, including plaintext OpenAI API keys, that agents had shared

Anyone could also write to the database, which means they could change posts that thousands of agents were reading.

The numbers behind the platform. Moltbook said it had 1.5 million registered agents. Wiz found about 17,000 human owners behind them, and no way for the platform to check whether an “agent” was actually AI or a person with a script.

The fix. Wiz first contacted Moltbook’s maintainer at 21:48 UTC on 31 January 2026, and after several rounds of fixes all tables were secured by 01:00 UTC on 1 February 2026. Wiz says the data it accessed during the research was deleted. Wiz also notes that the security researcher Jamieson O’Reilly had found the same misconfiguration independently.

The lesson Wiz draws is that “the issue ultimately traced back to a single Supabase configuration setting”. None of this involved an agent doing something unexpected. It was ordinary web security, left undone.

What you can take from this

  • Names change fast in this field. A tool that went viral as Clawdbot in January 2026 has been OpenClaw since the end of that month, and advice written under the old names may be out of date.
  • Add-ons are code. Both the ClawHub skills and the fake VS Code extension worked because they looked legitimate. The project’s own advice is to review what a skill asks for and to start with publishers you trust.
  • A “private” message is only as private as the database behind it. Wiz’s point about Moltbook is that people shared API keys in messages they assumed were private, and one configuration setting made them readable.
  • The project’s own security page is the up-to-date record. It is dated, it lists current advisories, and it will be newer than anything written about the project, this page included.

Sources

  • Peter Steinberger, “Introducing OpenClaw”, OpenClaw blog, 29 January 2026. openclaw.ai
  • OpenClaw homepage. openclaw.ai
  • Dave Morin and Peter Steinberger, “Introducing the OpenClaw Foundation”, OpenClaw blog, 8 July 2026. openclaw.ai
  • OpenClaw documentation: Gateway architecture, Memory overview, Skills, Automation, Security. docs.openclaw.ai
  • OpenClaw GitHub repository and release 2026.1.29. github.com
  • npm registry, package warelay. registry.npmjs.org
  • National Vulnerability Database, CVE-2026-25253. nvd.nist.gov
  • “Clawdbot Rebrands to Moltbot After Trademark Request From Anthropic”, Laravel News, 27 January 2026. laravel-news.com
  • “Researchers Find 341 Malicious ClawHub Skills Stealing Data from OpenClaw Users”, The Hacker News, 2 February 2026. thehackernews.com
  • Peter Steinberger, Jamieson O’Reilly and Bernardo Quintero, “OpenClaw Partners with VirusTotal for Skill Security”, OpenClaw blog, 7 February 2026. openclaw.ai
  • Aikido Security, “Fake Clawdbot VS Code Extension Installs ScreenConnect RAT”. aikido.dev
  • OpenClaw, “Security” status page, reviewed 9 September 2026. openclaw.ai/security
  • Josh Avant, “OpenClaw Completes Security Audit Through OpenAI’s Patch the Planet Initiative”, OpenClaw blog, 21 September 2026. openclaw.ai
  • Moltbook homepage. moltbook.com
  • Wiz, “Hacking Moltbook: The AI Social Network Any Human Can Control”. wiz.io

Checked September 2026. Everything on this page describes a fast-changing project as of September 2026. Version numbers, defaults and the security figures change often; the project’s own security page and repository are the place to check before acting on any of it. If you can show any of this wrong, with a source, write to hacksvitae@gmail.com.

  • openclaw
  • ai agents
  • security
  • software

SHARE & CITE

Hacks Vitae. "Clawdbot AI: A Leap Towards Sovereign Agentic Workflow." February 3, 2026. https://www.hacksvitae.com/life-hack/clawdbot-ai-sovereign-agentic-workflow

That's what we found. The rest is your call.

118 articles, each with its sources listed. Spotted something off? hacksvitae@gmail.com

Open the library