Skip to main content
See every side of every news story
Published loading...Updated

What Is OpenClaw, Formerly Moltbot? Everything You ...

Researchers disclosed critical security flaws in OpenClaw and Moltbook enabling remote code execution and data breaches affecting over 1.6 million AI agents, raising major cybersecurity concerns.

  • Recently, OpenClaw's GitHub release in November and Moltbook's launch drove mass agent activity with over 1.6 million registered bots and 7.5 million AI posts, while researchers catalog vulnerabilities.
  • OpenClaw's default settings left it exposed with powerful local privileges, full system access, and network-reachable control interfaces plus MCP shipping without security and gateways bound to 0.0.0.0, while Moltbook had an embedded key unlocking its backend.
  • Security researchers demonstrated that a malicious link could leak Gateway UI tokens via a WebSocket exploit, enabling operator-level access, and replicated a one-click account takeover leading to RCE alongside the tracked high-severity flaw CVE-2026-25253.
  • Security firms warn that the incident exposed tens of thousands of emails, about 1.5 million API keys and private messages, and OpenClaw hosts 386 malware-infected skills used by attackers.
  • Researchers note that the explosion of agent interactions offers scientific insights, while enterprises face a shadow IT problem as OpenClaw gains over 160,000 GitHub stars, prompting calls for identity‑based controls, sandboxes, audits, and updated AI policies.
Insights by Ground AI

16 Articles

Think freely.Subscribe and get full access to Ground NewsSubscriptions start at $9.99/yearSubscribe

Bias Distribution

  • 50% of the sources are Center
50% Center

Factuality Info Icon

To view factuality data please Upgrade to Premium

Ownership

Info Icon

To view ownership data please Upgrade to Vantage

The New Stack broke the news in on Thursday, February 5, 2026.
Too Big Arrow Icon
Sources are mostly out of (0)

Similar News Topics

News
Feed Dots Icon
For You
Search Icon
Search
Blindspot LogoBlindspotLocal