HomeSecurityOpenClaw: How an open source AI agent can be hijacked

OpenClaw: How an open source AI agent can be captured

When the open-source AI agent OpenClaw burst onto the scene, it did so with astonishing speed. In just five days, the project surpassed 100,000 stars on GitHub, making it one of the fastest-growing open-source AI tools in history. Developers quickly embraced it as a personal assistant that could run locally, connect to calendars and messaging platforms, execute system commands, and manage workflows autonomously.

See also: SecureClaw: OpenClaw's security problems continue

OpenClaw: How an open source AI agent can be captured

However, beneath this meteoric rise, researchers discovered the OpenClaw vulnerability, a weakness that allowed any website visited by a developer to silently capture the agent.

Security researchers at Oasis Security have identified what they describe as a full-blown vulnerability chain in the core architecture of OpenClaw. The chain allowed a malicious website to take over a developer’s AI agent without requiring any plugins, browser extensions, or any form of user interaction. After receiving the disclosure, the OpenClaw team classified the issue as “High” severity and released an update within 24 hours.

Originally released under the names Clawdbot and later MoltBot, OpenClaw quickly became a prime example of modern open-source AI innovation. Its explosive popularity even caught the attention of OpenAI. On February 15, OpenAI CEO Sam Altmanannounced that OpenClaw creator Peter Steinberger had joined the company, calling him “a genius with a lot of amazing ideas for the future of highly intelligent agents.” The tool’s appeal lies in its autonomy.

Through a web control panel or terminal interface, users can ask OpenClaw to send messages, manage workflows across platforms, execute commands, and even participate in what some have described as an emerging AI social network.

It operates as a locally hosted agent, putting powerful capabilities directly on developers’ laptops. However, that power has already attracted abuse. Earlier this month, researchers discovered more than 1,000 malicious “skills” on OpenClaw’s community marketplace, ClawHub. These fake add-ons were presented as cryptocurrency utilities or productivity integrations, but instead delivered information-stealing malware and backdoors.

This episode was a classic supply chain problem. However, the OpenClaw vulnerability was different.

See also: OpenClaw: Infostealer steals configuration files and gateway tokens

OpenClaw: How an open source AI agent can be captured

It did not rely on third-party plugins or downloads from the marketplace. Instead, the vulnerability chain lived in the OpenClaw portal itself, operating exactly as documented. No user-installed extensions were required. No interaction with the marketplace was necessary. The flaw was built into the core system.

Tools like OpenClaw are often adopted directly by developers without formal IT oversight. They often operate with deep access to local systems, credentials, message histories, and API keys, but without centralized governance or visibility.

At the heart of the OpenClaw architecture is the gateway, a local WebSocket server that acts as the brain of the system. The gateway handles authentication, chat sessions, configuration storage, and AI agent organization.

Connected to it are “nodes,” which can include a companion app for macOS, an iOS device, or other machines. These nodes register with the gateway and expose capabilities such as executing shell commands, accessing cameras, or reading contacts. The gateway can send instructions to any connected node. Authentication is done either through a long key string or a password.

By default, the gateway connects to localhost, operating under the assumption that local access is inherently trusted. This assumption proved to be the weak link in the vulnerability chain behind the OpenClaw vulnerability.

In lab tests, researchers achieved hundreds of password guesses per second using only browser-based JavaScript. A list of common passwords could be exhausted in less than a second. Even a large dictionary would fall, within minutes.

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

The researchers note that the Agentic Access Management was specifically designed to address this emerging challenge.

See also: OpenClaw integrates VirusTotal scanning to detect malicious ClawHub skills

OpenClaw: How an open source AI agent can be captured

As open source AI agents like OpenClaw become integrated into developers’ daily workflows, the OpenClaw vulnerability serves as a cautionary tale. The future may indeed belong to autonomous agents, but without proper governance and oversight, a single overlooked vulnerability chain can turn groundbreaking open source AI innovation into a serious business risk.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr
Being your self, in a world that constantly tries to change you, is your greatest achievement

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS