OpenClaw , one of the most popular AI assistants released in November 2025, has raised serious concerns in the cybersecurity field. This autonomous AI tool, previously known as ClawdBot and Moltbot , has the ability to perform tasks on a user’s computer without supervision, but at the same time introduces new risks that fundamentally change the security priorities of organizations.
See also: OpenClaw: How an open source AI agent can be hijacked

AI -based assistants like OpenClaw are autonomous programs that access a user's computer, files, and online services and can automate almost any task. Their popularity is growing rapidly among developers and IT workers, as they offer unprecedented automation capabilities.
OpenClaw is particularly useful when it has full access to the user's digital life, managing incoming messages and calendar, running programs and tools, browsing the web for information, and integrating with chat apps like Discord , Signal , Teams , or WhatsApp . Unlike other established AI assistants like Anthropic 's Claude and Microsoft 's Copilot , OpenClaw is designed to take initiatives based on understanding the user's life.
Serious OpenClaw Security Issues
Despite its impressive capabilities, this experimental technology can lead to unexpectedproblems. In late February, Summer Yue, director of security at Meta, described on Twitter how OpenClaw began mass-deleting messages from her inbox. The post included screenshots of Yue pleading with the bot via direct messages to stop.
See also: SecureClaw: OpenClaw's security problems continue

The risk posed by poorly secured AI assistants to organizations is significant, with recent research showing that many users are exposing the web-based administrative interface of their OpenClaw to the internet. Jamieson O'Reilly, a professional penetration tester and founder of security firm DVULN, warned that exposing a poorly configured OpenClaw allows external parties to read the bot's full configuration file.
According to analysis by Cisco researchers , OpenClaw is a “security nightmare” due to its access to shell commands, which allows the execution of malware-like skills. SentinelOne researchers also identified SSRF (Server-Side Request Forgery) risks for network identification and access to cloud metadata.
Protection Recommendations and Future Challenges
Experts recommend immediately updating to the latest versions beyond 2026.1.29 and 2026.2.14, enabling gateway authentication, and deploying behind a reverse proxy with origin validation. Organizations should log all deployments and treat exposed or out-of-date installations as security incidents.
Immersive Labs and Bitsight highlighted the dangers of the insecure default settings, while the project’s maintainers admitted that there is no “perfectly secure” installation and called it “very dangerous” for non-experts. China’s Ministry of Industry and Information Technology (MIIT) issued warnings citing the violations, according to Krebs on Security.
See also: Six security vulnerabilities identified in the OpenClaw system

As AI assistants continue to evolve, organizations must rethink their security strategies to address these new risks that blur the lines between data and code, trusted partner and insider threat.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
