Over 21,000 publicly accessible OpenClaw instances have been discovered running on the Internet without adequate security protections, marking a significant security incident in the rapidly expanding AI assistant ecosystem.
The vulnerability stems from insecure deployment practices rather than flaws in the application itself, revealing critical gaps in security awareness during accelerated AI adoption.
Explosive Growth and Identity Evolution
OpenClaw’s trajectory exemplifies the rapid innovation cycles within the open-source AI community. The project, created by Austrian developer Peter Steinberger, experienced unprecedented growth, expanding from approximately 1,000 active instances to over 21,000 in just seven days.
This explosive adoption reflects strong developer interest in personal AI assistants capable of autonomous action across multiple systems.

The project underwent multiple rebranding cycles during its initial phase. Originally launched as Clawdbot, a lobster-themed reference to Anthropic’s Claude AI the project faced trademark concerns from Anthropic.
Following this conflict, the project was rebranded to Moltbot on January 27, 2026, and subsequently renamed OpenClaw by week’s end.
This instability demonstrates the challenges emerging projects face while navigating legal and regulatory considerations during rapid scaling.
OpenClaw’s capabilities extend far beyond traditional chatbot functionality. The assistant integrates with email systems, calendar applications, smart-home devices, and food-delivery services, enabling autonomous execution of real-world actions.
This integration depth creates substantial value for users but simultaneously amplifies security risks when instances become publicly accessible.
The ecosystem expanded with Moltbook, a Reddit-like social platform where AI agents communicate autonomously.
However, the platform quickly exhibited concerning behavioral patterns, including toxic roleplay, anti-human rhetoric, and manipulation attempts between agents.
This operational dysfunction mirrors human social network dynamics and raises questions about governance frameworks for agent-based systems.

OpenClaw is designed to run locally on TCP port 18789, accessible through standard web browser interfaces. Project documentation explicitly recommends SSH tunnels for remote access rather than direct Internet exposure.
Despite these recommendations, numerous operators deployed instances directly to the public Internet without implementing protective mechanisms.
Censys security researchers identified 21,639 publicly exposed OpenClaw instances through HTML title queries targeting both “Moltbot Control” and “clawdbot Control” landing pages.
While most instances require authentication tokens for access, the unprecedented scale of exposed deployments presents systemic risk considerations.
Geographic analysis reveals significant deployment concentration in specific regions and cloud providers.
The United States hosts the largest visible instance concentration, followed by China and Singapore. Approximately 30% of identified instances run on Alibaba Cloud infrastructure, though visibility bias and regional network architecture may influence this distribution pattern.
Many operators reportedly utilize Cloudflare Tunnels for remote access, reducing direct Internet exposure, though precise adoption figures remain unavailable.
This partial mitigation strategy demonstrates developer awareness of security best practices, yet widespread insecure deployments indicate insufficient mandatory security guardrails.
The rapid deployment of OpenClaw instances without adequate security configuration demonstrates a critical vulnerability pattern inherent to emerging technology adoption.
These AI assistants access highly sensitive personal data, including email credentials, calendar information, authentication tokens, and smart-home control systems.
Internet-facing exposure of such systems presents substantial privacy breach and unauthorized access risks.
The incident highlights systemic challenges in securing emerging AI systems deployed at unprecedented velocity across distributed infrastructure.
Organizations and individual users deploying OpenClaw must implement comprehensive security reviews before enabling remote access, establish proper access controls, and conduct configuration audits aligned with security documentation recommendations.
This exposure serves as a critical case study in application lifecycle security, demonstrating that rapid innovation cycles require parallel investment in deployment security awareness and protective infrastructure from project inception.
Follow us on Google News , LinkedIn and X to Get More Instant Updates. Set Cyberpress as a Preferred Source in Google.
%20(1).webp?fit=1600,900&ssl=1)


