{"id":405961,"date":"2026-02-03T17:26:10","date_gmt":"2026-02-03T17:26:10","guid":{"rendered":"https:\/\/www.newsbeep.com\/uk\/405961\/"},"modified":"2026-02-03T17:26:10","modified_gmt":"2026-02-03T17:26:10","slug":"diy-ai-bot-farm-openclaw-is-a-security-dumpster-fire-the-register","status":"publish","type":"post","link":"https:\/\/www.newsbeep.com\/uk\/405961\/","title":{"rendered":"DIY AI bot farm OpenClaw is a security &#8216;dumpster fire&#8217; \u2022 The Register"},"content":{"rendered":"<p>OpenClaw, the AI-powered personal assistant users interact with via messaging apps and sometimes entrust with their credentials to various online services, has prompted a wave of malware and is delivering some shocking bills.<\/p>\n<p>Just last week, OpenClaw was known as Clawdbot, a name that its developers changed to Moltbot before settling on the new moniker.<\/p>\n<p>The project, based on <a target=\"_blank\" href=\"https:\/\/lucumr.pocoo.org\/2026\/1\/31\/pi\/\" rel=\"nofollow noopener\">the Pi coding agent<\/a>, launched in November. It recently attracted the attention of developers with large social media followings like <a target=\"_blank\" href=\"https:\/\/simonwillison.net\/2026\/Jan\/30\/moltbook\/\" rel=\"nofollow noopener\">Simon Willison<\/a> and <a target=\"_blank\" href=\"https:\/\/x.com\/karpathy\/status\/2017442712388309406?s=20\" rel=\"nofollow\">Andrej Karpathy<\/a>, leading to an explosion in popularity that quickly saw researchers and users find nasty flaws.<\/p>\n<p>In the past three days, the project has issued three high-impact security advisories: <a target=\"_blank\" href=\"https:\/\/www.theregister.com\/2026\/02\/02\/openclaw_security_issues\/\" rel=\"nofollow noopener\">a one-click remote code execution vulnerability<\/a>, and two <a target=\"_blank\" href=\"https:\/\/github.com\/openclaw\/openclaw\/security\/advisories\/GHSA-q284-4pvr-m585\" rel=\"nofollow noopener\">command<\/a> <a target=\"_blank\" href=\"https:\/\/github.com\/openclaw\/openclaw\/security\/advisories\/GHSA-mc68-q9jw-2h3v\" rel=\"nofollow noopener\">injection<\/a> vulnerabilities.<\/p>\n<p>In addition, Koi Security identified <a target=\"_blank\" href=\"https:\/\/www.koi.ai\/blog\/clawhavoc-341-malicious-clawedbot-skills-found-by-the-bot-they-were-targeting\" rel=\"nofollow noopener\">341 malicious skills<\/a> (OpenClaw extensions) submitted to <a target=\"_blank\" href=\"https:\/\/www.clawhub.ai\/\" rel=\"nofollow noopener\">ClawHub<\/a>, a repository for OpenClaw skills that&#8217;s been around for about a month. This was after security researcher Jamieson O&#8217;Reilly <a target=\"_blank\" href=\"https:\/\/x.com\/theonejvo\/status\/2015892980851474595\" rel=\"nofollow\">detailed<\/a> how it would be trivial to backdoor a skill posted to ClawHub. Community-run threat database OpenSourceMalware also spotted a skill that <a target=\"_blank\" href=\"https:\/\/opensourcemalware.com\/blog\/clawdbot-skills-ganked-your-crypto\" rel=\"nofollow noopener\">stole cryptocurrency<\/a>.<\/p>\n<p>Mauritius-based security outfit Cyberstorm.MU has also <a target=\"_blank\" rel=\"nofollow\" href=\"https:\/\/x.com\/CyberstormMu\/status\/2018423603327340619\/\">found<\/a> <a target=\"_blank\" rel=\"nofollow\" href=\"https:\/\/x.com\/CyberstormMu\/status\/2018402654242615399\">flaws<\/a> in OpenClaw skills. The group <a target=\"_blank\" rel=\"nofollow\" href=\"https:\/\/x.com\/CyberstormMu\/status\/2018173307657351437\">contributed<\/a> to OpenClaw&#8217;s code with a commit that will make TLS 1.3 the default cryptographic protocol for the gateway the project uses to communicate with external services.<\/p>\n<p>The list of <a target=\"_blank\" href=\"https:\/\/github.com\/openclaw\/openclaw\/issues?q=is%3Aissue%20state%3Aopen%20security\" rel=\"nofollow noopener\">open security-related issues<\/a> may also elicit some concern, to say nothing of the <a target=\"_blank\" href=\"https:\/\/www.wiz.io\/blog\/exposed-moltbook-database-reveals-millions-of-api-keys\" rel=\"nofollow noopener\">exposed database<\/a> for the related, <a target=\"_blank\" href=\"https:\/\/x.com\/mattprd\/status\/2017386365756072376\" rel=\"nofollow\">vibe-coded<\/a> Moltbook project, which is presented as a social media platform for AI agents. A recent <a target=\"_blank\" href=\"https:\/\/zeroleaks.ai\/reports\/openclaw-analysis.pdf\" rel=\"nofollow noopener\">security scan with AI software<\/a> [PDF] from a startup called <a target=\"_blank\" href=\"https:\/\/github.com\/ZeroLeaks\/zeroleaks\" rel=\"nofollow noopener\">ZeroLeaks<\/a> <a target=\"_blank\" href=\"https:\/\/x.com\/NotLucknite\/status\/2017967447089750220?s=20\" rel=\"nofollow\">doesn&#8217;t exactly inspire confidence<\/a>, though these claims have not been validated by human security experts.<\/p>\n<p>Dumpster fire<\/p>\n<p>&#8220;OpenClaw is a security dumpster fire,&#8221; observed Laurie Voss, head of developer relations at Arize and the founding CTO of npm, in <a target=\"_blank\" href=\"https:\/\/www.linkedin.com\/posts\/seldo_openclaw-analysispdf-activity-7423936260798484480-8qK_?utm_source=share&amp;utm_medium=member_desktop&amp;rcm=ACoAAAAEUrwBGDapdyAWPL2MZIjljoJFUQRWVlo\" rel=\"nofollow noopener\">a post<\/a> to LinkedIn.<\/p>\n<p>Karpathy last week tried <a target=\"_blank\" href=\"https:\/\/x.com\/karpathy\/status\/2017442712388309406\" rel=\"nofollow\">to clarify<\/a> that he recognizes <a target=\"_blank\" href=\"https:\/\/www.moltbook.com\/\" rel=\"nofollow noopener\">Moltbook<\/a> is &#8220;a dumpster fire&#8221; full of fake posts and security risks, and that he does not recommend that people run OpenClaw on their computers, even as he finds the idea of a large network of autonomous LLMs intriguing.<\/p>\n<p>Researchers Michael Alexander Riegler and Sushant Gautam recently co-authored <a target=\"_blank\" href=\"https:\/\/zenodo.org\/records\/18444900\" rel=\"nofollow noopener\">a report<\/a> analyzing Moltbook posts \u2013 remember these are AI agents (OpenClaw and others) chatting with one another. As might be expected, the bots tend to go off the (guard)rails when kibitzing.<\/p>\n<p>The authors say they identified &#8220;several critical risks: 506 prompt injection attacks targeting AI readers, sophisticated social engineering tactics exploiting agent &#8216;psychology,&#8217; anti-human manifestos receiving hundreds of thousands of upvotes, and unregulated cryptocurrency activity comprising 19.3 percent of all content.&#8221;<\/p>\n<p>Undeterred by this flock of stochastic parrots, people continue to experiment with OpenClaw, often at greater expense than they expected.<\/p>\n<p>Benjamin De Kraker, an AI specialist at The Naval Welding Institute who formerly worked on xAI&#8217;s Grok, published <a target=\"_blank\" href=\"https:\/\/x.com\/BenjaminDEKR\/status\/2017644773356548532\" rel=\"nofollow\">a post<\/a> on Saturday about OpenClaw burning through $20 worth of Anthropic API tokens while he slept, simply by checking the time.<\/p>\n<p>The &#8220;heartbeat&#8221; cron job he had set up to issue a reminder to buy milk in the morning checked the time every 30 minutes. It did so rather inefficiently, sending around 120,000 tokens of context describing the reminder to Anthropic&#8217;s Claude Opus 4.5.2 model. Each time check therefore cost about $0.75 and the bot ran about 25 of them, amounting to almost $20. The potential cost just to run reminders over a month would be about $750, he calculated.<\/p>\n<p><a target=\"_blank\" href=\"https:\/\/rezhajul.io\/posts\/reducing-openclaw-heartbeat-token-usage\/\" rel=\"nofollow noopener\">Others<\/a> are <a target=\"_blank\" href=\"https:\/\/x.com\/voronkoveth\/status\/2018268940682551483?s=20\" rel=\"nofollow\">noticing<\/a> that keeping an AI assistant active 24\/7 can be costly, and proposed various <a target=\"_blank\" href=\"https:\/\/x.com\/OpenRouterAI\/status\/2017742972163445070?s=20\" rel=\"nofollow\">cost mitigation<\/a> <a target=\"_blank\" href=\"https:\/\/x.com\/marcgregory_\/status\/2017875153305158098?s=20\" rel=\"nofollow\">strategies<\/a>.<\/p>\n<p>But given that Moltbook&#8217;s circular discussion group of AI agents <a target=\"_blank\" href=\"https:\/\/www.forbes.com\/sites\/johnkoetsier\/2026\/01\/30\/ai-agents-created-their-own-religion-crustafarianism-on-an-agent-only-social-network\/\" rel=\"nofollow noopener\">purportedly created a religion<\/a> dubbed the <a target=\"_blank\" href=\"https:\/\/molt.church\/\" rel=\"nofollow noopener\">Church of Molt<\/a> or &#8220;Crustafarianism,&#8221; and there&#8217;s now a website evangelizing a <a target=\"_blank\" href=\"https:\/\/dexscreener.com\/solana\/b3q4q1gzxxggt1ivj3mbxbmhm5zwqf9ckngm9xs7es8k\" rel=\"nofollow noopener\">$CRUST<\/a> crypto token, it&#8217;s doubtful that any appeal to caution will cure the contagion until resource scarcity hobbles AI datacenters or a market collapse changes priorities. \u00ae<\/p>\n","protected":false},"excerpt":{"rendered":"OpenClaw, the AI-powered personal assistant users interact with via messaging apps and sometimes entrust with their credentials to&hellip;\n","protected":false},"author":2,"featured_media":405962,"comment_status":"","ping_status":"","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[20],"tags":[554,733,4308,86,56,54,55],"class_list":{"0":"post-405961","1":"post","2":"type-post","3":"status-publish","4":"format-standard","5":"has-post-thumbnail","7":"category-artificial-intelligence","8":"tag-ai","9":"tag-artificial-intelligence","10":"tag-artificialintelligence","11":"tag-technology","12":"tag-uk","13":"tag-united-kingdom","14":"tag-unitedkingdom"},"_links":{"self":[{"href":"https:\/\/www.newsbeep.com\/uk\/wp-json\/wp\/v2\/posts\/405961","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.newsbeep.com\/uk\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.newsbeep.com\/uk\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.newsbeep.com\/uk\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/www.newsbeep.com\/uk\/wp-json\/wp\/v2\/comments?post=405961"}],"version-history":[{"count":0,"href":"https:\/\/www.newsbeep.com\/uk\/wp-json\/wp\/v2\/posts\/405961\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.newsbeep.com\/uk\/wp-json\/wp\/v2\/media\/405962"}],"wp:attachment":[{"href":"https:\/\/www.newsbeep.com\/uk\/wp-json\/wp\/v2\/media?parent=405961"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.newsbeep.com\/uk\/wp-json\/wp\/v2\/categories?post=405961"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.newsbeep.com\/uk\/wp-json\/wp\/v2\/tags?post=405961"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}