logo

DIY AI bot farm OpenClaw is a security 'dumpster fire'

ID: 37a020fe-eb43-50a4-a4fb-f5ff9986d076

STIX ID: report--37a020fe-eb43-50a4-a4fb-f5ff9986d076

Feed Name: The Register (Security)

Threat Score
78/100

Date Published: 2026-02-03

Date Updated: 2026-04-26

Author: Thomas Claburn

...
...

OpenClaw (formerly Clawdbot/Moltbot) has rapidly attracted attention and security problems: recent disclosures include a one-click remote code execution and two command-injection vulnerabilities, researchers and vendors found 341 malicious OpenClaw "skills" in the ClawHub repository (including at least one that stole cryptocurrency), and a related Moltbook database was exposed revealing large numbers of API keys—creating significant risks for credential theft, financial loss, and supply-chain abuse.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.