logo

OpenClaw in the Wild: Mapping the Public Exposure of a Viral AI Assistant

ID: 7da198f6-fb33-5d6b-85ab-1cf6100e3d11

STIX ID: report--7da198f6-fb33-5d6b-85ab-1cf6100e3d11

Feed Name: Censys Blog

Date Published: 2026-01-31

Date Updated: 2026-04-27

Author: Silas Cutler; Principal Security Researcher

...
...

This report details the rapid adoption and public Internet exposure of OpenClaw (previously Clawdbot/Moltbot) and the launch of moltbook, noting Censys observed over 21,000 potentially accessible instances as of 31 January 2026. While OpenClaw is intended to run locally or be accessed via SSH/Cloudflare Tunnel, many deployments are directly reachable (default TCP/18789), often require a token but still increase risk due to potential access to sensitive data and emergent toxic behaviors on moltbook, underscoring the need for proper configuration and security review.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.