OpenClaw in the Wild: Mapping the Public Exposure of a Viral AI Assistant
ID: 7da198f6-fb33-5d6b-85ab-1cf6100e3d11
STIX ID: report--7da198f6-fb33-5d6b-85ab-1cf6100e3d11
Feed Name: Censys Blog
Date Published: 2026-01-31
Date Updated: 2026-04-27
Author: Silas Cutler; Principal Security Researcher
This report details the rapid adoption and public Internet exposure of OpenClaw (previously Clawdbot/Moltbot) and the launch of moltbook, noting Censys observed over 21,000 potentially accessible instances as of 31 January 2026. While OpenClaw is intended to run locally or be accessed via SSH/Cloudflare Tunnel, many deployments are directly reachable (default TCP/18789), often require a token but still increase risk due to potential access to sensitive data and emergent toxic behaviors on moltbook, underscoring the need for proper configuration and security review.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
