logo

OpenClaw is a security nightmare - 5 red flags you shouldn't ignore (before it's too late)

ID: 18b0a4e5-0d2f-548c-abd9-f016886e3773

STIX ID: report--18b0a4e5-0d2f-548c-abd9-f016886e3773

Feed Name: ZDNet Security

Threat Score
70/100

Date Published: 2026-02-02

Date Updated: 2026-04-26

...
...

ZDNet warns that OpenClaw (formerly Clawdbot/Moltbot), a rapidly viral open-source AI assistant, has exposed serious security risks: misconfigured public instances have leaked Anthropic/OpenAI API keys, bot tokens, and credentials; the agent is vulnerable to prompt-injection attacks that can cause data leaks or remote actions; malicious skills and a trojanous VS Code extension have been observed; and opportunistic scams (including a fake crypto token) have already exploited the hype — the piece urges caution, limited permissions, and using only trusted repositories.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.