I’ve been warning about OpenClaw security since my first post in February. At the time, the concerns were theoretical. Plaintext credentials. Broad permissions. No sandboxing.

It’s no longer theoretical.

I’ve seen listings on dark web forums where threat actors are selling root shell access to machines running OpenClaw. Not just the machine itself, but the AI assistant, the owner’s full conversation history, API keys, and personal details the owner had shared with their agent in confidence.

One listing advertised access to a CEO’s computer. The seller highlighted that the CEO had been actively chatting with the AI, sharing details about his personal life, his family, his daily routine. The listing noted this made him “easy to locate or contact, as well as his family members.” The full company database and backend access were included too.

Price? $25,000 in crypto. Open to offers.

That’s not a conference talk scenario. That’s a real person with a price tag.

How This Happens

The path from “cool AI tool” to “your life is for sale” is shorter than most people think.

OpenClaw stores everything in plaintext. API keys, OAuth tokens, conversation histories, and persistent memory files like MEMORY.md and SOUL.md all sit in predictable directories on disk. Hudson Rock confirmed that infostealer malware had already been caught stealing OpenClaw config files. The malware wasn’t even targeting OpenClaw on purpose. It was running a broad file-grabbing routine, and the OpenClaw directory happened to be a goldmine.

And when someone gets access to a machine running an AI agent, they don’t just get credentials. They get context. Months of conversations. Behavioural profiles. Schedules. Business strategy. Personal details shared casually with a “trusted” assistant that stores it all in a markdown file.

The Scale

SecurityScorecard’s STRIKE team found 42,900 exposed OpenClaw instances across 82 countries. 63% were running vulnerable versions. Over 12,800 were exploitable through remote code execution.

Bitdefender found employees deploying OpenClaw onto corporate machines using single-line install commands, with no IT visibility. Palo Alto Networks called it the potential biggest insider threat of 2026.

The supply chain attacks haven’t slowed down either. The ClawHavoc campaign planted over 1,184 malicious skills on ClawHub. One fake “weather assistant” skill stole the entire .clawdbot/.env file, exposing API keys for paid AI services.

What To Do

If you’re running OpenClaw or any autonomous AI agent, treat it as privileged infrastructure. Not a toy.

Check your MEMORY.md and SOUL.md. If you’ve been telling your assistant about your family, finances, or business plans, all of that is sitting in plaintext on disk right now.

Rotate your API keys and tokens. Sandbox it away from your primary machine. And for organisations: scan your network for OpenClaw, Moltbot, and Clawdbot signatures. You might be surprised what’s already running.

If you’re a senior leader who has been using an AI agent as a personal assistant.. re-read that forum listing and ask yourself: could that be you?

TLDR: Dark web forums are actively selling access to machines running OpenClaw AI agents. One listing offered a CEO’s full machine access for $25K in crypto, including conversation history, personal details shared with the AI, and company database access. This is possible because OpenClaw stores everything in plaintext and most users don’t treat it as the privileged infrastructure it is. Over 42,900 exposed instances have been found globally. If your AI agent has access to your email, files, and terminal, lock it down or accept that your digital life might already be listed somewhere you’ll never see.


Sources and Further Reading

  • Hudson Rock: Infostealer malware stealing OpenClaw configuration files (February 2026)
  • SecurityScorecard STRIKE: Beyond the Hype – Moltbot’s Real Risk Is Exposed Infrastructure (February 2026)
  • Flare / BleepingComputer: The OpenClaw Hype – Analysis of Chatter from Deep and Dark Web (February 2026)
  • BlackFog: ClawdBot and OpenClaw – When Local AI Becomes A Data Exfiltration Goldmine (February 2026)
  • Bitdefender: Technical Advisory – OpenClaw Exploitation in Enterprise Networks (February 2026)
  • Trend Micro: Malicious OpenClaw Skills Used to Distribute Atomic macOS Stealer (February 2026)

Are you seeing OpenClaw pop up in your organisation without IT’s knowledge? I’d love to hear how others are handling this.

Leave a Reply

Your email address will not be published. Required fields are marked *