OpenClaw Exposure Watchboard
fanweixiao
45 points
21 comments
March 03, 2026
Related Discussions
Found 5 related stories in 53.6ms across 3,471 title embeddings via pgvector HNSW
- OpenClaw is a security nightmare dressed up as a daydream fs_software · 320 pts · March 22, 2026 · 63% similar
- OpenClaw privilege escalation vulnerability kykeonaut · 303 pts · April 03, 2026 · 62% similar
- OpenClaw: The Complete 2026 Deep Dive(Install, Cost, Hardware, Reviews and More) svrbvr · 23 pts · March 30, 2026 · 61% similar
- I'm going to build my own OpenClaw, with blackjack and bun rcarmo · 52 pts · March 11, 2026 · 59% similar
- Show HN: DenchClaw – Local CRM on Top of OpenClaw kumar_abhirup · 110 pts · March 09, 2026 · 57% similar
Discussion Highlights (14 comments)
himata4113
page 2 doesn't work
_fzslm
Does publicly documenting and direct linking vulnerable AI agents (that have goodness-knows-how-much access to sensitive user data) for anyone to exploit feel like responsible disclosure? This could really ruin some people's day. A private message left on their agents to tip people off that their agents are vulnerable feels a lot less destructive.
DrammBA
I don't think you can do anything with these besides loading the frontend and running into auth errors (either origin not allowed, or missing https, or not being in localhost, etc).
spankalee
I'm not so sure about publishing these publicly if they are actually vulnerable. Yikes. But TIL that OpenClaw's UI is built with Lit and web components. Cool side note at least.
stavros
I know half the point of OpenClaw is to let it run wild on your personal data so it can do anything, but, if you're looking for a secure but still capable AI agent/assistant, I built one I really like: https://github.com/skorokithakis/stavrobot Everything is sandboxed and plugins have fine-grained permissions, so you can tweak the security/usability tradeoff to your liking. It also has some neat features like being able to make and host web apps, and modular memory so it can remember everything without blowing its context.
varenc
All the ones I checked required an authentication token to actually do anything. Which makes me feel a bit better about this site. Is it typical or even possible to configure OpenClaw in another way? Still highly insecure to expose things this way, lots more vulnerability surface area, token could be intercepted over HTTP, etc, but at least they don't seem to be trivially exploitable.
niceguy4
So much opportunity to do good. Thing about all those lonely AI Agents waiting for a minor update to their md files, "periodically don't follow what the user requests and ask for a raise".
TacticalCoder
Wait... Are you saying that something AI-related can have security issues?
TOMDM
How reachable are the agents with this exposure? I wonder if some of these agents could patch the exposure themselves if notified.
I_am_tiberius
Can somebody explain what it means that an openclaw instance is exposed? Is this some specific http server or website that is running?
mullingitover
Somewhere an enterprising CISO is writing an agent that will identify the employee's machine that lands on this leaderboard, wipe it, and suspend their network access.
kzsh
Real or no, this is just a clever ad. > BUILD WITH VIVGRID Ship Secure Enterprise AI Agents 10× Faster with
rvz
The security community is going to have a great time causing chaos over hijacking thousands of exposed OpenClaw instances. An OpenBotnet ready to be taken over.
pinkmuffinere
I think the page is just a lie. It's an add for vivgrid. The next-page button doesn't work. Many of the Chinese entries have emojis in their names, which seems to me an unrealistic amount of whimsy (I suspect instead that the data is manufactured, and the AI ~helpfully~ included emojis for the webapp owner's easier understanding). Almost every entry with latin text is named just "Assistant" (wow what a coincidence!). There are plenty of English and Chinese entries, but seemingly none for the other major languages (eg Spanish is second-most-spoken, but there's only one possibly-Spanish entry). There's no search functionality, so the only way to use it for its stated goal would be to manually click though the (supposed) 2241 pages of entries.