← Back to Blog

    OpenClaw: The Viral AI Agent That Can Do Everything — and That's Exactly the Problem

    OpenClawAgentic AIKI-Sicherheit

    The Viral AI Agent — A Critical Analysis

    A tool that collected 60,000 GitHub stars in 72 hours. That simultaneously generates excitement and genuine security concerns. A sober assessment.

    In late 2025, Austrian developer Peter Steinberger published a small project called Clawdbot on GitHub. Named after the loading screen monster from Anthropic's Claude Code. Goal: a personal AI assistant that runs on your own computer, can be controlled via WhatsApp or Telegram, and independently executes tasks.

    What followed was one of the most remarkable viral moments in the open-source AI space: 60,000 GitHub stars in 72 hours. Multiple name changes — from Clawdbot to Moltbot to OpenClaw. Reactions from Andreessen Horowitz to Andrej Karpathy. Reports in Forbes, WIRED, and CNBC.

    📊 Numbers: As of February 2026, OpenClaw has over 150,000 GitHub stars. Millions of installations. And 42,900 publicly exposed instances — 15,200 with active security vulnerabilities (SecurityScorecard, February 2026).

    What OpenClaw Is — and What It Really Can Do

    OpenClaw is not a chatbot. It's a complete AI agent that runs locally on your own system and connects to a language model — typically Claude or ChatGPT via API. The difference from a classic AI tool: OpenClaw has access to the operating system, files, browser, emails, calendar, and external services. It can use these autonomously when necessary for task completion.

    Core Capabilities:

  1. Messenger Integration — WhatsApp, Telegram, Discord, Signal, iMessage, Slack, Teams — OpenClaw receives tasks via normal chat messages.
  2. Autonomous Execution — Create, edit, delete files; install software; write and execute scripts; make web requests.
  3. Persistent Memory — The agent remembers preferences, contexts, and task histories across sessions.
  4. Skills Platform — OpenClaw can be extended through skills — from password manager integration to smart home control.
  5. Self-Extension — The agent can independently write code to teach itself new capabilities.
  6. The Critical Question: How Much Autonomy Is Too Much?

    This is where the enthusiasm ends — and the necessary sobriety begins.

    OpenClaw grants the AI agent "full control over the computer" after setup — as stated in its own documentation. That's not a marketing phrase, but a technical description.

    Security Problem 1: Exposed Systems

    SecurityScorecard published an analysis in early February 2026: 42,900 publicly reachable OpenClaw instances, 15,200 of which with active vulnerabilities enabling remote takeover. The reason: Many users install OpenClaw without recommended security configurations — API keys are exposed, server ports are reachable without authentication.

    Security Problem 2: Prompt Injection

    OpenClaw connects to messaging services and processes incoming messages as tasks. This is the core principle — and simultaneously a classic attack surface for prompt injection attacks. A maliciously crafted message to the agent could cause it to perform unintended actions.

    Security Problem 3: Terms of Service and Claude API

    Anthropic has reportedly begun suspending users who use their Claude API access for OpenClaw. The reason: Anthropic's terms prohibit using services for developing or training AI systems.

    What OpenClaw Does Right

    Despite all justified criticism, it would be dishonest to overlook the project's real qualities:

  7. Local-first and privacy-friendly — All data stays on your own system. No cloud dependency.
  8. Democratization of AI agents — OpenClaw shows that powerful agency AI doesn't require enterprise infrastructure.
  9. Community-driven innovation — The skills platform and rapid development show what happens when an engaged open-source community backs a project.
  10. Transparency — The code is open, auditable, modifiable.
  11. Conclusion

    OpenClaw is not an enterprise tool in its current form. For individuals with technical affinity and clear awareness of risks, it's a fascinating experiment. The real relevance for decision-makers lies elsewhere: OpenClaw shows where the journey is heading. Personal AI agents that act independently, can be controlled via messaging services, and have permanent system access will come — in safer, enterprise-ready form.


    Monitor how AI talks about your brand. Request beta access to PromptScan.

    Cookie Settings

    We use cookies to improve your experience and analyze site usage. You can customize your preferences below. Privacy Policy