Moltbot / OpenClaw: What’s Going On and Why Businesses Should Pay Attention
A new AI assistant called OpenClaw — previously known as Clawdbot and later Moltbot — has become one of the most talked‑about AI tools of 2026. It went viral almost overnight because, unlike regular chatbots, it can actually do things on your computer: manage emails, browse websites, schedule appointments, send messages, organise files, and carry out routine tasks automatically. Its open‑source design and “AI that actually takes action” promise helped it spread rapidly across Silicon Valley and China.
But OpenClaw’s success has also attracted serious security concerns. Because it needs deep access to a user’s device in order to function, security researchers warn that even small mistakes in how it’s set up can lead to leaked passwords, exposed chat tokens, or even full system compromise. Cisco and other firms have called it a potential “security nightmare,” especially when used without technical expertise.
How It Started — and Why It Took Off So Fast
OpenClaw began as a personal project by an Austrian developer and changed names multiple times due to trademark issues and rapid growth. Despite launching only weeks ago, it gathered more than 100,000 GitHub stars and millions of social media impressions.
People gravitated to it because:
- it can act like a digital personal assistant
- it connects to popular messaging apps like WhatsApp, Telegram, and Discord
- it remembers user preferences over long periods
- it integrates with dozens of plugins and skills
This “hands‑on AI” experience has led some early adopters to claim it saves them hours each week.
However, that same openness and flexibility has created a large attack surface — one the cybercriminal community has quickly noticed.
Why It Has Become a Security Risk
Malicious Third‑Party Plugins Flooding the Ecosystem
OpenClaw lets users install “skills”, small add‑ons that expand its abilities. But within days, attackers published hundreds of malicious skills on OpenClaw’s official registry and GitHub, many pretending to be finance or productivity tools while secretly installing password‑stealing malware. In one short span, over 230–400 harmful skills appeared, targeting Windows and macOS systems.
Exposed and Misconfigured Installations
Researchers found numerous OpenClaw setups accidentally left open on the public internet with no passwords or authentication, leaking API keys, Slack tokens, Telegram bot secrets, and conversation logs.
A Critical “One‑Click Hijack” Vulnerability
A recently patched vulnerability (CVE‑2026‑25253) allowed attackers to hijack OpenClaw simply by tricking the user into visiting a malicious website. Once compromised, attackers gained full control of the AI assistant — and, through it, significant access to the computer.
High Privilege = High Risk
OpenClaw needs deep system access to work — reading and writing files, running scripts, controlling apps, and interacting with the internet.
If you’re a local administrator on your computer, OpenClaw effectively becomes one too. That means anything you can do — install software, delete files, run scripts — so can the AI agent. If OpenClaw receives a risky instruction (whether accidental, malicious, or sneaky), it can execute it with the highest level of privilege. The consequences can be severe: data loss, system compromise, or unauthorised changes to core business systems.
This is why experts consider it uniquely risky compared to standard chatbots.
What Businesses Should Take From This
OpenClaw isn’t enterprise software — but its rapid rise tells us something important: AI agents that take actions, not just generate text, are arriving fast. And when staff experiment with these tools at work, the risks extend into the corporate environment.
Here’s what organisations should look out for:
1. Employees installing AI assistants on work devices
These tools can access files, emails, calendars, internal apps, browser sessions, and more. A compromised AI agent on a work device could expose sensitive company information.
2. AI plugins functioning like unvetted software
OpenClaw skills behave like downloadable code packages — except many users don’t realise that. Fake skills have already delivered malware disguised as helpful add‑ons.
3. AI agents responding to hidden or malicious instructions
Tools like OpenClaw can be manipulated through “prompt injection” — hidden instructions inside websites, messages, or documents that cause the AI to perform actions the user never intended.
4. Increased “shadow AI” use
As AI agents become trendy, staff may start using them without notifying IT, similar to shadow IT and shadow SaaS concerns.
5. A preview of future workplace AI
OpenClaw is chaotic now, but it’s a clear sign of the future: autonomous AI agents that perform real actions will eventually enter business software — but they must come with strict guardrails, permissions, and auditing.
How Businesses Can Protect Themselves
You don’t need to ban every AI tool, but you do need to set boundaries. Consider:
- Clear internal policy: what AI tools are allowed, what’s restricted, and what must be approved.
- Device security: limit admin rights, enforce updates, and monitor for unusual behaviour.
- Education: help staff understand that AI agents aren’t “just apps” — they can install code, move files, or access sensitive data.
- Safe experimentation: Instead of only restricting usage, provide a controlled place for staff to experiment — such as a sandbox environment or an approved test device. Pair this with a channel where staff can share ideas, ask questions, and propose use cases. This turns curiosity into innovation while keeping risks contained.
- Monitoring for unauthorised AI deployments: include AI agents in shadow IT detection processes.
OpenClaw’s rise — from Moltbot to a global viral AI assistant — shows both the excitement around action‑oriented AI and the risks that come with it. The tool can be powerful, but it’s also unstable, easy to misconfigure, and already a target for attackers.
For businesses, this is not about OpenClaw itself — it’s about preparing for the broader trend: AI agents that act on behalf of users will soon be everywhere, and organisations need policies and safeguards in place long before they arrive on company devices.
Discover what meaningful AI adoption looks like in practice
Get in touch below to learn more





