• #DIY #AI bot farm #OpenClaw is a #security ’dumpster fire’
    https://www.theregister.com/2026/02/03/openclaw_security_problems

    OpenClaw, the AI-powered personal assistant users interact with via messaging apps and sometimes entrust with their credentials to various online services, has prompted a wave of malware and is delivering some shocking bills.

    Just last week, OpenClaw was known as #Clawdbot, a name that its developers changed to #Moltbot before settling on the new moniker.

    The project, based on the Pi coding agent, launched in November. It recently attracted the attention of developers with large social media followings like Simon Willison and Andrej Karpathy, leading to an explosion in popularity that quickly saw researchers and users find nasty flaws.

    In the past three days, the project has issued three high-impact security advisories: a one-click remote code execution #vulnerability, and two command #injection #vulnerabilities.

    In addition, Koi Security identified 341 #malicious skills (OpenClaw extensions) submitted to #ClawHub, a repository for OpenClaw skills that’s been around for about a month. This was after security researcher Jamieson O’Reilly detailed how it would be trivial to backdoor a skill posted to ClawHub. Community-run threat database OpenSourceMalware also spotted a skill that stole cryptocurrency.