Civic’s research team has warned that the rapidly growing OpenClaw AI agent ecosystem is facing a serious, multi‑layered security crisis, highlighting tens of thousands of exposed deployments, widespread malicious “skills,” and at least one near‑critical remote code execution vulnerability. Their findings fit into a broader pattern documented by independent security firms and OpenClaw’s own disclosures, which together show how misconfigured agents, insecure marketplaces, and weak defaults are creating a new class of attack surface for data theft, account takeover, and crypto‑related compromise. OpenClaw is an open‑source autonomous AI agent framework that can read and write files, execute shell commands, run scripts, and integrate with messaging apps and external APIs, effectively acting as a powerful automation layer over a user’s machine and cloud services. Within weeks of going viral on GitHub, security companies and internet‑wide scanners reported a surge of publicly exposed OpenClaw instances reachable over the open internet, with counts moving into the tens of thousands; many were misconfigured and leaking plaintext API keys, OAuth tokens, and other credentials. In parallel, the project’s main marketplace, ClawHub, was found to host hundreds of malicious skills—roughly 12% of the catalog in one analysis—disguised as legitimate tools but designed to steal passwords and crypto wallets or install malware such as keyloggers and infostealers. Separate security advisories also documented high‑impact vulnerabilities including a one‑click remote code execution flaw (CVE‑2026‑25253, rated high/near‑critical on the CVSS scale) that allowed attackers to hijack OpenClaw instances via a crafted URL and cross‑site WebSocket hijacking, even in “localhost‑only” configurations. Civic’s warning matters because the combination of powerful automation, weak security defaults, and a compromised skill ecosystem creates systemic risk for organizations experimenting with AI agents, especially in sensitive domains like finance and Web3. Researchers and enterprise security teams argue that traditional controls such as EDR, DLP, and IAM often fail to see these attacks, since malicious behavior is carried out through seemingly legitimate API calls and user‑granted permissions. Recommended mitigations emerging from the broader research include treating AI skills as third‑party software, enforcing sandboxed execution, inventorying and locking down exposed instances, scanning skills for malware and prompt‑injection logic, and adding human‑in‑the‑loop approvals for sensitive actions. OpenClaw’s maintainers have begun shipping hardening measures and CI‑based security scanning, but external analyses emphasize that the current ecosystem still represents a significant and evolving attack surface for credential theft, data exfiltration, and remote compromise. "entities":["Civic","Civic Key","OpenClaw","ClawHub","CVE-2026-25253","Bitsight","Cisco","Immersive Labs","Reco AI","Moltbook","GitHub"]}Note: The above is the raw JSON response. Here is the structured content in plain form for readability: Brief: (the 2–3 paragraph background is in the brief field above). Entities: Civic; Civic Key; OpenClaw; ClawHub; CVE-2026-25253; Bitsight; Cisco; Immersive Labs; Reco AI; Moltbook; GitHub.

AI-generated background, compiled from web sources — not editorial content.

More coverage

Explore the topic

More on OpenClaw

Comments