Multiple Hacking Groups Exploit OpenClaw Instances to Steal API key and Deploy Malware
Recent analyses have identified a significant exploitation of OpenClaw, previously known as MoltBot and ClawdBot, by multiple hacking groups targeting the deployment of malicious payloads.
Recent analyses have identified a significant exploitation of OpenClaw, previously known as MoltBot and ClawdBot, by multiple hacking groups targeting the deployment of malicious payloads.
OpenClaw, an open-source autonomous AI framework, was developed by Peter Steinberger, now affiliated with OpenAI. Since its widespread adoption in late January 2026, it has become a critical target for cyber threats.
The architecture of OpenClaw provides extensive system privileges, persistent memory access, and integration with sensitive services, making it vulnerable to credential theft and data exfiltration. Within 72 hours of its broad deployment, threat actors began exploiting several severe vulnerabilities, including the Remote Code Execution flaw (CVE-2026-25253), supply chain poisoning, and credential harvesting through exposed administrative interfaces.
Flare analysts have reported over 30,000 compromised OpenClaw instances, which have been used to steal API keys, intercept messages, and distribute info-stealing malware via Telegram and other communication channels.
OpenClaw, an open-source autonomous AI framework, was developed by Peter Steinberger, now affiliated with OpenAI.
ClawHavoc Campaign: Supply Chain Mass Deployment
One significant campaign, “ClawHavoc,” was detected on January 29, 2026. This supply chain attack involved deploying malicious payloads disguised as legitimate crypto tools, such as the Atomic Stealer for macOS and keyloggers for Windows. Users unknowingly downloaded stealer malware, which enabled attackers to extract persistent memory data and conduct lateral movement across enterprise systems.
By early February, another campaign, Automated Skill Poisoning Through ClawHub, emerged via the OpenClaw community marketplace. The platform's open publishing model and lack of code review allowed attackers to upload backdoored “skills” from seemingly trustworthy GitHub accounts. These updates executed remote shell commands, allowing attackers to exfiltrate OAuth tokens, passwords, and API keys in real time.
A Shodan scan on February 18, 2026, identified over 312,000 OpenClaw instances running on the default port 18789, many lacking authentication and exposed to the internet.
Security Implications and Recommendations
The OpenClaw incidents highlight a critical turning point in the security of autonomous AI agents. Organized threat groups have rapidly adapted to exploit an ecosystem that previously prioritized capability over cybersecurity. As OpenAI integrates OpenClaw’s developer, security experts emphasize the need for security-by-design approaches in future AI frameworks.
A Flare advisory recommends that companies using or testing autonomous assistants secure API credentials and isolate AI workloads to mitigate potential risks.
Based on reporting by Cyber Security News.
