Over 21,000 OpenClaw AI Instances Leak Personal Configuration Data
OpenClaw, an open-source AI assistant, has rapidly expanded from approximately 1,000 to over 21,000 active instances within a week. Developed by Austrian developer Peter Steinberger, this AI assistant integrates with various services including email,…
OpenClaw, an open-source AI assistant, has rapidly expanded from approximately 1,000 to over 21,000 active instances within a week. Developed by Austrian developer Peter Steinberger, this AI assistant integrates with various services including email, calendars, smart-home systems, and food-delivery services.
The project initially launched as Clawdbot, but was rebranded to Moltbot on January 27, 2026, due to trademark concerns, and was later renamed OpenClaw.
OpenClaw is designed to operate locally on TCP port 18789, accessible via a web browser. The project documentation advises using SSH tunnels for remote access, yet many instances were deployed on the public Internet without this security measure.
Censys identified 21,639 publicly exposed OpenClaw instances using HTML title queries. Although most instances require authentication tokens, the extensive number of exposed deployments poses security concerns.
OpenClaw, an open-source AI assistant, has rapidly expanded from approximately 1,000 to over 21,000 active instances within a week.
The United States hosts the largest number of visible instances, followed by China and Singapore. Notably, 30% of identified instances are hosted on Alibaba Cloud infrastructure. Many operators use Cloudflare Tunnels for remote access to minimize direct exposure.
The deployment of OpenClaw without adequate security configurations highlights significant vulnerabilities. These AI assistants manage sensitive information, such as email credentials and smart-home controls, posing substantial privacy and security risks when exposed to the Internet.
The concentration of instances across major cloud providers and geographic regions underscores the potential exposure risk. Organizations and users should prioritize secure configurations, implement proper access controls, and conduct security reviews before enabling remote access.
This situation emphasizes the importance of security awareness in the early stages of application lifecycle management, especially for rapidly deployed AI systems.
Based on reporting by GBHackers.
