Tuesday, August 11, 2026
LIVEThe Unrelenting Cyber Battle: Hacking Threats and the Imperative of Robust Data Protection///Navigating the Cyber Labyrinth: Bolstering Defenses Against Evolving Hacking Threats///The Dual Front War: Battling Hacking and Bolstering Data Protection in the Digital Age///The Ever-Evolving Cyber Threat Landscape: Navigating Hacking and Fortifying Data Protection///The Unseen Battle: Fortifying Data in an Age of Relentless Hacking///The Unseen War: Hacking's Relentless Advance and the Imperative of Data Protection///The Evolving Threat Landscape: Hacking, Data Protection, and the Imperative for Proactive Security///Navigating the Digital Minefield: Bolstering Data Protection in an Era of Relentless Hacking///The Dual Fronts of Digital Defense: Combating Hacking and Fortifying Data Protection///Hacking's New Frontier: Fortifying Data Protection in the Age of Advanced Cyber Threats///The Dual Front: Navigating Hacking Threats and Fortifying Data Protection in the Digital Age///Navigating the Digital Gauntlet: The Evolving Nexus of Hacking and Data Protection///The Unrelenting Cyber Battle: Hacking Threats and the Imperative of Robust Data Protection///Navigating the Cyber Labyrinth: Bolstering Defenses Against Evolving Hacking Threats///The Dual Front War: Battling Hacking and Bolstering Data Protection in the Digital Age///The Ever-Evolving Cyber Threat Landscape: Navigating Hacking and Fortifying Data Protection///The Unseen Battle: Fortifying Data in an Age of Relentless Hacking///The Unseen War: Hacking's Relentless Advance and the Imperative of Data Protection///The Evolving Threat Landscape: Hacking, Data Protection, and the Imperative for Proactive Security///Navigating the Digital Minefield: Bolstering Data Protection in an Era of Relentless Hacking///The Dual Fronts of Digital Defense: Combating Hacking and Fortifying Data Protection///Hacking's New Frontier: Fortifying Data Protection in the Age of Advanced Cyber Threats///The Dual Front: Navigating Hacking Threats and Fortifying Data Protection in the Digital Age///Navigating the Digital Gauntlet: The Evolving Nexus of Hacking and Data Protection///
Subscribe
Cyber Security
Independent · Digital
Thehackingpost
CybersecurityAI-assisted

Over 21,000 OpenClaw AI Instances Leak Personal Configuration Data

OpenClaw, an open-source AI assistant, has rapidly expanded from approximately 1,000 to over 21,000 active instances within a week. Developed by Austrian developer Peter Steinberger, this AI assistant integrates with various services including email,…

OpenClaw, an open-source AI assistant, has rapidly expanded from approximately 1,000 to over 21,000 active instances within a week. Developed by Austrian developer Peter Steinberger, this AI assistant integrates with various services including email, calendars, smart-home systems, and food-delivery services.

The project initially launched as Clawdbot, but was rebranded to Moltbot on January 27, 2026, due to trademark concerns, and was later renamed OpenClaw.

OpenClaw is designed to operate locally on TCP port 18789, accessible via a web browser. The project documentation advises using SSH tunnels for remote access, yet many instances were deployed on the public Internet without this security measure.

Censys identified 21,639 publicly exposed OpenClaw instances using HTML title queries. Although most instances require authentication tokens, the extensive number of exposed deployments poses security concerns.

OpenClaw, an open-source AI assistant, has rapidly expanded from approximately 1,000 to over 21,000 active instances within a week.
Iris Emerson · Thehackingpost

The United States hosts the largest number of visible instances, followed by China and Singapore. Notably, 30% of identified instances are hosted on Alibaba Cloud infrastructure. Many operators use Cloudflare Tunnels for remote access to minimize direct exposure.

The deployment of OpenClaw without adequate security configurations highlights significant vulnerabilities. These AI assistants manage sensitive information, such as email credentials and smart-home controls, posing substantial privacy and security risks when exposed to the Internet.

The concentration of instances across major cloud providers and geographic regions underscores the potential exposure risk. Organizations and users should prioritize secure configurations, implement proper access controls, and conduct security reviews before enabling remote access.

Advertisement

This situation emphasizes the importance of security awareness in the early stages of application lifecycle management, especially for rapidly deployed AI systems.

Based on reporting by GBHackers.

AI transparency. This article was produced with the assistance of artificial intelligence and published under human editorial oversight. AI systems can make mistakes. Read how we use AI (EU AI Act, Art. 50).
Related Stories