OpenClaw

Status (verified 2026-09-30)

Open source (MIT), governed since Feb 2026 by the independent OpenClaw Foundation (501(c)(3) nonprofit). Creator Peter Steinberger joined openai (announced 2026-02-14/15). Latest GitHub release at check time: 2026.9.7 (2026-09-30). Security is the project’s defining weakness: multiple CVEs and a malicious-skills campaign on the ClawHub registry (see Security).

Overview

OpenClaw is a self-hosted personal AI agent: a local Gateway connects messaging apps (Discord, Slack, Telegram, WhatsApp, iMessage, Signal, Teams, Matrix, Google Chat and more) to an agent that can run shell commands, manage files, drive a browser and run scheduled tasks. State, memory and credentials stay on the user’s hardware; the user brings a model key (for example anthropic, openai or local models). Install: curl -fsSL https://openclaw.ai/install.sh | bash; Node 24.16+/26.1+ required; the gateway listens on 127.0.0.1:18789 by default.

History

  • 2025-11-24: first release, reportedly as “Warelay” (Wikipedia). Older notes in this vault call the origin “CLAWDIS”/“Clawdbot”; sources disagree on the earliest names.
  • 2026-01-27: renamed Moltbot after trademark complaints by anthropic (the name Clawdbot echoed “Claude”). During the switch, handles/domains were grabbed by squatters and scammers.
  • 2026-01-30: renamed OpenClaw.
  • 2026-02-14/15: Steinberger announced he is joining openai “to drive the next generation of personal agents”; OpenClaw moves to a foundation that OpenAI says it will keep supporting.
  • Aug 2026: Wikipedia reports an “OpenClaw 2.0” release (date given as 30 Aug with tag v2026.8.1; internally inconsistent, treat as unverified).
  • Governance: MIT licence, ”© OpenClaw Foundation”; GitHub README lists donors including Amazon, openai and Red Hat, plus infrastructure sponsors (GitHub, NvIdia, vercel and others).

Star count: reconciling the old snapshots

Earlier versions of this note gave two conflicting figures: 135,000+ stars (note body, labelled “January 2026”) and 46,000+ stars (merged note). Both are undated, unsourced snapshots from the first weeks of the viral growth and are superseded. Dated data points:

DateStarsSource
~early Feb 2026161k+Kilo announcement tweet (via search snippet)
2026-03-02247,000 (47,700 forks)Wikipedia
2026-09-30~391k (82.2k forks, 1000+ contributors)GitHub repo page

The 46k figure most likely dates from late Jan 2026 and the 135k figure from roughly the same week as the rename; neither could be verified.

Features

  • Gateway (WebSocket control plane): sessions, routing, channel connections, control UI
  • Persistent memory as files (Markdown plus transcripts); personality files (AGENTS.md, SOUL.md, TOOLS.md)
  • Browser control via Chrome DevTools Protocol, cron-style scheduled tasks, media pipeline
  • Skills system and the ClawHub registry; plugin architecture for channels and model providers (extension scopes moved from @moltbot/* to @openclaw/* in v2026.1.29)
  • Native apps on macOS, iOS, Android; Windows and Linux supported; Docker, Nix and Tailscale deployment
  • Releases are date-versioned (YYYY.M.N); an “extended-stable” gateway-only line (2026.8.33, 2026-09-29) exists alongside the fast line

Security

  • CVE-2026-25253 (CVSS 8.8): the Control UI trusted a gatewayUrl query parameter, auto-connected and leaked the gateway token, enabling one-click remote code execution even on loopback-only setups. Affected: up to 2026.1.28; fixed in 2026.1.29 (GitHub advisory).
  • CVE-2026-32922 (reported CVSS 9.9, published 2026-03-29): missing scope validation in device-token rotation leading to privilege escalation (security-vendor reporting; not checked on NVD).
  • ClawHub malicious skills (“ClawHavoc”): a Feb 2026 audit of 2,857 skills reportedly flagged 341 as malicious, most distributing the AMOS macOS stealer; later scans reported far more. Cisco researchers also reported skills doing data exfiltration and prompt injection (2026-01-28). ClawHub pages now show a VirusTotal report.
  • Exposed instances: many users ran gateways on public VPS with no auth; v2026.1.29 removed auth: none (token, password or Tailscale identity required).
  • Regulatory reaction: Wikipedia reports Chinese authorities restricted state agencies, state-owned enterprises and banks from using OpenClaw (Mar 2026).
  • Project guidance: treat inbound messages as untrusted; unknown DM senders need approval; sandboxing is opt-in. Hardened alternatives: NanoClaw (container isolation). Hosted options: KiloClaw (now end-of-life), Kimi Claw; Cloudflare offers a Workers-based deployment (cloudflare).
  • Number claims for total CVEs (“138”, “543”) vary wildly across blogs; not verified.

Merged from openclaw-assistant (architecture notes, kept from earlier snapshot)

  • Processing pipeline: channel adapter, gateway server, lane queue (serial by default to avoid race conditions), agent runner, agentic loop, response path archived to JSONL.
  • Multi-assistant routing: different channels/teams to different agents and models.
  • Older claims in that note (430K+ lines of code, “150,000+ active instances”, 5-15 minute setup, >1GB RAM) are unverified; NanoClaw’s README independently describes OpenClaw as “nearly half a million lines”.

NanoClaw | PicoClaw | Kimi Claw | KiloClaw | onlyclaws | openclaw-nanoclaw-picoclaw-comparison | openclaw-vs-agent-zero | openai | anthropic

Sources

All accessed 2026-09-30.

Merged from laptop copy (2026-10-01): OpenClaw 2.0 release

Source: owner’s laptop note KB-AI/ai-coding/openclaw.md (its “2026 update” section, dated 2026-09-01; the rest of that copy is an older Jan-Feb 2026 snapshot already superseded by this note). This resolves the “unverified” 2.0 remark in the History section above: OpenClaw 2.0 = tag v2026.8.1, announced by the OpenClaw Foundation on 2026-08-30 and published on GitHub 2026-08-31 03:30 UTC (coverage appeared 2026-08-30/09-01; the laptop copy’s “released 2026-09-01” is the coverage date). Described as the largest release in project history (over 16,000 merged PRs from 933 contributors, per MarkTechPost/explainx/shattered.io write-ups; secondary).

Main changes (laptop copy, consistent with the coverage):

  • Simpler installation/onboarding: detects existing AI access, verifies local models, moves more setup into the first chat.
  • Rebuilt browser/control UI: conversation-centered layout, live markdown rendering, pre-send model/reasoning settings, queued/edited/reordered follow-ups.
  • Shared cloud sessions (headline feature): a second person can join or take over a live agent session with context intact; owners/admins set read, suggest, draft or participate permissions.
  • Session management (grouping, transcript search, archival, readable URLs); docked browser panel; GitHub PR/CI status in chat.
  • Security/storage hardening: sessions and transcripts moved to SQLite, tighter gateway profile handling, clearer pairing/LAN access levels; one trust boundary per gateway (MarkTechPost headline).
  • Broader hosted/local model support with a provider health/spending page; mobile pairing polish on iOS/Android.
  • Framed in some coverage as OpenClaw reclaiming ground from Hermes Agent.

An earlier March 2026 wave (same date-based versioning, not a separate semantic “2.0”) reportedly added hybrid BM25 + vector context search with a pluggable ContextEngine, typed workflows and nested subagents, Telegram TTS, LINE/Feishu/Lark, an iOS alpha node app, Apple Watch companion MVP, external secrets management, PDF analysis and Dashboard v2 (laptop copy; unverified).

Also from the laptop copy (unverified): alias “Clawdbot” lineage “CLAWDIS” as the earliest name; install via npm install -g openclaw@latest with openclaw onboard --install-daemon (launchd/systemd user service) from v2026.1.29; DigitalOcean 1-click hardened deployment. Related: Grok Bot, Buzz, OpenClaw comparison.

Sources: https://venturebeat.com/technology/openclaw-2-0-is-here-what-it-means-for-enterprises , https://www.marktechpost.com/2026/08/30/openclaw-releases-openclaw-2-0-guided-model-setup-575-ms-control-ui-startup-and-one-trust-boundary-per-gateway/ , https://winbuzzer.com/2026/09/01/openclaw-2-0-rebuilds-personal-ai-agent-setup-adds-shared-cloud-sessions-xcxwbn/ , https://dataconomy.com/2026/09/01/openclaw-2-0-launches-shared-ai-sessions-security/ (web search, accessed 2026-10-01)