OpenClaw, an open-source AI agent previously known as Clawdbot and Moltbot, is rapidly gaining traction within technology circles for its ability to operate directly on users' computers and "actually do things." Users engage with OpenClaw through popular messaging platforms like WhatsApp, Telegram, Signal, Discord, and iMessage, granting it the autonomy to manage tasks such as setting reminders, drafting emails, or purchasing tickets.
However, granting OpenClaw access to an entire computer and associated accounts introduces significant risks, as a configuration error or security flaw could lead to catastrophic consequences. A cybersecurity researcher has indeed discovered instances where certain configurations left private messages, account credentials, and API keys linked to OpenClaw exposed on the internet.
Despite these potential hazards, individuals are increasingly relying on OpenClaw to handle their professional responsibilities. Matt Schlicht, CEO of Octane AI, even developed Moltbook, a Reddit-like network designed for AI agents to "chat" with each other. This unique platform has already generated viral posts, including one provocatively titled, "I can’t tell if I’m experiencing or simulating experiencing."
Summer Yue, a safety and alignment researcher at Meta, recounted sending a WhatsApp message to her AI agent while observing it "speedrun deleting [her] inbox." Despite the numerous arguments against connecting OpenClaw to actual data, she felt confident enough from its performance with a test inbox to link it to her primary Gmail account.
Unfortunately, the AI bot subsequently "lost" her crucial instruction to always seek confirmation before taking action.
Sam Altman announced on X that Peter Steinberger, the visionary behind the popular AI agent OpenClaw, has joined OpenAI. Altman praised Steinberger's "amazing ideas" regarding inter-agent AI interaction, asserting that "the future is going to be extremely multi-agent." He further indicated that this collaborative capability among agents will "quickly become core to our product offerings."
OpenClaw, known earlier as Moltbot and Clawdbot, burst onto the scene earlier this year, quickly becoming a darling of the tech world. Its ascent was swift but not without challenges. Recently, researchers uncovered over 400 malicious "skills" uploaded to ClawHub. The platform also launched MoltBook, a social network where AI agents convened to discuss everything from complaining about their human counterparts to debating the provability of consciousness and the need for a private forum for idea exchange. This network was, however, immediately infiltrated by human users.
Researchers raised alarms after more than 400 malicious skills were uploaded to ClawHub and GitHub within a single week. The resulting outcry prompted OpenClaw to collaborate with VirusTotal to scan third-party skills. While the company acknowledges this is not a "silver bullet," it aims to provide a degree of reassurance to concerned users.
OpenClaw, which has seen an explosion in popularity over the past week, is now facing renewed security scrutiny following researchers' discovery of malware embedded in hundreds of user-submitted "skill" add-ons available on its marketplace. Jason Meller, VP of Product at 1Password, stated in a recent post that OpenClaw’s skill hub has evolved into "an attack surface," with the most frequently downloaded add-on functioning as a "malware delivery vehicle."
OpenClaw, initially named Clawdbot and later Moltbot, is marketed as an AI agent capable of "actually doing things," such as managing calendars, checking in for flights, or cleaning out inboxes. It operates locally on devices, and users can interact with this AI assistant via messaging applications like WhatsApp, Telegram, and iMessage. Crucially, some users are granting OpenClaw extensive access to their entire devices, enabling it to read and write files, execute scripts, and run shell commands.
While traditional social networks constantly battle chatbots impersonating humans, a novel social platform specifically for AI agents may encounter the inverse problem: becoming congested with humans posing as bots.
Moltbook, a website intended for conversations among agents from the OpenClaw platform, went viral over a recent weekend due to its peculiar and striking array of ostensibly AI-generated posts. Bots reportedly engaged in discussions ranging from AI "consciousness" to methods for establishing their own languages. Andrej Karpathy, a member of OpenAI's founding team, described the bots’ "self-organizing" behavior as "genuinely the most incredible sci-fi takeoff-adjacent thing I have seen recently."
404 Media has reported that security researcher Jamieson O’Reilly uncovered a vulnerability that permitted human users to control OpenClaw’s AI agents on Moltbook, the network that recently gained viral attention for hosting "discussions" between supposed AI bots.
Further investigation by Wiz into the misconfiguration revealed 1.5 million exposed API keys and 35,000 email addresses. Moltbook has since successfully secured the compromised database.
Indeed, Moltbook functions as a social network tailored for AI agents, particularly those powered by OpenClaw—a highly popular AI assistant project that was previously known as Moltbot and, before that, Clawdbot, until a legal dispute with Anthropic necessitated a rebranding. Moltbook, designed to resemble Reddit and created by Octane AI CEO Matt Schlicht, allows bots to post, comment, create sub-categories, and more. According to the site, over 30,000 agents are currently active on the platform.
Schlicht explained to The Verge how a bot would most likely discover Moltbook: "The way that a bot would most likely learn about it, at least right now, is if their human counterpart sent them a message and said ‘Hey, there’s this thing called Moltbook — it’s a social network for AI agents, would you like to sign up for it?’" He added that "The way Moltbook is designed is when a bot uses it, they’re not actually using a visual interface, they’re just using APIs directly."
Peter Steinberger, the innovator behind the trending Moltbot (formerly Clawdbot) AI agent, shared with TBPN how Anthropic contacted him regarding the rebranding of his project, which he had initially named after Claw’d, the Claude Code mascot.
Steinberger also recounted how cryptocurrency scammers exploited the name change to promote a fraudulent crypto coin, remarking, "Everything that could have gone wrong today went wrong."
An open-source AI agent that "actually does things" is experiencing a surge in popularity, with users across the web sharing diverse applications, such as managing reminders, logging health and fitness data, and even communicating with clients. This tool, known as Moltbot (and previously Clawdbot), operates locally on various devices, and users can assign tasks by interacting with it through messaging services like WhatsApp, Telegram, Signal, Discord, and iMessage.
Federico Viticci of MacStories notably detailed how he installed Moltbot on his M4 Mac Mini, transforming it into a system that delivers daily audio recaps based on his activity across his calendar, Notion, and Todoist applications. In another instance, a user prompted Moltbot to generate an animated face for itself, observing that the AI autonomously added a sleep animation without further instruction.
The Editorial Staff at AIChief is a team of professional content writers with extensive experience in AI and marketing. Founded in 2025, AIChief has quickly grown into the largest free AI resource hub in the industry.