OpenClaw is an open-source, self-hosted AI agent created by Austrian developer Peter Steinberger, founder of PDF technology firm PSPDFKit, that connects to messaging apps like WhatsApp and Telegram and can act autonomously on a user’s behalf — reading email, managing calendars, running code, and executing system commands.

Launched in November 2025 under the name Clawdbot, it became one of the fastest-growing open-source projects in GitHub’s history, but its rapid, largely unvetted adoption has also made it one of the most-cited case studies in agentic AI security failures, with implications for individual users, enterprises, and regulators across Southeast Asia.

How does it work?

OpenClaw runs on a hub-and-spoke architecture centred on a Gateway — a long-running process that connects messaging platforms such as WhatsApp, Discord, Telegram, Signal, and iMessage to an underlying AI model. Users install the Gateway on their own hardware, from a spare laptop to a low-cost cloud server, and it routes messages, manages scheduled tasks, and hands off work to “skills” — modular integrations that let the agent take real-world actions across services like GitHub, Notion, and smart home systems.

The project has changed names twice since its debut: launched as Clawdbot in November 2025, it was briefly renamed Moltbot in January 2026 following a trademark complaint from Anthropic, before settling on OpenClaw. Its growth has been unusually fast: one analysis found the project reached 209,000 GitHub stars in under three months, making it the fastest-growing software repository on record. On 14 February 2026, Steinberger announced he was joining OpenAI, handing OpenClaw’s future to an independent open-source foundation.

What do people actually use OpenClaw for?

Reported use cases fall into a few broad categories. On the personal productivity side, users commonly deploy it for inbox triage — categorising messages by urgency and drafting replies for review — as well as scheduled morning briefings that pull from calendars, email, and news feeds into a single message.

Developers use it as a remote control layer for coding and infrastructure work, sending instructions from a phone to edit files, run tasks, or troubleshoot issues on a remote machine. Businesses have adopted it for support-ticket triage and social media monitoring, while content teams use it for research, drafting, and repurposing material across platforms. A notable design feature is that OpenClaw can write and deploy new skills for itself based on a plain-language request — the same self-extending capability that underlies much of its versatility also widens its exposure to abuse, discussed below.

Is OpenClaw safe to use?

Security researchers have documented recurring problems tied directly to how quickly OpenClaw was adopted relative to how it was secured. A Cisco security review, cited in a widely-circulated technical breakdown of the project, found that 11.3 per cent of the community skill marketplace was malicious.

Internet-wide scans have repeatedly found exposed OpenClaw instances. Security teams initially identified 954 installations with gateway ports accessible from the internet, many without authentication, before a later scan by Illumio found more than 4,500 misconfigured installations leaving passwords, API keys, and private data exposed. A separate researcher-documented vulnerability, tracked as CVE-2026-25253, allowed attackers to bypass authentication via the loopback address and remotely encrypt a victim’s disk and steal credentials by luring them to click a single malicious link.

OpenClaw’s own security guidance acknowledges the risk of default configurations. Researchers at Giskard, an AI testing firm, confirmed that once an agent is exposed to public chat apps and equipped with powerful tools, misconfiguration becomes a direct path to data exfiltration and account takeover.

What are the risks for individual users specifically?

Beyond enterprise-scale exposure figures, individual users face a narrower but sharper set of risks:

What does this mean for Singapore and Southeast Asia?

Singapore has moved faster than most jurisdictions to put guardrails around agentic AI. On 22 January 2026, the Infocomm Media Development Authority (IMDA) launched the Model AI Governance Framework for Agentic AI at the World Economic Forum — described by legal analysts as the world’s first governance framework built specifically for AI systems capable of autonomous planning, reasoning, and action. The framework is structured around four areas: bounding risk upfront, keeping humans meaningfully accountable, implementing technical controls, and enabling end-user responsibility. IMDA updated the framework again in May 2026 with case studies addressing multi-agent systems and third-party agents.

The regulatory push has been paired with active adoption incentives. In February 2026, Prime Minister Lawrence Wong announced a National AI Council overseeing “AI missions” across advanced manufacturing, connectivity, finance, and healthcare, alongside an expanded tax scheme letting SMEs claim 400 per cent deductions on qualifying AI expenditure, capped at S$50,000 annually for 2027 and 2028. That combination — strong governance guidance alongside active SME adoption incentives — is precisely the gap OpenClaw’s risk profile exposes: individual developers and small operators are being encouraged to adopt agentic AI tools well ahead of the security literacy needed to run them safely.

The contrast with China is instructive. After OpenClaw’s adoption surged there, Chinese authorities moved to restrict its use on office devices across government agencies and state-linked entities, including major banks, with some employees also warned against installing it on personal phones connected to company networks. Singapore has taken the opposite approach, favouring voluntary guidance and sandbox testing over restriction — a stance that places more responsibility on individual users and organisations to self-govern.

For solo operators and small teams in Singapore weighing whether to adopt OpenClaw, the practical takeaway from the available research is one of configuration, not blanket avoidance: isolate the agent from primary credentials, vet any third-party skill before installing it, and treat an internet-exposed instance as a live liability rather than a convenience.

Author


Discover more from techcoffeehouse.com

Subscribe to get the latest posts sent to your email.

Use promo code “TCH15” to get 15% off on checkout.

Share your thoughts

This site uses Akismet to reduce spam. Learn how your comment data is processed.

Discover more from techcoffeehouse.com

Subscribe now to keep reading and get access to the full archive.

Continue reading

Discover more from techcoffeehouse.com

Subscribe now to keep reading and get access to the full archive.

Continue reading