If you’ve been following recent AI trends, you’ve probably come across Clawdbot, Moltbot, or what is now called OpenClaw, after a brief but chaotic rebranding frenzy.
Press enter or click to view image in full size
OpenClaw is an AI-powered personal assistant that can handle tasks like sending emails, filling out web forms, and running system commands, all through simple natural language prompts sent via its gateway chat or popular messaging apps like WhatsApp and Telegram.
Press enter or click to view image in full size
In this story, we’ll explore how publicly exposed OpenClaw instances can be found and accessed online, and how weak configurations combined with a token-stealing flaw can lead to full account takeover and arbitrary code execution.
Disclaimer: The techniques described in this article are for educational and research purposes only. Attempting to access or compromise systems without explicit authorization is illegal. All examples were carried out against an AWS instance created specifically for this research, running a default OpenClaw installation.