Home Blog
OpenClaw is stealing your data while you sleep

OpenClaw is stealing your data while you sleep


AI cybersecurity vibe coding

Have you ever handed someone the keys to your house, your car, and your filing cabinet all at once, trusting they’d never use them for anything shady? That’s basically what we’re doing with a new wave of AI assistants. And the most talked about one lately is called OpenClaw.

OpenClaw is like an assistant that lives inside your computer or phone. It opens apps, sends messages over WhatsApp or Telegram, edits files, and remembers everything you do. It’s free, connects to other powerful AIs to solve complex tasks, and can end up controlling everything from your social media to the lights in your house. It sounds incredible, and honestly it is. But to do all of that, it needs the keys to your personal drawers.

The OpenClaw boom

It was created by Peter Steinberger and launched in November 2025. Within weeks it went from an unknown project to surpassing 100,000 stars on GitHub in under seven days, one of the fastest-growing repositories in the platform’s history. OpenAI ended up hiring its creator, and Chinese cloud giants like Alibaba, Tencent, and ByteDance adopted it in record time. People love it because with a few clicks you can build entire products in a matter of days, without being a programming expert. It’s what’s known as “vibe coding”: coding by feel, going with your gut, like cooking without a recipe.

Here’s where the problem starts

Think about everything that assistant needs to see to function: your chats, your emails, your calendar, your passwords. It’s like having someone standing in your living room with a view of the entire house. As long as it’s OpenClaw looking, fine. But what happens if someone else gets in?

And this isn’t a distant hypothesis, it already happened. When OpenClaw exploded in January 2026, the number of instances exposed on the internet jumped from about 1,000 to over 21,000 in less than a week, and some studies counted more than 40,000. Then came ClawHavoc, an attack that planted more than 1,180 malicious plugins on ClawHub, the tool’s official marketplace, disguised as harmless utilities. What did they do? They stole browser passwords, macOS Keychain keys, crypto wallets, and cloud credentials. And on top of that, a chain of flaws was discovered that let any website take full control of the agent without installing a single plugin or making a single click. If an attacker gets in, they can pose as you: read everything, send messages in your name, delete whatever they want. You left the front door open because you trusted the butler, and one slip-up is enough for them to walk in and ransack the place.

The real problem isn’t OpenClaw, it’s the rush

“Vibe coding” has something beautiful about it: anyone can build. But it also has a trap. When you code by intuition and at full speed, you barely stop to check anything. You ship an app in hours without testing security, and every small mistake chains into the next until one minor flaw breaks everything.

Today everyone wants the same thing: products in days, results now. And in that race we forget to close the windows. Personal data ends up floating around out there, exposed, while we celebrate how fast everything shipped.

Security first, then AI

The move isn’t “AI first” but “security first.” It’s like setting the alarm before inviting people over, not after they’ve already broken in. And you don’t need to be an expert to do it right.

Before handing the keys to OpenClaw:

  • Review plugins and extra tools before installing them. Not everything from the community can be trusted.
  • Use limited accounts, never the main one. If something goes wrong, keep the damage contained.
  • Close off access you’re not using. Every extra permission is an open window.
  • Run it through antivirus and test it in a controlled environment before connecting it to your real life.

That way you keep OpenClaw’s magic without giving away your digital life along the way.

Better to prevent it than to be changing every lock at three in the morning.


Sources: Fortune and Tom’s Hardware on the adoption and the creator’s hire; The Hacker News and Kaspersky on the vulnerabilities and the ClawHavoc campaign.

© 2026  By Jere Romano