OpenClaw
OpenClaw is a free, open-source autonomous AI agent that runs on a user's own machine or server and executes real-world tasks through everyday messaging apps such as WhatsApp, Telegram, Discord, Slack, and Signal. Created by Austrian software engineer Peter Steinberger, it began in November 2025 as a weekend project called "WhatsApp Relay," was known as Clawd or Clawdbot and then briefly as "Moltbot," and took the name OpenClaw at the end of January 2026 [1][28]. Its GitHub repository overtook React in early March 2026 to become the most-starred non-aggregator software project on the platform, and it had about 390,800 stars on September 30, 2026 [2][32][31]. Since July 2026 the project has been stewarded by the OpenClaw Foundation, a 501(c)(3) non-profit [29]. NVIDIA CEO Jensen Huang called it "definitely the next ChatGPT" and "the largest, most popular, the most successful open-sourced project in the history of humanity" in a CNBC interview during GTC 2026 [3].
By default, OpenClaw keeps its configuration, memory files, and conversation history on the machine where its Gateway runs, so users control their own data [1][49]; OpenClaw 2.0 (August 2026) added optional shared cloud sessions and cloud workers [42][44]. It is model-agnostic: as of September 2026 its documentation lists official provider plugins for OpenAI models including GPT-6 Astra and GPT-5.6, Anthropic's Claude models including Claude Opus 5.5, Google Gemini, DeepSeek, Moonshot's Kimi, xAI's Grok, and many others, plus locally hosted models through Ollama, LM Studio, vLLM, and similar servers [47][72].
What is OpenClaw?
OpenClaw is an "always on" personal AI agent rather than a chatbot that waits for prompts. Where a conventional assistant generates text in response to a question, OpenClaw can take actions: it controls a web browser, reads and writes files, runs shell commands, schedules recurring jobs, and replies to the user inside whatever chat app they already use [1][10]. Fortune described it as an autonomous agent designed to act as "a kind of digital employee" [4]. At GTC 2026, NVIDIA's Jensen Huang told CEOs that "every company in the world today needs to have an OpenClaw strategy" and said that "every SaaS company will become an agentic company" [18][23].
The project is distributed under the MIT License, with the copyright held by the OpenClaw Foundation [31]. Steinberger announced in February 2026 that the project would move to a foundation when he joined OpenAI [8]; the OpenClaw Foundation was formally launched on July 8, 2026 as a 501(c)(3) American non-profit, and its launch post says Steinberger "keeps making the calls, especially the technical ones" [29][30].
Who created OpenClaw?
Peter Steinberger is best known as the founder of the PDF software company PSPDFKit, to which he says he "poured 13 years" of his life [8][4]. He started what became OpenClaw in November 2025. In his own account, "What started as 'WhatsApp Relay'" was a "weekend project," and the name Clawd, "a playful pun on 'Claude' with a claw," dates from November 2025 [28]. Anthropic's Claude was the reference point for that name [1][28]. Steinberger told podcaster Lex Fridman that he built the prototype because he "was annoyed that it didn't exist, so I just prompted it into existence" [4].
The project stayed small for its first two months. By January 29, 2026, Steinberger wrote, it had "over 100,000 GitHub stars and drew 2 million visitors in a single week" [28].
Steinberger has run an unusually visible development process. On May 15, 2026, he posted a screenshot of his CodexBar usage dashboard showing $1,305,088.81 in OpenAI API spending over 30 days, covering 603 billion tokens and 7.6 million requests, with gpt-5.5 as the top model [33][22]. Tom's Hardware and The Next Web reported that the spending came from roughly 100 OpenAI Codex instances run by a three-person team on the open-source OpenClaw project, that OpenAI (Steinberger's employer since February) covered the cost, and that the agents reviewed pull requests, scanned commits for vulnerabilities, deduplicated GitHub issues, and wrote fixes [22][24]. Steinberger said the figure reflected Codex "Fast Mode" pricing and that turning Fast Mode off would cut the raw cost to around $300,000 [22].
History
Origins as Clawdbot
The openclaw/openclaw GitHub repository was created on November 24, 2025 [31]. The first version was a WhatsApp relay, so a user could text an AI assistant and have it act on their behalf [28][5]. CNBC reported that the agent, "previously known as Clawdbot and Moltbot," was first launched in November by Steinberger [5].
Why was OpenClaw renamed?
Steinberger wrote that the Clawd name "felt perfect until Anthropic's legal team politely asked us to reconsider" [28]. After Anthropic raised trademark concerns, the project was rebranded to "Moltbot" on January 27, 2026 [26]. The name was chosen "in a chaotic 5am Discord brainstorm with the community"; molting refers to lobsters shedding their shells to grow, but Steinberger said the name "never quite rolled off the tongue" [28].
Steinberger announced the final name, "OpenClaw," in a blog post dated January 29, 2026, saying that trademark searches had come back clear and domains had been bought [28]. "Open" stood for open source and "Claw" for the lobster heritage, and the lobster stayed on as the mascot [28]. The same release added Twitch and Google Chat plugins, support for Kimi K2.5 and Xiaomi MiMo-V2-Flash, and 34 security-related commits [28].
Viral growth and the Moltbook phenomenon
OpenClaw's explosive growth coincided with the launch of Moltbook, a Reddit-like social network created by entrepreneur Matt Schlicht for AI agents such as OpenClaw bots [1][6]. Censys dates Moltbook's launch to January 27, 2026 [26]. Humans were not meant to post, but researchers soon showed that the site was insecure and that people could easily pose as AI agents; TechCrunch reported that Moltbook "went viral because of fake posts" [6]. The attention nonetheless drove interest back to OpenClaw itself [1][6].
Star counts rose quickly. Star History reported in late February 2026 that OpenClaw had passed Linux on GitHub's all-time star leaderboard, and in early March that it had crossed 250,000 stars and overtaken React (about 243,000 stars) to become "the most-starred non-aggregator software project on GitHub," going "from zero to #1 in under four months" [32][2][7]. The Next Web reported more than 302,000 stars by April 2026 [24]. On September 30, 2026, the repository had 390,800 stars and 82,199 forks [31]; only five repositories on GitHub had more stars: build-your-own-x, awesome, public-apis, freeCodeCamp, and free-programming-books [65]. The OpenClaw Foundation calls OpenClaw "the fastest growing repository in GitHub history" [29].
Steinberger joins OpenAI
On February 14, 2026, Steinberger announced that he would be joining OpenAI "to work on bringing agents to everyone" and that "OpenClaw will move to a foundation and stay open and independent" [8]. He wrote that OpenAI "already sponsors the project" [8]. The next day Sam Altman wrote on X that Steinberger was "joining OpenAI to drive the next generation of personal agents," called him "a genius with a lot of amazing ideas about the future of very smart agents interacting with each other to do very useful things for people," and said OpenClaw would "live in a foundation as an open source project that OpenAI will continue to support" [25]. According to the OpenClaw Foundation, Steinberger now leads Claw Labs, a team inside OpenAI that works on shared product improvements [29][37].
Meta acquired Moltbook in March 2026, bringing Moltbook CEO Matt Schlicht and COO Ben Parr into Meta Superintelligence Labs; CNBC and TechCrunch reported the deal on March 10, 2026 [9][6].
The OpenClaw Foundation
The foundation took five months to arrive. The New Stack reported that in March 2026 the process of attaining 501(c)(3) status "was still a work in progress" [30]. On July 8, 2026, Dave Morin (chair of the board) and Steinberger announced that "OpenClaw is officially a 501(c)(3) American non-profit organization," with a first full-time team of six engineers, led by Chief Architect Vincent Koc, and four operations staff and a stated goal of keeping OpenClaw "MIT licensed, open, and independent" [29][30]. The launch post named OpenAI, NVIDIA, Microsoft, the University of Michigan, Red Hat, and Tencent among its partners, said OpenAI and the University of Michigan were major donors, and described "Foundation-convened councils on agent identity, agent profiles, evals, and enterprise deployment" [29]. The foundation also claimed "4.5 million new claws being born every week" [29]. Red Hat later said it had joined as a sponsor in July, with its upstream work led by OpenClaw maintainer Sally O'Malley [54]. See OpenClaw Foundation for more detail.
How does OpenClaw work?
OpenClaw's technical architecture is built around two primary components: the Gateway and the agent runtime [10][73].
The Gateway
The Gateway is a single long-lived process on the user's machine (or a VPS) that "owns all messaging surfaces," including WhatsApp, Telegram, Slack, Discord, Signal, iMessage, and WebChat [10]. Control clients such as the macOS app, the CLI, and the web UI connect to it over WebSocket on the configured bind host, which defaults to 127.0.0.1:18789; companion "nodes" on macOS, iOS, and Android connect to the same server and expose device commands such as camera capture, screen recording, and location [10]. The documentation specifies one Gateway per host [10].
The Gateway:
- Maintains connections to the configured messaging providers
- Exposes a typed WebSocket API of requests, responses, and server-push events, and validates inbound frames against JSON Schema
- Emits events such as agent, chat, presence, health, heartbeat, and cron
- Handles device pairing and authentication for remote clients [10]
The agent runtime
The agent loop is, in the documentation's words, "the serialized, per-session run that turns a message into actions and a reply: intake, context assembly, model inference, tool execution, streaming, persistence" [73]. Direct messages share a main session by default, while group chats, rooms, and webhooks each get isolated sessions [74]. Since May 2026, OpenAI agent turns run by default through OpenAI's native Codex app-server harness, with OpenClaw keeping control of channels, persona, memory, sessions, scheduling, and its own tools [46].
Agent loop
The core agent loop follows a structured sequence for every interaction [73]:
| Step | Action | Description |
|---|---|---|
| 1 | Message reception | Gateway receives a message from a connected platform |
| 2 | Session routing | Message is routed to the appropriate session context |
| 3 | Context loading | Agent loads relevant skills, memory, and conversation history |
| 4 | LLM call | Conversation is sent to the configured language model |
| 5 | Tool execution | Any tool calls requested by the model are executed |
| 6 | Response streaming | Reply is streamed back to the originating channel |
| 7 | Memory persistence | Conversation and memory updates are written to the workspace |
Context management and compaction
To stay within model context limits, OpenClaw performs automatic compaction: older conversation turns are summarized into a compact entry saved in the session transcript, while recent messages are kept intact and the full history stays on disk [50]. Before compacting, OpenClaw reminds the agent to save important notes to its memory files [50].
Memory and storage
OpenClaw's memory is written as plain Markdown files in the agent's workspace; the documentation says "the model only remembers what gets saved to disk; there is no hidden state" [49]. As of September 2026 the memory files are:
- USER.md (optional): stable preferences and profile facts written as directives.
- MEMORY.md: long-term memory of durable facts and decisions, loaded at the start of a session.
- memory/YYYY-MM-DD.md: daily notes, indexed for memory search.
- DREAMS.md (optional): summaries from the background "dreaming" sweep that distills daily notes into MEMORY.md [49].
Session records and transcripts, originally stored as JSONL files, now live by default in a per-agent SQLite database, with an import path for legacy JSONL history [74]. Because memory is plain text, users can inspect, edit, or delete it at any time.
Which models does OpenClaw support?
OpenClaw is model-agnostic. Official provider plugins publish their own model catalogs, and other providers or local servers can be added through custom provider configuration [11][47][72]. The table shows examples listed in the documentation as of September 2026:
| Provider | Example models in the docs | Notes |
|---|---|---|
| OpenAI | GPT-6 Astra (fresh-setup default), GPT-5.6 Sol, Terra and Luna, GPT-5.5 | API key or ChatGPT/Codex sign-in; agent turns use the Codex app-server harness by default [46][47] |
| Anthropic | Claude Opus 5.5 | API key, or the Claude CLI as a backend [47] |
| Gemini 3.1 Pro Preview, Gemini 3.5 Flash | API key; Vertex and Gemini CLI runtime also documented [47] | |
| DeepSeek | DeepSeek V4 Flash | Official provider plugin [47] |
| Moonshot AI | Kimi K2.6; Kimi K3 in the custom-provider example | Plugin install required for Moonshot [47][72] |
| xAI | Grok 4.7 | SuperGrok/X Premium sign-in or API key [47] |
| Other bundled plugins | MiniMax M3, Z.AI GLM-5.2, Mistral, Xiaomi MiMo-V2.6 Pro, Tencent Hy3 preview, NVIDIA Nemotron 3 Ultra, OpenRouter, Groq, Together, and others | Listed in the official provider plugin table [47] |
| Local runtimes | Ollama (example: Llama 3.3), LM Studio, vLLM, SGLang, llama.cpp | Run on the user's own hardware [72] |
Users can set a primary model, configure failover chains, and assign different models to different agents [11][47].
Features
Multi-channel messaging support
Users talk to their agent through chat applications they already use. As of September 2026 the documentation's channel catalog lists 32 channels, some bundled, some installed as official plugins, and some maintained externally [48]:
| Category | Platforms |
|---|---|
| Consumer messaging | WhatsApp, Telegram, Signal, iMessage, LINE, SMS (Twilio) |
| Team collaboration | Slack, Discord, Microsoft Teams, Google Chat, Mattermost, Nextcloud Talk, Synology Chat |
| Open and developer protocols | IRC, Matrix, Nostr, A2A, WebChat |
| Regional platforms | Feishu, WeChat and WeCom (external plugins), QQ bot, Yuanbao, Zalo |
The older BlueBubbles route for iMessage has been replaced by a native iMessage integration [48][10]. The user's phone or desktop messaging app becomes the interface to an agent running on hardware they control.
Built-in tools
OpenClaw ships with a set of core tools that give the agent practical capabilities [1][10]:
- Browser automation: The agent can navigate websites, fill forms, click buttons, and extract information from web pages.
- File system access: Read, write, create, and organize files on the host machine.
- Shell execution: Run terminal commands and scripts, subject to configurable exec approvals.
- Automations: Set up recurring and scheduled jobs.
- Webhooks: Respond to external events and triggers from other services.
- Camera and screen recording: Capture visual information through paired device nodes.
A May 2026 security roadmap said the project was experimenting with contextual approval to cut prompt fatigue, and that OpenAI users could turn on Auto Review, a Codex-specific feature that replaces manual approval at the sandbox boundary with a separate reviewer agent [38].
Skills and ClawHub
Beyond built-in tools, OpenClaw's capabilities can be extended through "skills." Each skill is a directory containing a SKILL.md file with YAML frontmatter and Markdown instructions that teach the agent how and when to use tools; skills can be bundled, installed, or stored in a workspace [51][1].
ClawHub is the public registry for these skills. It stores "a SKILL.md plus supporting files," and skills are installed with commands such as clawhub install [12]. The catalog grew fast: Koi Security audited 2,857 ClawHub skills in early February 2026, Kaspersky counted around 6,000 on February 10, and the security dataset OpenClaw released in June 2026 covered 67,453 latest public skill versions [34][17][39]. Since June 2026 every published skill carries an NVIDIA Skill Card describing who published it, what it can do, and what the scanners found, viewable with openclaw skills verify <slug> --card [39].
Local-first privacy
Unlike SaaS AI assistants where user data resides on third-party servers, OpenClaw runs where the user chooses: a laptop, a home server, or a VPS [28]. Conversation history, configuration, and memory files remain under the user's control. The agent sends data outward when it calls a cloud-hosted LLM API or a messaging platform API, and Kaspersky warned that even a carefully configured agent sends every request and all processed data to the chosen LLM provider [17].
Releases in 2026
OpenClaw uses calendar-style version numbers (for example 2026.8.1) and has shipped at a very high cadence; the project said it released 106 versions in 230 days before OpenClaw 2.0 [42][44].
| Date | Release or change | Details |
|---|---|---|
| April 24-29, 2026 | 2026.4.24 to 2026.4.29 | Slower Gateways and plugin dependency repair loops; Steinberger apologized on May 5 and announced a smaller core and an LTS plan [63] |
| May 14, 2026 | Codex harness default | OpenAI agent turns switched to the native Codex app-server harness by default [46] |
| June 30, 2026 | 2026.6.11 | Reliability release focused on misplaced replies, stuck sends, reconnects, and safer admin defaults [44] |
| July 13, 2026 | 2026.7.1 | Control UI and onboarding overhaul, app updates, GPT-5.6 compatibility; 3,063 contributions from 532 contributors [44] |
| July 30, 2026 | Extended-stable channel | Monthly long-lived releases numbered YYYY.M.33 with backported fixes, plus a public feature maturity scorecard [45] |
| August 30, 2026 | 2026.8.1 ("OpenClaw 2.0") | Simpler installation, rebuilt browser app, shared cloud sessions, conversation search, masked credential requests; built by 933 contributors from over 16,000 pull requests [42][44] |
| September 3, 2026 | 2026.9.1 and new installers | Native macOS installer and automatic local model setup on Windows PCs with NVIDIA RTX GPUs of at least 24 GB [64][44] |
| September 23, 2026 | 2026.9.6 | Latest regular release as of September 30, 2026: 2,614 pull requests from 351 contributors [44] |
| September 29, 2026 | 2026.8.33 | Extended-stable release adding GPT-6 Astra, Muse Spark 1.3 and other model support plus security fixes [44] |
The Register reviewed OpenClaw 2.0 as doing "a lot to make installing and getting OpenClaw up and running for more people," but "not bringing security by default along with that accessibility," noting that the release notes describe shared sessions as "not tenant isolation or a security boundary," that Secret Store values "are not encrypted at rest," and that a new sandbox for untrusted code is turned off by default [43].
Is OpenClaw safe?
OpenClaw's rapid adoption raised serious security concerns and drew attention from major cybersecurity firms and government agencies. Cisco's AI security researchers titled their analysis "Personal AI Agents like OpenClaw Are a Security Nightmare," pointing to an agent that can run shell commands, read and write files, and execute scripts with broad privileges [14]. Microsoft's security team advised that OpenClaw "should be treated as untrusted code execution with persistent credentials" and run only in fully isolated environments [16].
Vulnerabilities
Several serious vulnerabilities were discovered in OpenClaw's early months:
- CVE-2026-25253: OpenClaw versions before 2026.1.29 took a
gatewayUrlvalue from a query string and automatically opened a WebSocket connection to it, sending the user's token [35]. The flaw is rated 8.8 (High) on the CVSS 3.1 scale [35]. ProArch described the resulting attack chain: a victim visits a malicious page, the token leaks, and the attacker connects to the victim's Gateway, turns off exec approvals, and runs arbitrary commands [13]. - Mass findings: Kaspersky reported that a security audit in late January 2026 identified 512 vulnerabilities, eight of them classified as critical [17].
- Prompt injection attacks: Kaspersky described demonstrations in which an email containing hidden instructions caused an agent to hand over a private key [17]. Microsoft warned that the agent's persistent memory "can be modified, causing it to follow attacker-supplied instructions over time" [16].
In April 2026 Steinberger wrote that GitHub showed 1,309 security advisories filed against OpenClaw since January 10, of which 535 were published and 746 closed as invalid [37]. By September 16, 2026, the project's security team said 722 fixes had been published since January and that 14 reports had resulted in confirmed critical vulnerabilities, all fixed and disclosed [40].
Exposed instances
Because many users exposed the Gateway to the internet during the late-January 2026 adoption surge, large numbers of OpenClaw installations were reachable online. Kaspersky reported that a researcher's Shodan scan in late January found nearly a thousand publicly accessible installations running without any authentication [17]. Censys researcher Silas Cutler tracked growth from around 1,000 to more than 21,000 instances in under a week and identified 21,639 exposed instances as of January 31, 2026, though Censys noted that most of them still required a token to use [26]. Bitsight observed more than 30,000 instances between January 27 and February 8 [15]. Security researcher Jamieson O'Reilly gained access to Anthropic API keys, Telegram bot tokens, Slack accounts, and months of complete chat histories, and could send messages on behalf of users and execute commands with full administrator privileges [17]. On February 7, 2026, OpenClaw named O'Reilly, the founder of Dvuln, as lead security advisor [36].
Malicious skills
The ClawHub marketplace also became a supply-chain attack vector. On February 2, 2026, Koi Security reported that an audit of 2,857 ClawHub skills had found 341 malicious skills across multiple campaigns; 335 of them, a campaign Koi codenamed "ClawHavoc," used fake prerequisites to install the Atomic Stealer (AMOS) macOS infostealer, and a Windows variant shipped a trojan with keylogging functionality [34]. Kaspersky separately counted more than 230 malicious skills published between January 27 and February 1 [17]. ProArch later cited more than 800 malicious skills identified in the marketplace [13]. Cisco found that a skill ranked first in the repository, "What Would Elon Do?," silently exfiltrated data and used prompt injection to bypass safety guidelines [14].
Enterprise exposure
Bitsight reported OpenClaw instances in sensitive sectors including healthcare, finance, government, and insurance, suggesting the software was already running inside corporate networks [15]. Microsoft, Cisco, and Kaspersky all published guidance warning organizations about the risks of OpenClaw deployments [14][16][17].
Security improvements
The project responded in public. The OpenClaw rename release on January 29, 2026 included 34 security-related commits [28], and version 2026.1.29 fixed CVE-2026-25253 [35]. On February 7, 2026, ClawHub began scanning every published skill with VirusTotal, including its Gemini-powered Code Insight analysis, with malicious skills blocked from download [36]. By April 2026 the project had written a trust model into its SECURITY.md file, moved functionality out of the core into plugins, and adopted CodeQL, Semgrep, and OpenAI's Codex Security for code review [37]. A May 15, 2026 roadmap described the fs-safe filesystem library, the Proxyline egress-routing layer, ClawHub trust signals, command-chain parsing for approvals, and a 148-rule OpenGrep rulepack built from past advisories [38].
On June 1, 2026, OpenClaw announced a collaboration with NVIDIA in which every ClawHub skill passes through three scanners (OpenClaw's static analysis, VirusTotal, and NVIDIA SkillSpector) before a Codex-based step called ClawScan issues a verdict of clean, suspicious, or malicious [39]. The scanners barely agreed: only 468 skills (0.69%) were flagged by all three, and the project released its scan results as a public dataset on Hugging Face [39]. On September 16, 2026, the project launched a public security page at openclaw.ai/security and said its security reviewers include engineers from NVIDIA and Tencent [40]. On September 21, 2026, it published the results of a Trail of Bits audit carried out through OpenAI's Patch the Planet initiative: 27 private advisories, of which 24 were severity-rated (0 critical, 2 high, 16 medium, 6 low), which the project said were all repaired and shipped in the 2026.8.1 and 2026.7.33 releases [41]; its release notes separately describe 2026.7.33 as an unstable extended-stable build that was not published as a GitHub Release, with 2026.7.35 the first published July-line release [44].
Ecosystem and derivatives
NemoClaw and OpenShell (NVIDIA)
NVIDIA announced NemoClaw during Jensen Huang's GTC keynote on March 16, 2026, as an enterprise-grade agent platform built on top of OpenClaw [18]. The OpenClaw Foundation describes it as "one command" that installs OpenClaw with open Nemotron models and the OpenShell secure runtime [29]. At launch NVIDIA called NemoClaw an early-stage alpha release [18]. NVIDIA's involvement has since widened: Steinberger credited NVIDIA with "engineering time, security thinking and work on NemoClaw and OpenShell" [37], NVIDIA co-developed ClawHub's skill scanning [39], and NVIDIA engineers help review OpenClaw security reports [40].
OpenClaw Enterprise
On September 29, 2026, the OpenClaw Foundation announced OpenClaw Enterprise (OCE), which it describes as "an open source, vendor neutral platform for managing persistent agents in sensitive environments" [52]. The foundation's post says OCE "originally started at OpenAI and then was donated to the OpenClaw Foundation" and has been developed with Red Hat and NVIDIA; the foundation's announcement on X described the Foundation as open sourcing the control plane "in collaboration with @RedHat, @nvidia and @OpenAI" [52][56]. OCE is MIT-licensed and its README calls it "Kubernetes for agents," built around the OpenClaw Control Plane (OCC) [57]. The foundation says OCE is suitable for "internal pilot workloads" ahead of a 1.0 release "later this year," can run with docker-compose for local development or on Kubernetes, and "will always be free for any organization to use" [52]. NVIDIA said organizations can use OpenShell "as an open source option for governing agents with OpenClaw Enterprise," and OCE's documentation lists OpenShell as the bundled integration for its optional sandbox, while noting that the stock OpenShell gateway cannot yet honor the identity and token references the control plane requires and that local verification relies on development-only workarounds, not a supported production path [55][58]. Red Hat, which the foundation names as an internal OCE pilot [52] and which says it looks forward to deploying OCE for its own internal agent deployments, described it as "an enterprise-grade control plane for deploying and operating persistent agents" [53]. VentureBeat noted that enterprises would still pay for their own compute, models, and infrastructure [59].
Microsoft Autopilot
Microsoft built its Scout agent, renamed Autopilot on September 25, 2026, on OpenClaw, and Microsoft engineers have contributed policy-conformance checks, a native Windows companion app, and a Windows sandbox backend upstream [60][29].
Other derivatives and forks
| Project | Description |
|---|---|
| IronClaw (NEAR AI) | "A Rust reimplementation inspired by OpenClaw" with WebAssembly-sandboxed tools [67] |
| ZeroClaw | Single-binary Rust personal assistant runtime with 30+ channels and hardware support [68] |
| GitClaw | "OpenClaw but it runs entirely on github actions" [69] |
| MoltWorker (Cloudflare) | Runs OpenClaw on Cloudflare Workers [66] |
| TenacitOS | "OpenClaw Mission Control Dashboard" [70] |
| NanoClaw | "A lightweight alternative to OpenClaw that runs in containers for security" [71][59] |
The breadth of the derivative ecosystem reflects both the project's popularity and the demand for specialized versions tailored to different deployment scenarios.
International adoption and restrictions
Global spread
OpenClaw's adoption spread rapidly beyond its European origins. Bloomberg reported in March 2026 that China's tech scene was "buzzing with OpenClaw hype and products" [19]. Chinese users paired OpenClaw with Chinese-developed models such as DeepSeek and configured it to work with Chinese messaging apps [5], and Tencent, Alibaba, Baidu, and MiniMax launched compatible tools; Chinese users nicknamed running it "raising lobsters" [20].
Local governments offered large subsidies for companies building on OpenClaw. In Shenzhen, Longgang district proposed subsidies of up to 2 million yuan (about US$289,000) for OpenClaw app developments [20], and its draft measures, open for public comment until April 6, 2026, included subsidies and financing of up to 10 million yuan (US$1.4 million) for companies that build notable OpenClaw applications, free computing resources, and discounted office space for "one-person companies" [62][27].
China restrictions
In March 2026, Chinese authorities moved to restrict state-run enterprises and government agencies, including the largest banks, from running OpenClaw on office computers, citing security concerns [61][20]. According to Bloomberg, several organizations were told to notify superiors if they had already installed related apps, for security checks and possible removal; some employees were barred from installing OpenClaw on office computers and on personal phones using company networks, and one person said the ban extended to the families of military personnel [61]. Other notices stopped short of an outright ban and required prior approval before use [61]. The Ministry of Industry and Information Technology's National Vulnerability Database also published security guidelines for OpenClaw users [20]. Local governments were thus subsidizing OpenClaw development while national agencies restricted its use [61][62].
Criticism and controversy
OpenClaw has drawn criticism on several fronts. Cisco called personal agents like OpenClaw "a security nightmare" [14], and Gary Marcus, a prominent AI critic, published an essay titled "OpenClaw (a.k.a. Moltbot) is everywhere all at once, and a disaster waiting to happen," warning about deploying autonomous agents at scale without adequate safety controls [21]. The Register was still describing the project's security posture as a "slow-burning security dumpster fire" when OpenClaw 2.0 shipped in August 2026 [43].
Steinberger has pushed back on part of this. He argued that many security reports were low-quality, noting that 87% of reports labeled critical had been closed as invalid, and said a widely shared research paper had tested OpenClaw with guardrails disabled; he described OpenClaw as "built for one trusted person per agent" [37]. The OpenClaw Foundation itself acknowledged in September 2026 that "the default stance of IT in most organizations is to ban agentic platforms like OpenClaw altogether," which it cited as the reason for building OpenClaw Enterprise [52].
Timeline
| Date | Event |
|---|---|
| November 24, 2025 | GitHub repository created; the project starts as "WhatsApp Relay" and becomes Clawd/Clawdbot [31][28] |
| January 27, 2026 | Renamed to Moltbot following Anthropic trademark concerns; Moltbook launches [26] |
| January 29, 2026 | Renamed to OpenClaw; version 2026.1.29 fixes CVE-2026-25253 [28][35] |
| January 31, 2026 | Censys counts 21,639 exposed instances [26] |
| February 2, 2026 | Koi Security reports 341 malicious ClawHub skills, 335 of them in the "ClawHavoc" campaign [34] |
| February 7, 2026 | VirusTotal scanning comes to ClawHub; Jamieson O'Reilly named lead security advisor [36] |
| February 14-15, 2026 | Steinberger announces he is joining OpenAI and that OpenClaw will move to a foundation [8][25] |
| Early March 2026 | Passes 250,000 GitHub stars, overtaking React [32] |
| March 2026 | China restricts OpenClaw use in state agencies and banks [61] |
| March 10, 2026 | Meta's acquisition of Moltbook reported [6][9] |
| March 16-17, 2026 | NVIDIA announces NemoClaw at GTC; Jensen Huang calls OpenClaw "the next ChatGPT" [18][3] |
| April 2026 | Surpasses 300,000 GitHub stars [24] |
| May 15, 2026 | Steinberger posts a $1.3 million, 30-day OpenAI API bill; security roadmap published [33][38] |
| June 1, 2026 | ClawHub skill scanning with NVIDIA SkillSpector and Skill Cards [39] |
| July 8, 2026 | OpenClaw Foundation launches as a 501(c)(3) non-profit [29] |
| July 30, 2026 | Extended-stable release channel announced [45] |
| August 30, 2026 | OpenClaw 2.0 (2026.8.1) released [42] |
| September 16, 2026 | Public security page launched [40] |
| September 21, 2026 | Trail of Bits audit results published [41] |
| September 25, 2026 | Microsoft's OpenClaw-based Scout agent renamed Autopilot [60] |
| September 29, 2026 | OpenClaw Enterprise announced [52] |
Current state
As of September 30, 2026, OpenClaw is stewarded by the OpenClaw Foundation, a 501(c)(3) non-profit with a full-time staff, and remains MIT-licensed [29][31]. The repository had 390,800 GitHub stars, making it the sixth-most-starred repository on GitHub [31][65]. The latest regular release was 2026.9.6 (September 23), with a monthly extended-stable line for organizations that want fewer changes [44][45].
The project's priorities have shifted from growth toward stability and security: OpenClaw 2.0 simplified installation, the foundation publishes security statistics and audit results, and ClawHub runs multiple scanners on every skill [42][40][41][39]. Large companies now build on it, including Microsoft (Autopilot), NVIDIA (NemoClaw), Red Hat, and OpenAI, whose internal agents are among the first pilots of OpenClaw Enterprise [60][18][54][52]. Security critics argue that the defaults still leave too much to users [43].
ELI5: OpenClaw explained simply
Imagine a really smart helper that lives on your own computer instead of on someone else's. You talk to it the same way you text a friend on WhatsApp or Telegram, but instead of just chatting back, it can actually do things: open websites, fill out forms, organize your files, or run errands on the computer for you. Because it lives on your machine, your messages and notes stay with you and not on a company's server. A programmer named Peter built it as a fun weekend project, gave it a lobster mascot, and so many people loved it that it became one of the most "starred" projects ever on GitHub (a website where coders share their work). The tricky part is that a helper this powerful can be dangerous if it is not locked up properly, which is why security experts keep warning people to set it up carefully.
See also
- Large language model
- AI agents
- Open-source AI
- AI safety
- Prompt injection
- Function calling
- Moltbook
- OpenClaw Foundation
- OpenClaw Enterprise
- NVIDIA NemoClaw
- NVIDIA OpenShell
- Hermes Agent
References
- ^1 ^2 ^3 ^4 ^5 ^6 ^7 ^8OpenClaw - Wikipedia
- ^1 ^2OpenClaw rocks to GitHub's most-starred status, but is it safe? - The New Stack
- ^1 ^2Nvidia CEO Jensen Huang says OpenClaw is 'definitely the next ChatGPT' - CNBC
- ^1 ^2 ^3Who is OpenClaw creator Peter Steinberger? The developer who caught the attention of OpenAI - Fortune
- ^1 ^2 ^3From Clawdbot to Moltbot to OpenClaw: Meet the AI agent generating buzz and fear globally - CNBC
- ^1 ^2 ^3 ^4 ^5Meta acquired Moltbook, the AI agent social network that went viral because of fake posts - TechCrunch
- ^OpenClaw Just Beat React's 10-Year GitHub Record in 60 Days - Medium
- ^1 ^2 ^3 ^4 ^5OpenClaw, OpenAI and the future - Peter Steinberger
- ^1 ^2Meta gets into social networks for AI agents with Moltbook acquisition - CNBC
- ^1 ^2 ^3 ^4 ^5 ^6 ^7 ^8Gateway Architecture - OpenClaw Documentation
- ^1 ^2Model Providers - OpenClaw Documentation
- ^ClawHub - GitHub
- ^1 ^2OpenClaw CVE-2026-25253: Affected Versions, Patch and Immediate Fixes - ProArch
- ^1 ^2 ^3 ^4Personal AI Agents like OpenClaw Are a Security Nightmare - Cisco Blogs
- ^1 ^2OpenClaw Security: Risks of Exposed AI Agents Explained - Bitsight
- ^1 ^2 ^3Running OpenClaw safely: identity, isolation, and runtime risk - Microsoft Security Blog
- ^1 ^2 ^3 ^4 ^5 ^6 ^7 ^8Don't get pinched: the OpenClaw vulnerabilities - Kaspersky
- ^1 ^2 ^3 ^4 ^5Nvidia's version of OpenClaw could solve its biggest problem: security - TechCrunch
- ^China's Tech Scene Is Buzzing With OpenClaw Hype and Products - Bloomberg
- ^1 ^2 ^3 ^4China bans OpenClaw from government computers and issues security guidelines amid adoption frenzy - Tom's Hardware
- ^OpenClaw (a.k.a. Moltbot) is everywhere all at once, and a disaster waiting to happen - Gary Marcus
- ^1 ^2 ^3OpenClaw creator burned through $1.3 million in OpenAI API tokens in a single month - Tom's Hardware
- ^Huang says OpenClaw to transform every SaaS into agentic company: GTC - Seeking Alpha
- ^1 ^2 ^3OpenClaw creator's $1.3 million monthly OpenAI bill reveals the real cost of autonomous AI coding at scale - The Next Web
- ^1 ^2OpenClaw creator Peter Steinberger joining OpenAI, Altman says - CNBC
- ^1 ^2 ^3 ^4 ^5OpenClaw in the Wild: Mapping the Public Exposure of a Viral AI Assistant - Censys
- ^Chinese local governments offer OpenClaw project subsidies as security questions linger - South China Morning Post
- ^1 ^2 ^3 ^4 ^5 ^6 ^7 ^8 ^9 ^10 ^11 ^12 ^13 ^14Introducing OpenClaw - OpenClaw Blog (Peter Steinberger, January 29, 2026)
- ^1 ^2 ^3 ^4 ^5 ^6 ^7 ^8 ^9 ^10 ^11Introducing the OpenClaw Foundation - OpenClaw Blog (Dave Morin and Peter Steinberger, July 8, 2026)
- ^1 ^2 ^3"The Switzerland of AI": OpenClaw becomes a non-profit foundation - The New Stack
- ^1 ^2 ^3 ^4 ^5 ^6 ^7openclaw/openclaw - GitHub repository (star and fork counts retrieved September 30, 2026)
- ^1 ^2 ^3OpenClaw Surpasses React to Become the Most-Starred Software Project on GitHub - Star History
- ^1 ^2Peter Steinberger (@steipete), post with CodexBar API cost screenshot, May 15, 2026 - X
- ^1 ^2 ^3Researchers Find 341 Malicious ClawHub Skills Stealing Data from OpenClaw Users - The Hacker News
- ^1 ^2 ^3 ^4CVE-2026-25253 - National Vulnerability Database
- ^1 ^2 ^3OpenClaw Partners with VirusTotal for Skill Security - OpenClaw Blog (February 7, 2026)
- ^1 ^2 ^3 ^4 ^5How OpenClaw Got Safer in Public - OpenClaw Blog (Peter Steinberger, April 30, 2026)
- ^1 ^2 ^3Where OpenClaw Security Is Heading - OpenClaw Blog (Jesse Merhi, May 15, 2026)
- ^1 ^2 ^3 ^4 ^5 ^6 ^7OpenClaw Collaborates with NVIDIA for Stronger Agent Skill Security - OpenClaw Blog (June 1, 2026)
- ^1 ^2 ^3 ^4 ^5Where to find OpenClaw security updates - OpenClaw Blog (OpenClaw Security Team, September 16, 2026)
- ^1 ^2 ^3OpenClaw Completes Security Audit Through OpenAI's Patch the Planet Initiative - OpenClaw Blog (September 21, 2026)
- ^1 ^2 ^3 ^4 ^5OpenClaw 2.0, Accidentally - OpenClaw Blog (Hannes Rudolph, August 30, 2026)
- ^1 ^2 ^3OpenClaw 2.0 pours glitter on slow-burning security dumpster fire - The Register
- ^1 ^2 ^3 ^4 ^5 ^6 ^7 ^8 ^9 ^10Releases - openclaw/openclaw - GitHub
- ^1 ^2 ^3On the Road to LTS: Extended-Stable Releases and the Maturity Scorecard - OpenClaw Blog (Kevin Lin, July 30, 2026)
- ^1 ^2 ^3OpenAI Models in OpenClaw, Done Right - OpenClaw Blog (Nik Pash, May 14, 2026)
- ^1 ^2 ^3 ^4 ^5 ^6 ^7 ^8 ^9 ^10Official provider plugins - OpenClaw Documentation
- ^1 ^2Chat channels - OpenClaw Documentation
- ^1 ^2 ^3Memory overview - OpenClaw Documentation
- ^1 ^2Compaction - OpenClaw Documentation
- ^Skills - OpenClaw Documentation
- ^1 ^2 ^3 ^4 ^5 ^6 ^7OpenClaw Enterprise - The Open Agent Platform - OpenClaw Blog (Kevin Lin, September 29, 2026)
- ^Why Red Hat is building an open foundation for enterprise agents with OpenClaw Enterprise - Red Hat Blog (Joe Fernandes, September 29, 2026)
- ^1 ^2Red Hat sponsors the OpenClaw Foundation to advance an open future for production AI agents - Red Hat Blog (Stephen Watt, September 9, 2026)
- ^NVIDIA AI (@NVIDIAAI), post on OpenClaw Enterprise and OpenShell, September 30, 2026 - X
- ^OpenClaw (@openclaw), "Today we're announcing OpenClaw Enterprise", September 29, 2026 - X
- ^openclaw/openclaw-enterprise - GitHub repository
- ^Sandbox - OpenClaw Enterprise documentation (GitHub)
- ^1 ^2OpenClaw launches free enterprise control plane for persistent AI agents, backed by OpenAI, Red Hat and Nvidia - VentureBeat
- ^1 ^2 ^3Microsoft Autopilot is built on OpenClaw. The contributions go both ways. - OpenClaw Blog (Graham McBain, September 25, 2026)
- ^1 ^2 ^3 ^4 ^5China moves to curb use of OpenClaw AI at banks, state agencies - The Star (Bloomberg)
- ^1 ^2China's Shenzhen backs OpenClaw AI with subsidies, despite Beijing's security concerns - The Standard (Reuters)
- ^OpenClaw Had a Rough Week - OpenClaw Blog (Peter Steinberger, May 5, 2026)
- ^OpenClaw improves user onboarding with a new installer on macOS, plus easier local model setup for Windows NVIDIA RTX PCs - OpenClaw Blog (September 3, 2026)
- ^1 ^2GitHub repository search: repositories with more than 200,000 stars, sorted by stars (retrieved September 30, 2026)
- ^cloudflare/moltworker - GitHub repository
- ^nearai/ironclaw - GitHub repository
- ^zeroclaw-labs/zeroclaw - GitHub repository
- ^SawyerHood/gitclaw - GitHub repository
- ^carlosazaustre/tenacitOS - GitHub repository
- ^nanocoai/nanoclaw - GitHub repository
- ^1 ^2 ^3 ^4Custom providers and local runtimes - OpenClaw Documentation
- ^1 ^2 ^3Agent loop - OpenClaw Documentation
- ^1 ^2Session management - OpenClaw Documentation
Improve this article
Add missing citations, update stale details, or suggest a clearer explanation. Every suggestion is reviewed for sourcing before it goes live.
6 revisions · v7 · 6,494 words · full history
Fact-checks are independent of edits: a reviewer re-verifies the article against its sources and stamps the date. How we verify
Research and drafting on this wiki are AI-assisted, under named human editorial standards. How AI is used here
Reviewer note: Independent verification V4 (xg13, 30 Sep 2026): ~175 claims vs ~120 sources (all 74 refs, GitHub API, NVD, Star History, Koi, Kaspersky/Censys/Bitsight, CNBC); 1 material (auto-approval mode dating) + 5 minor fixed
Cite this page: AI Wiki. "OpenClaw." aiwiki.ai, updated 30 Sept 2026, fact-checked 30 Sept 2026. CC BY 4.0. https://aiwiki.ai/wiki/openclaw