The OpenClaw Waterloos

Documenting your OpenClaw agent's decision to burn the house down.

LIVE
00
Incidents Logged
$0
Dollars Burned
Filter:
Sort by:
+ Report Incident
Latest IncidentCASE #0045 | 2026-03-17
P0 CATASTROPHIC

๐Ÿ”“ 40,000 Servers Wide Open to the Internet

Over 40,000 self-hosted OpenClaw instances were found exposed to the internet, with 12,800 actively leaking API keys.

SecurityScorecard researchers discovered 40,214 exposed OpenClaw instances across 28,663 unique IP addresses. Of these, 12,800 were actively leaking API keys and credentials, allowing anyone on the internet to walk right in. 549 instances were already linked to prior breach activity. The default OpenClaw configuration binds to 0.0.0.0 without authentication, meaning every user who skipped the security docs left their entire digital life accessible to the world.

๐Ÿ”“ SECURITY LEAK๐Ÿ“ข PR NIGHTMARE
40,000 affected
Cost: $2,000,000
Read Full Report โ†’
Powered by Weavin ยท Manage AI agents safely