What is OpenClaw, the AI ​​agent that has unleashed panic among users and experts?

Foto del autor

By Jack Ferson

In recent years you have probably gotten used to talking about artificial intelligence almost as if it were another person. You ask him to write texts, to summarize documents for you, to help you with some work or studies and a long etcetera. All of this already seems normal to us.

But while many continue to use AI as a tool to use from time to time, projects that go much further are emerging behind it. They are no longer satisfied with answering questions. They want to act, decide and move around the Internet as if they were real users. And that’s where things start to get a little complicated.

OpenClaw is one of those projects that marks a before and after. Not because it is the most famous of all, but because it embodies very well the change that is being experienced: going from an AI that helps, to an AI that acts on its own..

However, there is a problem with this agent. This free chatbot that works locally, although this has its nuances, since it interacts with the outside, does what other AI agents do not dare, at the cost of taking full control of your PC. That is why you should know it thoroughly.

  • What is OpenClaw?
  • ​From Clawdbot to OpenClaw, via Moltbot: what really happened
  • How OpenClaw works inside and where its virality comes from
  • OpenClaw could be leaking your most sensitive data

What is OpenClaw?

Previously mentioned, OpenClaw is an artificial intelligence agent created to function with almost total autonomy. Simply put, you don’t need a person to tell you step by step what to do. You set a goal and the AI ​​is in charge of deciding how to get there.

This radically differentiates it from a ChatGPT-style chatbot. OpenClaw breaks that question and answer scheme. It can initiate actions, test solutions, correct itself and continue working even when the user is not in front of the PC.

In practice, he behaves more like a worker than an assistant. You can research information, browse websites, analyze data, generate content and link tasks to others until completing a complex assignment.

It is free and open source and was developed by Peter Steinberger, who already has more than 44,000 stars on GitHub.

Installs on a computer with macOS, Windows or Linux (works even on a Raspberry Pi 5), but It is controlled through the mobile phone with a messaging app such as WhatsApp, TelegramDiscord, Spotify, Signal, Gmail, almost any app with which you can exchange messages.

Works with any AIby default with Claude Anthropic in local mode with Ollama, but you can use whatever you want, including GPT. Of course, keep in mind that some of these AI are paid. But there are many local AIs that are not.

Of course, to use OpenClaw you have to give permission for it to access your entire PC, including reading and writing files, as well as WhatsApp, Telegram, Google, or whatever accounts you want to use.

From here, there are no limits. From WhatsApp or Telegram you can ask OpenClaw to filter your email or move files from one place to another under certain conditions, to download things, or to notify you of viral topics on a certain social network. The possibilities are endlessand people find new apps every day.

​From Clawdbot to OpenClaw, via Moltbot: what really happened

Surely in some documents you still see the name Clawdbot or even Moltbot on some websites. The truth is that this was his original name. Under that name it began to circulate on social networks, forums and developer communities.

In these videos, an AI was seen capable of organizing tasks, talking to itself, making decisions and executing actions without direct human intervention. The reaction was one of absolute fascination, on the one hand, and concern on the other.

The fact that it has access to your entire PC gave rise to a large number of questions about its operation, control, data it handles, etc. That’s why they decided to give it a facelift, a new name: Moltbot.

The change sought to relaunch the tool with an image that produced more peace of mind, but it has not completely cleared up doubts. For many experts, the problem is not the name, but the approach.

But this is not all and recently there was a new change, which we hope is definitive and which gives its name to this report.

The name OpenClaw mixes two ideas: on the one hand, Openwhich refers to its nature of open sourceand on the other Clawwhich maintains a nod to the original mascot and the collaborative spirit of the project.

Under the name OpenClaw, the tool remains the same autonomous AI assistantcapable of executing tasks, integrating with messaging applications such as WhatsApp or Telegram, accessing files and automating workflows, but with an identity that seems different and aligned with other concepts.

How OpenClaw works inside and where its virality comes from

To understand OpenClaw you have to imagine it as a system made up of several layers that work together. On the one hand, it has an advanced language model, capable of understanding human instructions and generating text. That is the most visible part.

But underneath is something more important: a planning system. This system allows AI to break down a large task into smaller steps, decide what to do first, see results, and continue..

You can open web pages, read information, process it and use it as a basis for the next action. All this happens without the user having to be aware of every movement. That is, he not only thinks, but also acts.

The problem with all of this is how you are actually managing the data. To function, it needs access to information. Browse, read, analyze and process data from multiple sources. That, in itself, is not strange in an AI.

The problem is that It is not always clear what information is collected, how it is stored and for how long.

Cybersecurity experts have made it quite clear that an autonomous agent like OpenClaw can become a perfect way to leak sensitive information, even without malicious intent. All it takes is that it has access to data that it shouldn’t or that is communicated without proper encryption.

In short, It is very powerfulat the cost of taking full control of your PC, the browser and your accounts, with what that entails. It is not a malwaresince it is open source and has been reviewed, but and one hacker finds a vulnerability and sneaks in, he will have access to your entire PC and your accounts.

In fact, It has already been possible to inject prompts to control the AI ​​from outside. For example, sending a simple innocent email, but which hides hidden orders for OpenClaw to stop everything it is doing and read or copy certain files. It has already been corrected, but it can happen again.

OpenClaw could be leaking your most sensitive data

As expected, problems have not been long in coming. OpenClaw is facing a huge problem with a historic data leak.

The administration interfaces of thousands of companies have been exposed. OpenClaw has revealed confidential worker data, client credentials and command execution. The consequences depend on the permissions you have given the chatbot and the access level it has on the host.

The chatbot’s security systems have completely failed and Clawdbot Control has been exposed. The system has incorrect proxy configuration that leaves a door open to cybercriminals.

OpenClaw Prioritizes local actions, connections through reverse proxies often treat all Internet traffic as trusted. The chatbot ends up accepting unauthenticated access en masse.

«Someone had created their own Signal account (encrypted) on their public Clawdbot control server, with full read access. That is a device that links the URI (also QR codes). Tapping it on a mobile with Signal installed will link it to the account with full access,» explains Jamieson O’Reilly, a security researcher, in a post on LinkedIn.

OpenClaw is vulnerable to chain attacks which are executed with a simple set of packaged instructions. O’Reilly has discovered that 16 developers from seven countries could access the chatbot without verification in the first eight hours.

With all this, make it clear that OpenClaw is not, by definition, a virus or malicious software. But it is a tool with enormous potential to be used in a not very responsible way. In the wrong hands, it can open the door to serious privacy issues, data leaks, or not-so-good uses.

Deja un comentario