# PIR-2026-0042 - Mass exposure of misconfigured OpenClaw instances leaking agent credentials (+ CVE-2026-25253 one-click RCE)

- `id`: PIR-2026-0042
- `title`: Thousands of self-hosted OpenClaw agent gateways deployed on public IPs leak API keys, tokens, and chat histories; a one-click RCE (CVE-2026-25253) compounded even localhost-bound installs
- `date_occurred`: 2026-01-25 onward (viral adoption wave; exposed population grew ~1,000 to 21,639 in one week)
- `date_detected`: 2026-01-25/31 (Censys internet-wide scan window); independent follow-up scans through Feb-Mar 2026
- `date_disclosed`: 2026-01/02 (Censys publication; CVE-2026-25253 patched in v2026.1.29)
- `status`: corroborated (two independent internet-wide scanning efforts + vendor patch + broad security-industry coverage)

### The agent
- `agent_description`: Self-hosted OpenClaw (formerly Clawdbot/Moltbot) personal-agent gateways run by individuals and companies - always-on assistants holding Anthropic API keys, Telegram/Slack/OAuth tokens, and full conversation histories, with shell and messaging access on the host.
- `operator_type`: individual (mostly), with startup/enterprise deployments mixed in
- `autonomy_level`: autonomous-within-policy (always-on agents with shell + external comms)
- `model_stack`: predominantly Claude via user API keys; varies per instance
- `harness`: OpenClaw gateway + Control UI, self-hosted

### Authority
- `authority_scope`: credentials (LLM API keys, messaging OAuth tokens, plaintext creds in Markdown/JSON files), code execution (shell on host), external comms (messaging channels), data access (full chat histories)
- `funds_at_risk_usd`: unknown (per-instance API spend + whatever the host and tokens reach; never aggregated)
- `blast_radius`: fleet/systemic (v0.1 tier - one insecure deployment pattern replicated across 21K+ independent installs of the same product; correlated exposure, not one org)

### The failure
- `root_cause`: operator-error (primary; instances deployed on public IPs with default/insecure configs against explicit docs guidance); contributing harness flaw CVE-2026-25253
- `failure_locus`: operator-config (primary); harness (contributing - the Control UI's trust of URL parameters)
- `exploitation_status`: in-wild-malfunction (the mass credential/data exposure was a real production event with no documented adversarial harvesting - "exposure" reclassified to the v0.2 token; mass plundering undocumented; the CVE-2026-25253 RCE component was researcher-demonstrated, patched before confirmed in-wild exploitation)
- `mechanism`: During the viral adoption wave, users put instances straight onto public IPs despite documentation recommending SSH tunnels. Censys (querying "Moltbot Control"/"clawdbot Control" landing pages) found 21,639 publicly accessible instances by 2026-01-31, up from ~1,000 a week earlier; a later independent study counted 42,665 exposed, ~5,194 verified vulnerable, with most of those exhibiting auth-bypass conditions. Open instances leaked API keys, OAuth tokens, plaintext credentials, and chat histories. Separately, CVE-2026-25253 (CVSS 8.8) chained the Control UI's unvalidated URL parameters with cross-site WebSocket hijacking into a one-click RCE that worked even against localhost-bound instances until v2026.1.29.
- `adversary_present`: unknown (exposure certain; who harvested it is undocumented; individual compromises reported anecdotally)

### Impact
- `severity`: degraded (mass credential/data exposure across the fleet; no quantified realized theft attributed)
- `direct_loss_usd`: unknown (no aggregate figure; anecdotal individual compromises)
- `indirect_loss_usd`: unknown (fleet-wide re-keying, hardening, incident response)
- `downtime`: n/a (per-operator)
- `data_exposure`: API keys, OAuth tokens, plaintext credentials, full agent conversation histories, on exposed instances
- `controls_that_worked`: vendor patch velocity (CVE fixed in v2026.1.29); the docs' SSH-tunnel guidance worked for operators who followed it - the failure population is those who did not

### Detection and recovery
- `detected_by`: third-party (Censys scan; independent researchers; security vendors)
- `time_to_detect`: days (exposure wave to first published scan ~1 week)
- `time_to_recover`: rolling (patching + config hardening per operator; exposed-instance counts kept growing in later scans, so recovery is partial at best)
- `remediation`: CVE patch v2026.1.29; public warnings; hardening guides; third-party audit tooling (e.g. SecureClaw) emerged
- `structural_fix`: partial - later builds tightened defaults, but the root pattern (consumer-grade self-hosting of credential-rich always-on agents) persists

### Evidence
- `telemetry_grade`: population-level witnessed (two independent internet-wide scans agree on scale); none for individual compromises (no victim telemetry public)
- `sources`:
  - https://censys.com/blog/openclaw-in-the-wild-mapping-the-public-exposure-of-a-viral-ai-assistant/ (primary scan)
  - https://www.securityweek.com/openclaw-security-issues-continue-as-secureclaw-open-source-tool-debuts/
  - https://adversa.ai/blog/openclaw-security-101-vulnerabilities-hardening-2026/ (aggregates CVE + 42,665-instance follow-up study)
  - https://www.reco.ai/blog/openclaw-the-ai-agent-security-crisis-unfolding-right-now
  - `independence`: good - scan data, vendor patch, and multi-firm coverage are mutually independent.
- `confidence`: high on exposure scale, CVE details, and timeline (21,639 figure verified against Censys-derived reporting); low on realized harm - how many exposed instances were actually plundered is undocumented (the weakest link)
