id: PIR-2026-0042title: Thousands of self-hosted OpenClaw agent gateways deployed on public IPs leak API keys, tokens, and chat histories; a one-click RCE (CVE-2026-25253) compounded even localhost-bound installsdate_occurred: 2026-01-25 onward (viral adoption wave; exposed population grew ~1,000 to 21,639 in one week)date_detected: 2026-01-25/31 (Censys internet-wide scan window); independent follow-up scans through Feb-Mar 2026date_disclosed: 2026-01/02 (Censys publication; CVE-2026-25253 patched in v2026.1.29)status: corroborated (two independent internet-wide scanning efforts + vendor patch + broad security-industry coverage)agent_description: Self-hosted OpenClaw (formerly Clawdbot/Moltbot) personal-agent gateways run by individuals and companies - always-on assistants holding Anthropic API keys, Telegram/Slack/OAuth tokens, and full conversation histories, with shell and messaging access on the host.operator_type: individual (mostly), with startup/enterprise deployments mixed inautonomy_level: autonomous-within-policy (always-on agents with shell + external comms)model_stack: predominantly Claude via user API keys; varies per instanceharness: OpenClaw gateway + Control UI, self-hostedauthority_scope: credentials (LLM API keys, messaging OAuth tokens, plaintext creds in Markdown/JSON files), code execution (shell on host), external comms (messaging channels), data access (full chat histories)funds_at_risk_usd: unknown (per-instance API spend + whatever the host and tokens reach; never aggregated)blast_radius: fleet/systemic (v0.1 tier - one insecure deployment pattern replicated across 21K+ independent installs of the same product; correlated exposure, not one org)root_cause: operator-error (primary; instances deployed on public IPs with default/insecure configs against explicit docs guidance); contributing harness flaw CVE-2026-25253failure_locus: operator-config (primary); harness (contributing - the Control UI's trust of URL parameters)exploitation_status: in-wild-malfunction (the mass credential/data exposure was a real production event with no documented adversarial harvesting - "exposure" reclassified to the v0.2 token; mass plundering undocumented; the CVE-2026-25253 RCE component was researcher-demonstrated, patched before confirmed in-wild exploitation)mechanism: During the viral adoption wave, users put instances straight onto public IPs despite documentation recommending SSH tunnels. Censys (querying "Moltbot Control"/"clawdbot Control" landing pages) found 21,639 publicly accessible instances by 2026-01-31, up from ~1,000 a week earlier; a later independent study counted 42,665 exposed, ~5,194 verified vulnerable, with most of those exhibiting auth-bypass conditions. Open instances leaked API keys, OAuth tokens, plaintext credentials, and chat histories. Separately, CVE-2026-25253 (CVSS 8.8) chained the Control UI's unvalidated URL parameters with cross-site WebSocket hijacking into a one-click RCE that worked even against localhost-bound instances until v2026.1.29.adversary_present: unknown (exposure certain; who harvested it is undocumented; individual compromises reported anecdotally)severity: degraded (mass credential/data exposure across the fleet; no quantified realized theft attributed)direct_loss_usd: unknown (no aggregate figure; anecdotal individual compromises)indirect_loss_usd: unknown (fleet-wide re-keying, hardening, incident response)downtime: n/a (per-operator)data_exposure: API keys, OAuth tokens, plaintext credentials, full agent conversation histories, on exposed instancescontrols_that_worked: vendor patch velocity (CVE fixed in v2026.1.29); the docs' SSH-tunnel guidance worked for operators who followed it - the failure population is those who did notdetected_by: third-party (Censys scan; independent researchers; security vendors)time_to_detect: days (exposure wave to first published scan ~1 week)time_to_recover: rolling (patching + config hardening per operator; exposed-instance counts kept growing in later scans, so recovery is partial at best)remediation: CVE patch v2026.1.29; public warnings; hardening guides; third-party audit tooling (e.g. SecureClaw) emergedstructural_fix: partial - later builds tightened defaults, but the root pattern (consumer-grade self-hosting of credential-rich always-on agents) persiststelemetry_grade: population-level witnessed (two independent internet-wide scans agree on scale); none for individual compromises (no victim telemetry public)sources:Independence: good - scan data, vendor patch, and multi-firm coverage are mutually independent.
- confidence: high on exposure scale, CVE details, and timeline (21,639 figure verified against Censys-derived reporting); low on realized harm - how many exposed instances were actually plundered is undocumented (the weakest link)