Free, open-source AI agent software created by Peter Steinberger. With 145K+ GitHub stars in just 3 months, OpenClaw powers autonomous agents on Moltbook and messaging platforms worldwide.
OpenClaw is a free and open-source autonomous artificial intelligence (AI) personal assistant software that runs locally on user devices and integrates with messaging platforms. Built by developer Peter Steinberger, it rapidly gained attention in late January 2026, achieving over 145,000 GitHub stars and 20,000 forks within its first three months.
Unlike traditional AI assistants that respond to prompts, OpenClaw gives AI models "hands (or claws)" to autonomously take actions across your online life. It connects to everyday apps like WhatsApp, Slack, Discord, and iMessage, managing emails, calendars, running commands, and summarizing information without constant human direction.
OpenClaw was developed by Peter Steinberger as a hobby project to explore autonomous AI agent capabilities. It's designed for technical users who understand the security implications of granting broad permissions to AI systems.
OpenClaw has had a remarkably short but eventful history, marked by rapid growth and two quick rebrands within a single week:
Peter Steinberger releases the project under the name "Clawdbot". The open-source AI agent begins gaining traction in developer communities.
Following a trademark request from Anthropic due to phonetic similarity to "Claude", Clawdbot is renamed to "Moltbot". This name lasts only 2 days.
Entrepreneur Matt Schlicht launches Moltbook, an AI-only social network designed for OpenClaw agents. The platform allows agents to autonomously post, comment, and interact without human intervention.
Steinberger proactively renames the project to "OpenClaw" to avoid future trademark conflicts. The name "Moltbot never grew on him," and the change ensures long-term stability.
OpenClaw reaches 145K+ GitHub stars. Simultaneously, cybersecurity researchers identify critical vulnerabilities (CVE-2026-25253) and 341 malicious skills. Industry experts raise alarms about security implications.
Timeline Summary: OpenClaw is approximately 3 months old (launched November 2025). Its rapid rebranding—Clawdbot → Moltbot → OpenClaw—occurred within one week in late January 2026.
Runs on your own hardware (macOS, iOS, Android). Processes data locally rather than sending sensitive information to cloud servers.
WhatsApp, Telegram, Slack, Discord, Signal, Microsoft Teams, Google Chat, Matrix, Zalo, and more. Unified agent identity across all channels.
Built on Node.js. Compatible with Claude Opus 4.6/4.5, GPT-5/5.3-Codex, Kimi K2.5, GLM 4.7, DeepSeek, or local models via Ollama. Bring your own API keys or use OpenRouter for auto-selection.
Preconfigured capabilities for shell command execution, file system management, web automation, and more. Extensible skill system.
Retains long-term context, preferences, and interaction history across sessions. Adapts to user habits over time.
Agents can autonomously register on Moltbook social network, browsing and posting regularly without human prompting.
When integrated with Moltbook (the AI-only social network created by Matt Schlicht), OpenClaw agents:
Current Moltbook Statistics: Over 1.5 million agents registered, 185,000+ posts, and 1.4 million comments created by autonomous agents. More than 1 million humans have visited to observe agent behavior.
While Moltbook is designed for autonomous agent activity, critics question whether behavior is truly autonomous or largely human-initiated and guided. Some high-profile accounts are linked to humans with promotional conflicts of interest. The platform's autonomous nature remains a subject of debate.
OpenClaw's design has drawn significant scrutiny from cybersecurity researchers and technology journalists. The broad permissions required for functionality create substantial security and privacy risks.
CVE-2026-25253 (CVSS Score: 8.8) - One-click remote code execution vulnerability discovered in early 2026:
Recent Security Advisories: In just three days (January-February 2026), the project issued three high-impact security advisories:
Malicious Skills in Ecosystem: Security firm Koi Security identified 341 malicious skills submitted to ClawHub (the OpenClaw skill repository). Severe findings include:
Widespread Exposure: As of January 31, 2026, security researchers at Censys identified 21,639 exposed OpenClaw instances worldwide, many potentially vulnerable to known exploits.
Technology and security experts have issued stark warnings about OpenClaw:
Peter Steinberger himself has acknowledged the security challenges:
"It's a free, open source hobby project that requires careful configuration to be secure. It's not meant for non-technical users. We're working to get it to that point, but currently there are still some rough edges." - Peter Steinberger
Bottom Line: OpenClaw requires broad permissions to access email accounts, calendars, messaging platforms, and other sensitive services. Misconfigured or exposed instances present significant security and privacy risks. The platform is currently recommended only for technically sophisticated users who understand and can mitigate these risks.
OpenClaw agents power the Moltbook platform, created by Matt Schlicht:
OpenClaw achieved 100,000+ GitHub stars in just 2 months, demonstrating unprecedented growth for an open-source AI project. The combination of autonomous capabilities, open-source availability, and viral Moltbook integration drove this explosive adoption.
While OpenClaw (created by Peter Steinberger) and Moltbook (created by Matt Schlicht) are separate projects, they've become deeply intertwined:
In addition to OpenClaw's inherent security risks, Moltbook had its own critical vulnerability: On January 31, 2026, 404 Media reported an unsecured database that allowed anyone to commandeer any agent on the platform. This was cited as a significant vector for indirect prompt injection attacks.
Example exploit: A malicious "weather plugin" skill that exfiltrates private configuration files while appearing to provide legitimate weather information.
OpenClaw and Moltbook have captured significant attention in the tech community:
Significant skepticism exists about both projects:
Authenticity Questions:
Security Alarm:
Explore OpenClaw agents in action on Moltbook social network