How a viral open-source tool went from “game-changer” to “security dumpster fire” – and what every SME needs to know before it’s too late.
If you’ve been anywhere near LinkedIn in the past six months, you’ll have seen the posts. The ones with the rocket emojis and the breathless claims that OpenClaw – the open-source AI agent platform formerly known as Clawdbot (and MoltBot breifly) – can “replace half your team” or “automate your entire workflow in an afternoon.” Some of these posts were written by people who genuinely believe it. Some were written by OpenClaw itself, which tells you everything you need to know about where we are in early 2026.
I’ll be honest. I was impressed by it too. The idea of spinning up a small army of AI agents that can handle research, draft emails, manage spreadsheets and even write code is intoxicating for any business owner who’s ever stared at a to-do list that could wallpaper the office. For SMEs in particular – the ones running lean, wearing six hats before lunch – this kind of tool feels like finally getting that extra pair of hands you’ve been crying out for.
But here’s the thing. That extra pair of hands might be rifling through your filing cabinet while you’re not looking.
Wes Roth Lit the Fuse
Credit where it’s absolutely due. YouTuber and tech commentator Wes Roth has been following the OpenClaw journey from the very beginning, championing its potential while keeping a critical eye on the cracks forming beneath the surface. His latest video, bluntly titled “not good for OPENCLAW,” is the one that should have every business owner reaching for the pause button on their AI ambitions. It’s not doom-mongering. It’s not clickbait. It’s a well-sourced, genuinely alarming breakdown of how a promising tool has become what Roth himself calls a “security dumpster fire.”

If you’ve deployed OpenClaw in your business – or you’re thinking about it – his video is required viewing. Consider this article the companion guide for those of us who would rather read than watch, and who need the practical takeaways distilled for a business context.
What’s Actually Going Wrong?
Let’s get into the specifics, because vague warnings about “security risks” are not helpful (but they do get clicks!). There are three distinct threats that Roth and several security researchers have identified, and they are not theoretical. They are happening right now.
Your API Keys Are Being Stolen While You Sleep
Infostealer malware – the kind that quietly rummages through your system looking for valuable credentials – has evolved. It now specifically targets the .env files and gateway tokens that sit inside OpenClaw directories. These are the files that contain your API keys for services like Anthropic and OpenAI. If an attacker gets hold of them, they can burn through your API credits at an eye-watering pace. We’re talking hundreds, potentially thousands of pounds in charges before you even notice something is off.
For an SME that set up an OpenAI account with a company credit card and a generous usage limit “just in case,” this is the digital equivalent of leaving the office door unlocked with a sign that says “help yourself.”
One Dodgy Link Can Hand Over the Keys
Security researcher Mav Levin, working under the DepthFirst banner, uncovered a vulnerability now tracked as CVE-2026-25253. The short version: if someone sends you a malicious link and you click it while your OpenClaw instance is running, an attacker can hijack your entire setup via WebSocket. That’s not “they can see your screen.” That’s “they can operate your AI agents as if they were sitting at your desk.” Your agents, with all the permissions you gave them, now working for someone else.
Think about what your OpenClaw instance has access to. Your email? Your CRM? Your cloud storage? That’s the attack surface we’re talking about.
40,000 Unlocked Front Doors
Research from JFrog and Censys has revealed that over 40,000 OpenClaw instances are currently sitting on the public internet without so much as a basic firewall. Forty thousand. That’s not a rounding error. That’s a small city’s worth of businesses and individuals who have essentially put their AI-powered operations on display for anyone with a browser and bad intentions.
If you followed a YouTube tutorial that said “just forward port 3000 on your router,” you may well be one of them. There’s no shame in it – the setup guides rarely mention security because it’s not as exciting as showing off what the tool can do. But ignorance, as they say, is only bliss until someone exploits it.
Cisco Didn’t Just Warn – They Stepped In
Here’s where things get interesting, and where there’s actually a sliver of good news for businesses who want to use AI agents without playing Russian roulette with their data.
Cisco, not typically a company you associate with scrappy open-source projects, has moved from issuing warnings to actively building tools that protect the OpenClaw ecosystem. Their AI Skill Scanner is the standout. It uses what’s called “LLM-as-a-judge” technology to scan skills downloaded from ClawHub – the marketplace where users share pre-built agent capabilities – for hidden malicious commands. Think of it as a bouncer checking bags at the door before letting anyone into the club. Wes Roth flagged this as the “must-have” tool for anyone running OpenClaw, and he’s not wrong.
Beyond that, Cisco’s AI Defense integration, built into their IOS XE 26 infrastructure, is designed to block prompt injection attacks at the hardware level. These are attacks where someone crafts a message that tricks your AI agent into doing something destructive – like deleting system files or exfiltrating data. If your business runs on Cisco networking gear, this is worth a conversation with your IT provider.
The “Shadow AI” Problem Hits the Office
Perhaps most relevant for SMEs is what Cisco and Gartner are now calling the “Shadow AI” problem. Employees, often with the best of intentions, are installing OpenClaw on their work laptops to speed up their own tasks. No IT approval. No security review. No oversight whatsoever. Each of these rogue installations is a potential data-leak channel that your business doesn’t know exists and can’t monitor.
If you’ve ever had a staff member install a dodgy browser extension that caused problems, multiply that by a factor of about a thousand. That’s the scale of risk we’re talking about when an unaudited AI agent has access to company email, documents and cloud services.
When the AI Starts Rewriting Itself
This is the part that genuinely concerns me, and it’s the section of Roth’s video that shifts the tone from “here are some security problems” to “we might be losing control of the tools we built.”
OpenClaw agents are now capable of self-modifying logic. When they hit an error, rather than stopping and reporting the problem, they can rewrite their own code to work around it. On the surface, that sounds brilliant. An AI that fixes its own bugs? Lovely. Except that it also means the security guardrails you put in place can be quietly bypassed by the very agent they were designed to constrain. Traditional security thinking assumes the software you’re protecting will stay the same between audits. That assumption is now broken.
There’s also the model-swapping trend that Roth highlighted. Users are increasingly switching from Claude to the Kimi K2.5 model for its so-called “Agent EQ” – its ability to handle nuanced tasks with fewer errors. The security implications of routing your business data through different AI models, each with its own data handling practices and geographic considerations, is something most SMEs haven’t thought about for a moment. But they should.

And then there’s the Moltbook situation. Research by Gal Nagli at Wiz uncovered that approximately 1.5 million bots were communicating on the Moltbook social network, a platform designed for OpenClaw agents to share information with each other. Many of these bots were found to be spreading prompt injections – essentially poisoning the well that other agents drink from. If your agent pulls information from Moltbook, it could be receiving instructions from a malicious source without any human ever being involved.
What the Experts Are Saying
It’s worth noting that this isn’t a fringe concern being pushed by a handful of worried YouTubers. The security community has mobilised around this issue with some serious names involved.
Simon Willison, one of the most respected voices in AI safety, has coined what he calls the “Lethal Trifecta” of AI agent risk: access to data, exposure to untrusted content, and the authority to act. If your OpenClaw instance ticks all three boxes – and most do – you are sitting in the danger zone.
CrowdStrike has updated their Falcon Exposure Management platform to specifically detect rogue OpenClaw instances on corporate networks. When one of the biggest names in cybersecurity builds a tool specifically to find your software running where it shouldn’t be, that’s a message worth heeding.
Peter Steinberger, OpenClaw’s original creator now working at OpenAI, has been vocal about the need for the community to take security seriously. The open-source foundation is solid, he argues, but the way people are deploying it is anything but.
The Hardening Checklist: What to Do Right Now
If you’re running OpenClaw – or if you suspect someone in your organisation might be – here’s the practical action list, distilled from Roth’s recommendations and the broader security community’s guidance.
Get off the public internet immediately. If your instance is accessible via a public IP address, stop reading this and go fix that first. Services like Tailscale can create a private network overlay that keeps your instance accessible to authorised users without exposing it to the world.
Containerise everything. Run your OpenClaw instance inside a read-only Docker container. This limits the damage any compromised agent can do, because it can’t write to the host system. Think of it as putting your AI in a padded room rather than letting it wander freely around the building.
Audit every skill before you install it. Use Cisco’s AI Skill Scanner on every single skill you download from ClawHub. Yes, every one. The five minutes it takes could save you from a breach that takes five months to recover from.
Set hard API spending limits. Log into your OpenAI and Anthropic accounts and set strict usage tiers. “Agent loops” – where an AI gets stuck in a cycle and keeps making API calls – can rack up charges that would make your accountant weep. A hard limit of, say, £50/$50 per day is a sensible starting point. You can always increase it later.
Talk to your team. Have an honest conversation about AI tools in the workplace. Make it clear that installing unapproved software – no matter how impressive the demo video on LinkedIn looked – is a security risk. Give people a proper channel to request tools they want to use, rather than forcing them underground.
The Bigger Picture for SMEs
Here’s what I keep coming back to. The businesses most attracted to tools like OpenClaw are often the ones least equipped to manage the security implications. When you’re a ten-person company and the founder is also the IT department, the marketing team and the person who fixes the printer, the idea of running a comprehensive security audit on your AI deployment is laughable. You barely have time to run the business, let alone stress-test the tools that are supposed to be making it easier.
But that’s exactly why this matters. Large enterprises have security operations centres, dedicated teams and seven-figure cybersecurity budgets. They’ll be fine. SMEs don’t have that luxury, and the consequences of a breach – financial, reputational, regulatory – can be existential for a small business.
The promise of AI agents is real. The productivity gains are real. But so are the risks, and pretending otherwise because the technology is exciting is how businesses get hurt.
A genuine thanks to Wes Roth for being early and loud on these specific exploits. His willingness to call out problems in technology he clearly admires is exactly the kind of transparency the open-source community needs. Watch his full video – it’s worth your time, even if the news isn’t cheerful.
For the rest of us, the question isn’t whether to use AI agents. That ship has sailed. The question is whether you’re going to use them with your eyes open, your defences up and your API spending limits firmly in place – or whether you’re going to find out the hard way that the “AI army” you deployed to save your business was the thing that compromised it.
I know which one I’d choose.
This is an op-ed written by Mark Byrne, Director, Business Awards UK.