MyOpenClaw

Security Alert

Is Self-Hosted OpenClaw Safe?

2026 scans reported 135,000+ publicly reachable or misconfigured OpenClaw endpoints. Current releases default to loopback and require auth for non-loopback access, but old versions, proxy mistakes, and third-party skills still need care.

135,000+

Publicly reachable or misconfigured endpoints reported in 2026 scans

341

Malicious skills placed on ClawHub in the ClawHavoc campaign (Feb 2026)

Exact

ClawHub versions pinned, with checksums used where supported

The 3 security risks of self-hosting OpenClaw

These aren't theoretical. All three have been exploited in the wild.

01

Public gateway misconfiguration

Critical

Current OpenClaw defaults to loopback and requires valid authentication for non-loopback access. Public reverse proxies, port forwarding, stale releases, or weakened auth can still expose a Gateway. 2026 scans reported more than 135,000 publicly reachable or misconfigured instances.

Treat any public Gateway as an authenticated service. Verify bind mode, proxy rules, token handling, and release version before exposing it.

02

Supply chain attacks (ClawHavoc)

High

In February 2026, the ClawHavoc campaign placed 341 malicious skills on ClawHub — the community skill registry. These skills executed arbitrary code on installation. Self-hosted users running `clawhub install` without version pinning were silently compromised.

The attack exploited the fact that `clawhub install @latest` trusts whatever the registry serves. Hardcoded @latest references are the attack surface.

03

Unpatched instances

Medium

OpenClaw ships frequent updates, often with breaking config changes. Many self-hosters fall behind — running versions months out of date, missing security patches. Staying current requires reading changelogs, testing compatibility, and manually updating on your schedule.

Version fragmentation also makes community support harder. The most common self-hosting issues are already fixed in the current release.

How MyOpenClaw handles security

Every protection below is active on every instance, by default.

Gateway token authentication

Every MyOpenClaw instance is protected by a unique HMAC-SHA256 gateway token. No token, no access — your AI is not reachable from the public internet without it.

Pinned and tested release artifacts

ClawHub skills use exact version pins instead of @latest. Supported Docker, plugin, and Python artifacts use checksum verification, and release images are tested before rollout.

Tested security updates

We track OpenClaw releases and test security patches. Dashboard update controls apply tested releases without SSH.

Encrypted secrets at rest

Setup passwords, gateway tokens, and API keys are encrypted with AES-256-GCM before storage. Key rotation is supported without re-encrypting existing records.

Supply chain audit

Integration sources and versions are reviewed before bundling. Exact pins and prebuilt image tests reduce dependency drift at startup.

Isolated Fly Machines

Each instance gets its own Fly Machine and persistent volume instead of sharing one application process or conversation store.

Still self-hosting? Check this immediately.

If you run self-hosted OpenClaw, verify these three things now:

  1. 1Check openclaw.json: confirm auth.enabled is true and you have a strong gateway token set
  2. 2Verify your bind address: it should be 127.0.0.1, not 0.0.0.0 — unless you're behind a properly configured reverse proxy
  3. 3Audit your installed skills: remove any that aren't pinned to an exact version, especially anything installed with @latest

Managed OpenClaw hosting without server setup

Skip the configuration gauntlet. MyOpenClaw deploys OpenClaw with authentication enabled, supply chain controls active, and tested dashboard updates before you've finished your coffee.

Start Secure Hosting

Starts at $29/mo. Cancel anytime. No contracts.

FAQ

OpenClaw security questions

2026 internet scans reported more than 135,000 publicly reachable OpenClaw endpoints. That figure describes observed exposure and misconfiguration, not the current secure default. OpenClaw now defaults to loopback and rejects non-loopback access without valid authentication.
ClawHavoc was a February 2026 supply chain campaign that placed malicious skills on ClawHub, the community skill registry. Skills executed code at install time, making unpinned installation risky. MyOpenClaw reduces exposure with exact version pins, checksums where supported, and tested release images.
Not automatically. It depends on the managed provider. MyOpenClaw uses gateway token auth, isolated machines, version-pinned skills, tested release images, and encrypted secrets at rest. A poorly configured managed host could be worse than a well-configured self-hosted setup.
Technically, as the infrastructure provider, we have access to the underlying machine. In practice: your API keys are encrypted at rest and never logged, your conversation history and memory files live on your persistent volume, and our team does not routinely access customer data. We publish a security-focused CLAUDE.md detailing our supply chain hardening for full transparency.
Yes. Keep `gateway.bind` on loopback unless remote access is required, configure strong Gateway auth before any non-loopback bind, use an HTTPS reverse proxy, pin third-party skills, and apply tested OS and OpenClaw updates. MyOpenClaw manages these infrastructure controls for hosted instances.