Security Alert
2026 scans reported 135,000+ publicly reachable or misconfigured OpenClaw endpoints. Current releases default to loopback and require auth for non-loopback access, but old versions, proxy mistakes, and third-party skills still need care.
Publicly reachable or misconfigured endpoints reported in 2026 scans
Malicious skills placed on ClawHub in the ClawHavoc campaign (Feb 2026)
ClawHub versions pinned, with checksums used where supported
These aren't theoretical. All three have been exploited in the wild.
Current OpenClaw defaults to loopback and requires valid authentication for non-loopback access. Public reverse proxies, port forwarding, stale releases, or weakened auth can still expose a Gateway. 2026 scans reported more than 135,000 publicly reachable or misconfigured instances.
Treat any public Gateway as an authenticated service. Verify bind mode, proxy rules, token handling, and release version before exposing it.
In February 2026, the ClawHavoc campaign placed 341 malicious skills on ClawHub — the community skill registry. These skills executed arbitrary code on installation. Self-hosted users running `clawhub install` without version pinning were silently compromised.
The attack exploited the fact that `clawhub install @latest` trusts whatever the registry serves. Hardcoded @latest references are the attack surface.
OpenClaw ships frequent updates, often with breaking config changes. Many self-hosters fall behind — running versions months out of date, missing security patches. Staying current requires reading changelogs, testing compatibility, and manually updating on your schedule.
Version fragmentation also makes community support harder. The most common self-hosting issues are already fixed in the current release.
Every protection below is active on every instance, by default.
Every MyOpenClaw instance is protected by a unique HMAC-SHA256 gateway token. No token, no access — your AI is not reachable from the public internet without it.
ClawHub skills use exact version pins instead of @latest. Supported Docker, plugin, and Python artifacts use checksum verification, and release images are tested before rollout.
We track OpenClaw releases and test security patches. Dashboard update controls apply tested releases without SSH.
Setup passwords, gateway tokens, and API keys are encrypted with AES-256-GCM before storage. Key rotation is supported without re-encrypting existing records.
Integration sources and versions are reviewed before bundling. Exact pins and prebuilt image tests reduce dependency drift at startup.
Each instance gets its own Fly Machine and persistent volume instead of sharing one application process or conversation store.
If you run self-hosted OpenClaw, verify these three things now:
Skip the configuration gauntlet. MyOpenClaw deploys OpenClaw with authentication enabled, supply chain controls active, and tested dashboard updates before you've finished your coffee.
Start Secure HostingStarts at $29/mo. Cancel anytime. No contracts.