The corrected record on Clawdbot: what it became, what broke, and what to actually run in August 2026.
We published the original version of this guide on January 26, 2026. Clawdbot stopped being called Clawdbot the next day. On January 27 the project was renamed Moltbot under trademark pressure from Anthropic, and on January 30 it was renamed again to OpenClaw, the name it still carries today - Wikipedia. Within three more weeks its creator had joined OpenAI, the project had moved into a nonprofit foundation, and its skill registry had become the center of one of the biggest AI supply-chain security incidents ever recorded.
Most pages that rank for "Clawdbot" today are frozen January explainers describing a product that no longer exists under that name. This page used to be one of them. Instead of quietly patching a few names, we rewrote it as the thing readers searching "clawdbot" actually need in August 2026: a disambiguation and reality check. What Clawdbot was, what it became, which claims from the January hype cycle held up, which collapsed, and an honest answer to the question underneath every one of those searches: should you run this thing?
One more thing before we start: o-mega.ai builds an AI agent workforce platform. We are not a neutral observer here. We run fleets of autonomous agents in production for business users, which makes us both a competitor to some of what OpenClaw does and an operator with first-hand scars from exactly the problems OpenClaw's security crisis exposed. We will say plainly where OpenClaw is the better choice and where it is not, and you can weigh our perspective accordingly.
This guide covers the full rename timeline, the current architecture and model lineup (verified against live docs this week, not recalled from January), the OpenClaw vs Claude Cowork vs managed platform decision with real pricing, and the security crisis with CVE numbers and exposed-instance counts from the researchers who measured them.
Contents
- What Happened to Clawdbot: The Full Rename Timeline
- The Rise (and Reality Check) of Personal AI Agents
- What OpenClaw Is Today, Formerly Clawdbot, Briefly Moltbot
- Under the Hood: How OpenClaw Works in August 2026
- OpenClaw vs Claude Cowork vs Managed Platforms
- Key Features, Refreshed, with the Security Caveats That Belong Next to Them
- What Early Adopters Did, and What Held Up
- The Security Crisis: CVEs, 40,000+ Exposed Instances, and ClawHavoc
- Which One Should You Run in August 2026
- Future Outlook: Foundations, Clones, and the Agent Layer
1. What Happened to Clawdbot: The Full Rename Timeline
The single most confusing thing about this product is its name, so let us settle it first. The project that went viral as Clawdbot in late 2025 has had four names in its short life, and the one that stuck is OpenClaw. If you see "Clawdbot," "Moltbot," and "OpenClaw" used interchangeably in forum threads, they refer to the same codebase, the same creator, and mostly the same architecture. The renames were forced by a trademark dispute, not by any fork or change of direction - Forbes.
The project began life on November 24, 2025 under the name Warelay, built by Austrian developer Peter Steinberger, best known before this as the founder of PSPDFKit - Wikipedia. It was soon rebranded around its Claude-first identity as Clawd, then Clawdbot, which is the name under which it exploded across AI Twitter and Reddit in January 2026. Anthropic objected to the Claude-adjacent branding, and on January 27, 2026 the project became Moltbot. Steinberger then decided that if he had to rebrand anyway, he would pick a name he actually liked: on January 30, 2026 he announced OpenClaw with the line that "the lobster has molted into its final form" - Forbes.
| Date | Name / Event | What happened |
|---|---|---|
| Nov 24, 2025 | Warelay | Initial release by Peter Steinberger, soon rebranded Clawd, then Clawdbot |
| Jan 26, 2026 | Clawdbot | Peak of the Clawdbot hype cycle (and the day the original version of this guide shipped) |
| Jan 27, 2026 | Moltbot | Renamed under Anthropic trademark pressure |
| Jan 27-29, 2026 | ClawHavoc | 341 malicious skills discovered in the skill registry (see Section 8) |
| Jan 30, 2026 | OpenClaw | Final rename; same day, patch for the CVE-2026-25253 one-click RCE ships |
| Feb 14, 2026 | OpenClaw Foundation | Steinberger joins OpenAI; project moves to a nonprofit foundation |
| Mar 2, 2026 | 247,000 GitHub stars | Star count recorded at 247,000 with 47,700 forks |
| Jul 8, 2026 | Full-time foundation team | Foundation staffs up with dedicated maintainers |
| Jul 30, 2026 | Extended-stable channel | First LTS-style release, 2026.6.33, for enterprise users |
Sources for the table: the consolidated timeline on Wikipedia, the rename reporting in Forbes, the foundation and release details on openclaw.ai, and the security dates from Conscia's incident write-up, all opened and verified for this refresh.
To appreciate why the renames landed so hard, remember the velocity underneath them: the repository had accumulated 135,000+ GitHub stars within weeks of going viral, before the first rename even happened - Reco. Hundreds of thousands of people were watching, installing, and forking a project whose name, domain, and package identity then changed twice inside four days. Confusion at that scale is not an inconvenience; it is an attack surface.
And attackers used it. The renames had real security consequences. Malwarebytes documented typosquat domains and cloned repositories appearing almost immediately after each rename, seeded with legitimate code that later pulled malicious updates, and fraudsters launched counterfeit crypto tokens trading on the abandoned Clawdbot name - Forbes. Steinberger himself had his GitHub account temporarily hijacked during the chaos and faced harassment over the episode - Forbes. If you bookmarked an install script or a "Clawdbot" GitHub repo in January, do not trust it today. The only canonical home is openclaw.ai and the foundation's official repository.
The second structural change came on February 14, 2026, when Sam Altman announced on X that Steinberger was joining OpenAI to "drive the next generation of personal agents" - TechCrunch. The project itself did not become an OpenAI product: it moved into the OpenClaw Foundation, a nonprofit that OpenAI funds and contributes to, with Steinberger explaining that he wanted "to change the world, not build a large company" - TechCrunch. By July 8, 2026 the foundation had a full-time team of maintainers - openclaw.ai.
Why does this governance detail matter to you as a user? Because the January-era criticism of Clawdbot was that it was a one-man hobby project with root access to your digital life. That criticism is now outdated in one direction (there is a funded foundation, a security process, and an enterprise release channel) and sharpened in another (the creator now works for OpenAI, and the project's default model for fresh OpenAI-key setups is OpenAI's GPT-5.6 Sol - OpenClaw docs). The "fully independent hacker project" framing from January no longer describes reality. What you get instead is something more durable and less romantic: open-source infrastructure with institutional backing.
2. The Rise (and Reality Check) of Personal AI Agents
The thesis that made Clawdbot interesting in January is still the right lens, so we are keeping it: the shift that matters is from reactive AI to proactive AI. A chatbot answers when you ask. An agent monitors, remembers, schedules, and takes initiative inside your actual tools. Every product worth discussing on this page, from OpenClaw to Claude Cowork to our own platform, is a different answer to the same structural question: once a language model can operate software, who runs the loop, where does it run, and who is responsible when it acts?
What has changed since January is that this stopped being a niche experiment and became a measured, mainstream behavior. When Anthropic expanded Claude Cowork beyond the desktop in July, it published usage data from 1.2 million anonymized sessions across more than 600,000 organizations: business process operations accounted for 33.4% of Cowork sessions, content creation for 16.4%, and software development for just 8.7% - TechCrunch. Read that again: the dominant use of an agentic AI product is now ordinary business work, not coding. The agent moved out of the terminal and into the back office, which is precisely the trajectory we mapped in our guide to the autonomous agent workforce.
The competitive landscape also stopped looking like "one viral open-source project vs the incumbents." According to the consolidated reporting on Wikipedia, by May 2026 Google was building its own agent alternative known as Remy, Microsoft was internally testing an OpenClaw-based desktop environment called ClawPilot under Project Lobster, and Chinese companies including Tencent and Z.ai had announced OpenClaw-based services. OpenAI hired the creator. Anthropic took Cowork cross-device. Every major lab now treats the always-on personal agent as a product category to own, not a curiosity.
It is worth being precise about why proactivity, the defining feature of this category, changes the security equation rather than just the productivity one, because the point gets lost between the hype and the panic. A reactive chatbot processes only what you paste into it, so the human is a filter on every input. A proactive agent reads your inbox, fetches web pages, and consumes other agents' outputs without a human filter on any of it, and for a language model there is no hard boundary between the data it reads and the instructions it follows. That single structural fact generates most of Section 8: the malicious skills, the prompt-injection findings, the instruction channels hiding inside social platforms. It also explains why "just be careful what you ask it" was never a real mitigation. You are not the only one asking.
The reality check is the other half of the story, and it is the part the January hype cycle did not price in. The same properties that made Clawdbot magical (shell access, always-on connectivity, an open skill registry, memory of everything you tell it) made it the largest agent attack surface on the internet within weeks of going viral. Section 8 covers this in depth with the actual numbers, but the headline is that tens of thousands of instances ended up exposed to the public internet and the skill registry shipped hundreds of malicious packages. If the January question was "can an AI really do things for me?", the August question is "who is accountable when an AI with my credentials does things?" That question, not model quality, is now the real dividing line between the self-hosted and managed approaches this guide compares. For a deeper structural treatment of what agents are and why they change workflows, our foundational explainer on what AI agents actually are still holds up.
3. What OpenClaw Is Today, Formerly Clawdbot, Briefly Moltbot
Strip away the renames and the drama, and the product description is stable: OpenClaw is an open-source gateway that turns a large language model into a persistent personal agent you talk to through your existing messaging apps. Its official tagline is "The AI that really does things" - openclaw.ai. You message it on WhatsApp or Telegram like a contact; it reads your email, manages your calendar, runs code, browses the web, and messages you first when something needs your attention. It runs on hardware you control, stores its memory as plain files on your disk, and is free software with no license fee.
"Does things" is the load-bearing phrase, and it is worth unpacking because it defines who this product is for. A chatbot produces text about your problem; OpenClaw executes against it. Ask it to reorganize a folder and files move. Tell it to watch for an email and it messages you when the email lands. Ask for a summary of a webpage and it fetches the page itself rather than recalling training data about it. Every one of those verbs is a real action with real side effects performed by a process holding your credentials, which is simultaneously the entire appeal and the entire risk budget. The product's core bet, unchanged from the Clawdbot days, is that the appeal is worth the risk for people who understand what they are running, and the whole arc of 2026 has been the ecosystem learning to say the second half of that sentence out loud.
The scale of the integration surface has grown far beyond the January version of this guide, which reported "8 different communication platforms." The official site now lists 29 channels, including WhatsApp, Telegram, Discord, Slack, iMessage, and Signal - openclaw.ai. The omni-channel design remains the product's sharpest experiential difference from every managed alternative, and the January argument for it still holds: because every channel routes into one gateway with one memory, a task you start by voice note on your phone continues seamlessly in Slack at your desk, and the agent's view of your world is unified rather than sharded across per-app assistants that do not know about each other. Big-suite AI features still work the sharded way (the assistant in your email does not know what the assistant in your calendar just did), and that difference in architecture, not model quality, is why OpenClaw users describe the experience as having a colleague rather than using a feature. There are first-party companion apps for macOS 15+ (universal binary) and Windows 10 20H2+ or Windows 11 in both x64 and ARM64 builds, with the Windows implementation using Microsoft Execution Containers for sandboxing - openclaw.ai. Installation is still a one-liner:
curl -fsSL https://openclaw.ai/install.sh | bash
# or
npm i -g openclaw
openclaw onboard # interactive setup wizard
The openclaw onboard wizard walks through channel setup, model credentials, and the sandboxing decision, which the project frames as "full access or sandboxed, your choice" - openclaw.ai. The guided setup has grown considerably smarter since January: recent releases added strongest-model selection during onboarding and local-provider detection that automatically discovers Ollama and LM Studio installations on your machine - Releasebot. The gap between "clone a hacker's repo and edit YAML" (the January experience) and today's onboarding is one of the quieter but most consequential changes of the year, because it moved the effective audience from developers to any patient power user. That phrase deserves a pause, because it is the entire risk model of the product compressed into six words. Full access means the agent can touch anything your user account can touch. Sandboxed means it operates inside a container with an allowlist. Most of the disasters in Section 8 happened to people who chose full access, bolted the gateway onto a public IP, and installed skills from strangers. The software gives you the rope; the choice of what to do with it is genuinely yours, and after the events of this spring the documentation is far more insistent about the safe path than the January version was.
Three other facts complete the current picture. First, stewardship: OpenClaw is a project of the OpenClaw Foundation, the nonprofit established when Steinberger joined OpenAI, and it now has a full-time maintainer team - openclaw.ai. Second, adoption: the repository hit 247,000 GitHub stars and 47,700 forks by March 2, 2026, making it one of the fastest-growing repositories GitHub has ever hosted - Wikipedia. Third, maturity: as of July 30, 2026 the project ships an extended-stable release channel, starting with version 2026.6.33 (based on 2026.6.11 with backported security and reliability fixes), plus published maturity scorecards on the road to a formal LTS - Releasebot. That last item is the clearest signal of where this project is heading: away from "move fast and molt" and toward something an IT department could defensibly approve.
If you want the hands-on version of everything in this section, we maintain a dedicated OpenClaw setup guide with 10 configurations covering hardware choices, channel wiring, and hardening, and a separate breakdown of what OpenClaw actually costs to run once model API bills enter the picture.
4. Under the Hood: How OpenClaw Works in August 2026
The architecture we described in January is one of the few things that survived the year intact, so we are keeping the three-layer framing and updating the details. OpenClaw is not itself an AI model. It is an orchestration gateway that sits between your messaging apps and whichever model brains you configure, wrapped in a memory system and a tool framework. Understanding these layers is what separates people who run OpenClaw safely from people who end up in a Censys scan.
The first layer is the gateway, the always-running process on your machine or server that receives every message, maintains conversation state, decides which tools to invoke, and calls the model. The second layer is channels, the connectors that bridge the gateway to the 29 supported platforms so that a WhatsApp message and a Slack message land in the same brain with the same memory - openclaw.ai. The third layer is the model backend, which is fully pluggable. This is also where the biggest factual rot in our January version lived: we told readers "Claude 2 with its 100k context is a popular choice." That model era is long gone, and repeating January model advice in August would cost you real money and quality.
Here is the model layer as it actually stands, verified against the live documentation this week. Fresh setups with an OpenAI API key and ChatGPT/Codex OAuth setups both land on the same canonical catalog ref, openai/gpt-5.6-sol - OpenClaw docs. The supported provider list spans OpenAI, Anthropic, GitHub Copilot, OpenRouter, Ollama, and LM Studio, plus custom endpoints - OpenClaw docs. The catalog moves fast. Version 2026.9.1, released September 3, 2026, pulled in Anthropic's Claude Fable 5.1 from shared model metadata, and 2026.9.2, released September 5, 2026, added OpenAI's new flagship GPT-6 Astra, selectable as openai/gpt-6-astra with an API-key profile or an eligible ChatGPT/Codex account, with text and image input - OpenClaw releases. Astra is an opt-in selection rather than the new default, and OpenAI's price list explains the restraint: at $10 input / $50 output per million tokens it costs 2.5x what the default gpt-5.6-sol does ($4 / $20), which is a serious tax on an agent that wakes up every few minutes - OpenAI pricing. Claude Opus 5, Kimi K3 support and local-provider auto-discovery for llama.cpp GGUF models landed earlier in the same cycle - Releasebot. The irony of the year: the project renamed away from its Claude identity under trademark pressure, and its default brain is now an OpenAI model, while its creator works at OpenAI. The "Clawd" in the original name is pure archaeology at this point.
If you point OpenClaw at Anthropic models, here is the current price list from Anthropic's own pricing page, which matters enormously for an always-on agent that consumes tokens around the clock - Anthropic pricing:
| Model | Input / MTok | Output / MTok | Notes |
|---|---|---|---|
| Claude Haiku 4.5 | $1 | $5 | Cheapest current-generation option |
| Claude Sonnet 5 | $2 | $10 | Launch price, now the standard rate; no increase scheduled |
| Claude Opus 5 | $5 | $25 | Flagship-class reasoning |
| Claude Fable 5.1 | $10 | $50 | Top of the current lineup; cache hits at $0.25 |
In practice, configuring the model layer looks like this. OpenClaw's model catalog uses provider-prefixed identifiers, with per-agent primary and fallback assignments documented in the model concepts guide - OpenClaw docs. A typical configuration looks like this:
{
"agents": {
"defaults": {
"model": {
"primary": "openai/gpt-5.6-sol",
"fallbacks": ["anthropic/claude-sonnet-5", "ollama/gemma4:26b"]
}
}
}
}
The fallback chain is not decoration. It is how experienced operators survive rate limits and provider outages without their always-on agent going dark, and it is also how they implement the cost strategy that matters most here. Two cost mechanics matter more for agents than for chatbots. Prompt caching cuts repeated context to 10% of the base input price on cache hits (cache writes cost 1.25x base for the 5-minute tier and 2x for the 1-hour tier, so caching pays for itself after one to two reads), which is transformative for an agent that re-sends the same system prompt and memory hundreds of times a day. On Claude Fable 5.1 the read multiplier is sharper still at 0.025x, putting a cache hit at $0.25 per million tokens against a $10 base, so the most expensive model in the lineup is the one that penalises a warm cache least - Anthropic pricing. And model routing (cheap model for triage, expensive model for hard reasoning) is the single biggest lever on an always-on agent's bill; we measured the technique in detail in our guide to cutting agent costs with model routing. OpenClaw supports both patterns through per-agent model configuration. For picking the brain itself, our August 2026 ranking of LLMs for agent workloads covers the trade-offs model by model, and our Sonnet 5 benchmark breakdown explains why that model's price-to-capability ratio made it the default recommendation for high-volume agent loops.
To make the economics concrete, run the arithmetic on a plausible always-on personal setup: an agent handling 300 model calls per day (messages, scheduled briefings, tool loops), averaging 3,000 input and 500 output tokens per call. On Sonnet 5 ($2 input / $10 output per million tokens), that is 0.9M input tokens ($1.80) plus 0.15M output tokens ($1.50) per day, roughly $99 per month. Add effective prompt caching (say 80% of input arriving as $0.20/MTok cache hits) and the same workload drops to about $60 per month. Route the identical traffic to Opus 5 ($5/$25) and the uncached figure is around $250 per month; route it to Haiku 4.5 ($1/$5) and it falls under $50. All unit prices are from Anthropic's live pricing page, and the spread is the entire argument for routing - Anthropic pricing. The January-era community folklore of "$1 a day to run your bot" and the horror stories of four-figure monthly bills are both real; they are the same workload with different model discipline. That baseline is also stable now. The $2/$10 Sonnet 5 rate was announced at launch as introductory pricing through August 31, 2026, but Anthropic's pricing page records it as the standard price and states that the increase to $3/$15 scheduled for September 1, 2026 will not occur - Anthropic pricing. The 50% jump budgets were bracing for is not coming, which makes the mid-tier the safest place to park an always-on workload.
The remaining mechanics from the January version remain accurate and deserve restating briefly. Memory is plain Markdown files on your disk, organized by date and topic, searched semantically when the agent needs to recall context; you can open and edit what your agent "knows" with a text editor, which remains one of the most user-respecting design decisions in the product. Tool use runs through the Model Context Protocol pattern: the model requests a tool invocation, the gateway executes it within configured limits, and the result flows back into context, which is what lets a text-prediction engine send an email, run a script, or read a calendar without the model itself ever touching your system directly. The gateway is the enforcement point in that loop, which is exactly why gateway vulnerabilities (Section 8) were so much worse than model misbehavior ever was: a jailbroken model can be argued with, a compromised enforcement point cannot.
Skills are the extension mechanism, small packages of instructions and code that teach the agent new tricks, distributed through the community registry now called ClawHub (renamed from ClawdHub along with everything else). The registry had scaled past 10,700 listed skills by mid-February - Conscia, covering everything from Notion sync to home automation to video generation, and the agent can write new skills for itself on request. Architecturally, skills are what make OpenClaw feel limitless; economically, they are why the ecosystem compounds (every user's integration problem, solved once, becomes everyone's capability); and from a security standpoint they are third-party code executing inside the most trusted process on your machine. That triple identity is the most important single thing to understand about this product, and it is why skills get their own treatment in Sections 6 and 8.
5. OpenClaw vs Claude Cowork vs Managed Platforms
The January version of this guide compared Clawdbot against "Claude," which in hindsight was the wrong axis. The real decision facing someone in August 2026 is between three operating models for the same underlying capability, and the honest comparison is about who carries the operational burden, not whose model is smarter. The framing we used in January, renting intelligence vs owning it, survives because it is structurally true. What changed is the middle of the market.
The first archetype is self-hosted OpenClaw: free software, your hardware, your API keys, your security posture. The second is Claude Cowork, Anthropic's managed agent for general knowledge work, which stopped being a desktop-only Mac app on July 7, 2026 when Anthropic expanded it to the web and mobile, with tasks that keep running in the background even when your laptop is closed - TechCrunch. The mobile and web rollout started with Max subscribers ($100/month for Max 5x, $200/month for Max 20x), and Cowork is bundled into paid Claude plans from Pro at $20/month upward - claude.com/pricing. The third archetype is a managed agent workforce platform, which is the category O-mega occupies: cloud-run agents with browser and computer automation, credential isolation, and audit trails, aimed at business workflows and teams that will never SSH into anything. Disclosed plainly: this is our product, and this row of the table is first-party.
| Self-hosted OpenClaw | Claude Cowork | Managed platform (e.g. O-mega) | |
|---|---|---|---|
| Software cost | Free, open source | From $20/mo (Pro); web+mobile rollout led with Max at $100-$200/mo | Subscription per plan |
| Model costs | Your API keys, metered per token | Included in plan limits | Included in plan credits |
| Runs where | Your Mac/mini/VPS, 24/7 if you keep it up | Anthropic's cloud; desktop, web, iOS/Android | Vendor cloud, always-on |
| Channels | 29 messaging platforms | Claude apps only | Web app plus integrations |
| Extensibility | Unlimited: skills, custom code, any model | Anthropic's supported tools | Platform skill/tool library |
| Security burden | Entirely yours: patching, sandboxing, exposure | Anthropic's | Vendor's |
| Best for | Technical users who want ownership and privacy | Individuals already in the Claude ecosystem | Teams that need outcomes without ops |
Channel and platform data from openclaw.ai and the Cowork expansion coverage in TechCrunch; subscription prices from claude.com/pricing.
The renting-vs-owning frame from our January version deserves one more turn of the crank, because seven months of evidence sharpened it. When you rent intelligence (Cowork, or any managed platform including ours), you are really renting four things bundled together: the model, the runtime, the security perimeter, and the accountability when something goes wrong. When you own it (OpenClaw), you unbundle all four, keep the upside of each, and carry the downside of each. January commentary treated the bundle as pure margin extraction by vendors, and the spring demonstrated what the bundle actually prices: the exposed-instance counts in Section 8 are a direct measurement of what happens when thousands of people take ownership of a perimeter they did not know they were buying. Neither side of the trade is wrong. What is wrong is choosing a side without knowing the four components exist.
For teams sitting between the individual and enterprise poles, note that Anthropic also sells Team plans at $20 per seat per month (standard, annual) and $100 per seat for the premium tier, with Cowork included, central administration, and SSO - claude.com/pricing. That pricing makes Cowork a genuine competitor for small-team agent work that would have defaulted to spreadsheets and interns in 2025, and it boxes self-hosted OpenClaw into an even more specific niche for business use: teams with real infrastructure skills and either data-locality requirements or integration needs that a closed runtime cannot meet.
Anthropic's own usage data explains why this comparison now matters to non-technical readers. Of those 1.2 million Cowork sessions analyzed in late May, business process operations dominated at 33.4%, with content creation at 16.4% and software development at only 8.7% - TechCrunch. The people adopting agents fastest are not the people who can harden a Docker deployment.
Read that chart against this article's subject and the strategic picture snaps into focus. The workloads dominating managed-agent usage (process operations, document work, administrative coordination) are exactly the workloads OpenClaw's community proved out in January with email triage and calendar automation. The demand was never in question; the delivery mechanism was. What the market discovered between January and July is that most of the people who want an agent do not want to operate one, and every product move covered in this guide (Cowork going cross-device, Microsoft's ClawPilot experiments, the foundation's enterprise release channel) is a different bet on how to close that gap between demand and operational capacity.
So where does each archetype genuinely win? OpenClaw wins on ownership. If you want your agent's memory on your own disk, your model choice unconstrained (including fully local inference via Ollama when privacy demands it), and the freedom to wire it into anything with an API, nothing managed comes close, and the price of the software is zero. Cowork wins on frictionlessness for individuals. If you already pay for Claude and your needs are personal productivity, document work, and research, you get a competent agent with zero infrastructure and Anthropic's security team standing behind it; our Cowork insider guide covers its tactics and limits in depth. Managed platforms win when the user is a business. The moment an agent touches customer data, shared credentials, or revenue-bearing workflows, "who patches the CVE" and "where is the audit log" stop being enthusiast questions and become liability questions, and paying a vendor to own them is usually cheaper than owning them badly.
A note on the comparison our January version spent the most words on, OpenClaw vs plain chatbot Claude or ChatGPT: we have retired it, because the market did. In January, "why not just use the chat app" was a live question. In August, every major provider's paid tier ships some form of agentic capability, so the chat-vs-agent boundary now runs inside each product line rather than between products. The live question is the one this section answers: not whether you want an agent, but whose operational model you want it under.
The dishonest version of this section would stop there. The honest version adds: if you are a technical individual who enjoys operating systems, OpenClaw is the better choice than our product for personal use. It is more flexible than anything managed, the community is extraordinary, and running your own agent teaches you more about this technology than any SaaS ever will. The reverse is equally true: if you cannot tell us what a WebSocket origin check is, Section 8 is your reading assignment before you install anything, because the failure mode of self-hosting is not "it does not work," it is "it works for a stranger."
6. Key Features, Refreshed, with the Security Caveats That Belong Next to Them
The feature skeleton from January survives because the features themselves survived; what our original version lacked was the second column, the cost of each feature in attack surface. After watching this project's 2026 unfold, we think describing an agent feature without its security implication is journalistic malpractice, so this section pairs them.
Omni-channel presence remains the signature experience. One brain across 29 platforms means you start a task on WhatsApp on the train and finish it in Slack at your desk, with full continuity - openclaw.ai. The caveat: every channel is an inbound path to a process that can execute code. The gateway's web Control UI was the vector for the worst vulnerability of the spring (Section 8), and each additional connected surface is another place where an attacker-controlled message can reach your agent. The mitigation is structural, not behavioral: keep the gateway bound to localhost or a private network, never a public IP.
Persistent memory still works the way we described in January: Markdown files on disk, organized by date and topic, retrieved semantically so the agent recalls "the proposal from last week" without you re-explaining it. It remains the feature users love most and the clearest expression of the project's local-first philosophy, and it is genuinely differentiating: no managed product lets you open your agent's brain in a text editor, correct a wrong memory by editing a file, or back the whole thing up with rsync. Over months of use this becomes a compounding asset, a personal knowledge base that the agent actively maintains and consults, which is why long-term users describe switching away as unthinkable. The caveat is inherited: those files now contain a running transcript of your life, so the machine that holds them is exactly as sensitive as your email archive, and any skill you install can potentially read them. Memory is also where a subtler failure lives, one we flagged in January and stand by: if the agent records a wrong conclusion, it will confidently reuse that misinformation later, so periodically auditing what your agent believes is real maintenance, not paranoia.
Proactive routines (morning briefings, watchdogs, scheduled reports) are what make the product feel like an employee rather than a tool. The caveat is subtle: proactive behavior means the agent acts on content it fetched on its own, without you in the loop, and that is precisely the shape of a prompt-injection attack. A poisoned web page or email that your agent reads during a 7 AM briefing can carry instructions your agent may follow. We wrote a full defensive guide to this exact failure class in prompt injection defense for AI agents, and it applies to OpenClaw verbatim.
Skills are the ecosystem's superpower and its wound. The registry, now called ClawHub, scaled past 10,700 listed skills by mid-February - Conscia. The agent can even write its own skills on request, hot-loading new capabilities mid-conversation, which is still one of the most striking demonstrations of what agentic software can do. The caveat gets its own section: hundreds of those community skills turned out to be malware, and "install a stranger's code into the process that reads your email" is a sentence that should make anyone pause. We keep a curated, safety-annotated list in our top 100 skills and tools for OpenClaw roundup.
Voice and multimodal interaction rounds out the set: send a voice note, get a spoken reply, wire in telephony if you want your agent to actually call you. The companion apps for macOS and Windows - openclaw.ai have pulled this from the January era's duct-taped scripts into something closer to a native assistant experience, with the desktop app handling notifications and local device access that a pure chat channel cannot. This one's caveat is mostly about cost, since audio pipelines multiply token and service usage on top of an already always-on system, and speech adds transcription and synthesis charges to every exchange that text handles for tokens alone. Taken together, the pattern across all five features is consistent: capability and exposure are the same dial. OpenClaw's design philosophy is to hand you that dial with full range, which is exactly right for its audience and exactly wrong as a default for everyone else. That philosophy is the deep reason the archetypes in Section 5 exist at all: managed platforms are, in essence, someone else deciding where the dial should sit and being accountable for the answer.
7. What Early Adopters Did, and What Held Up
Our January version collected the use cases that made Clawdbot famous. Seven months later, the interesting question is which of them survived contact with reality. The answer, based on what the community kept building versus what quietly disappeared, sorts into three buckets: patterns that held up, patterns that consolidated, and one pattern that became the cautionary tale of the year.
What held up: the boring workflows. Agents as operators of recurring drudgery, that is. The email-triage secretary, the calendar coordinator, the research assistant that ingests PDFs into searchable memory, the DevOps sidekick that watches error trackers and drafts fixes: these all proved durable, and they map almost perfectly onto the session data Anthropic later published showing business process work as the dominant agent use - TechCrunch. The January anecdotes were real signals, not hype artifacts. We track the current state of these patterns, with configurations, in our top 50 OpenClaw use cases ranking.
What distinguishes the surviving patterns is worth spelling out, because it is the most transferable insight on this page. Every workflow that held up shares three properties: the task recurs on a schedule or trigger (so the setup cost amortizes), the output is cheap to verify (you can glance at a triaged inbox or a drafted reply and confirm it is right), and the blast radius of a mistake is bounded (a mislabeled email embarrasses nobody). Every pattern that quietly died in the community inverted at least one of those: one-off tasks where setup exceeded doing it manually, outputs that took longer to check than to produce, or actions with unbounded consequences like unsupervised purchasing and public posting. The January version of this guide relayed a story of an agent autonomously arguing with an insurance company by email, told at the time as a triumph. We reread it in August as a coin flip that landed well: unsupervised outbound communication with a counterparty is a bounded-verification failure and an unbounded-consequence action rolled into one, and most operators who tried that class of automation walked it back to draft-for-approval mode. The pattern language, not any single anecdote, is the durable lesson.
What consolidated: the hardware cargo cult. January's rush to buy Mac minis as dedicated agent servers cooled into a more sensible spectrum: a spare machine, a small VPS, or a companion app on the laptop you already own, with the foundation's companion apps for macOS and Windows removing much of the original server-wrangling - openclaw.ai. The lesson early adopters learned is that the constraint was never compute; the gateway idles cheaply. The constraints are uptime, network exposure, and the model API bill. There is a second-order lesson buried in that correction which generalizes well beyond this product: when a technology goes viral, the community initially over-invests in the visible, purchasable part of the stack (hardware you can photograph for a tweet) and under-invests in the invisible parts (patch discipline, credential scoping, cost monitoring) that actually determine outcomes. The gap between the Mac mini enthusiasm of January and the exposure statistics of February is that misallocation, measured.
The cautionary tale: Moltbook. In late January, Matt Schlicht launched Moltbook, a Reddit-like social network where people's OpenClaw agents post and reply to each other autonomously in forums called Submolts - Wikipedia. It became an overnight phenomenon: Simon Willison called it "the most interesting place on the internet right now," and Andrej Karpathy marveled at agents self-organizing on it - TechCrunch. It also concentrated every open question about agent autonomy into one venue. The Moltbook skill instructed agents to check for updates every four hours, a design TechCrunch flagged at launch as an inherent security risk, since it gave a third party a standing instruction channel into thousands of agents - TechCrunch. Then came the consent stories: in the MoltMatch incident, a student's agent created a dating profile for him without being asked, and a Malaysian model's photos were used on the platform without her consent - Wikipedia. And in the security bucket, the platform's breach exposed roughly 35,000 email addresses and 1.5 million agent API tokens at a time when it hosted 770,000+ active agents - Reco.
Moltbook deserves its place in this guide because it is the purest available demonstration of the year's central lesson: autonomy compounds. One agent acting for one person under supervision is a productivity tool. Hundreds of thousands of agents acting on each other's outputs, on a platform that can push them instructions, is an ecosystem with emergent behavior nobody signed off on. The MoltMatch student did not configure "create a dating profile"; his agent inferred it. If you want to experiment anyway, and it is genuinely fascinating, our walkthrough on creating agents on Moltbook includes the containment steps we consider non-negotiable: a dedicated agent identity, throwaway credentials, and no access to your primary memory store.
The meta-lesson across all three buckets matches what we see operating agents commercially: the durable value is in supervised, scoped, repeatable workflows, and the spectacular failures come from unscoped autonomy plus third-party instruction channels. That is not an argument against agents. It is the operating manual for them.
8. The Security Crisis: CVEs, 40,000+ Exposed Instances, and ClawHavoc
Our January version said Clawdbot "could have vulnerabilities" and advised readers to be careful. That hand-waving did not survive the spring, and rewriting it honestly is the single biggest upgrade in this refresh. What happened to OpenClaw between late January and March 2026 is now the defining case study in agent security, taught in vendor briefings and cited in national policy decisions. Here is the documented record, every number from a source we opened while writing this.
The headline vulnerability was CVE-2026-25253, a one-click remote code execution flaw scoring 8.8 CVSS: the gateway's Control UI accepted an unvalidated gatewayUrl query parameter and performed no WebSocket origin validation, so a single malicious link could hijack a victim's local gateway connection and execute code with the agent's privileges - Conscia. It was patched in version 2026.1.29 on January 30, the same day as the OpenClaw rename, with two further command-injection vulnerabilities disclosed on February 3 - Reco.
A patch only helps the people who apply it, and the exposure data showed how many people were running this software in ways no patch could save. Censys watched publicly reachable instances grow from roughly 1,000 on January 25 to 21,639 by January 31 - Reco. Bitsight counted over 30,000 across a broader window, and independent researcher Maor Dayan identified 42,665 exposed instances, of which 5,194 were actively verified as vulnerable and 93.4% exhibited authentication bypass conditions - Conscia. Each of those numbers is a person who wired an agent into their email, files, and messaging apps, then left the door open.
The second front was the skill registry. In the ClawHavoc campaign of January 27-29, Koi Security found 341 malicious skills among ClawHub's 2,857 listings, roughly 12% of the registry, with 335 of them sharing a single command-and-control infrastructure and primarily delivering the Atomic macOS Stealer credential-theft malware - Conscia. It got worse as the registry grew: a February 16 scan found over 824 malicious skills among 10,700+ listings, Bitdefender's analysis put the compromised share near 20% (~900 packages), and a single operator using the handle "hightower6eu" uploaded 354 malicious packages alone - Conscia. Beyond the registry itself, Cisco's AI security team documented a third-party skill performing silent data exfiltration and prompt injection without user awareness - Wikipedia.
The consequences escalated beyond individual victims. Enterprise security firm Token Security found that 22% of analyzed customers had employees running OpenClaw variants without security team approval, classic shadow IT but with shell access - Forbes. And in March 2026, Chinese authorities restricted state enterprises and government agencies from running OpenClaw on security grounds - Wikipedia. A hobbyist tool does not usually earn a national-level restriction inside five months of existing.
If you run OpenClaw today, the record above converts into a short, non-negotiable hardening posture. The crisis data is unusually clear about what separated victims from bystanders: exposure, staleness, and unvetted third-party code accounted for essentially every documented compromise, which means the defense is equally concrete. None of this requires deep expertise; all of it requires actually doing it.
- Never expose the gateway to a public IP; bind to localhost or a private network (the entire Censys/Bitsight population violated this one rule)
- Update within 24 hours of any security release, or run the extended-stable channel and update on its cadence
- Choose sandboxed mode, not full access, and run the gateway as an unprivileged user
- Treat every skill as untrusted code: read it, scope it, and prefer skills you or the foundation have verified
- Scope credentials per integration with revocable, least-privilege tokens instead of your primary account passwords
Do those five things and you are outside the population that every scary number in this section describes; skip any one of them and no amount of model intelligence protects you, because the compromise happens below the model. The deeper configuration walkthroughs, including network layouts for each hardware setup, are in our OpenClaw setup guide.
Credit where due: the project's response has been substantive rather than cosmetic. The patch cadence through the crisis was fast, the foundation professionalized maintenance with a full-time team - openclaw.ai, and the extended-stable channel launched July 30 exists specifically so risk-averse deployments can run a slower, security-backported release line (2026.6.33) with published maturity scorecards - Releasebot. OpenClaw in August 2026 is meaningfully safer than Clawdbot was in January. The attack surface, however, is inherent to the category, not incidental to this project.
That is the operator take we can add that no aggregator can. At O-mega we run autonomous agents with browser and computer access in production, and every element of this crisis was predictable from first principles because we price these exact risks every week. An agent is a process that holds credentials, accepts instructions from content it reads, and executes actions with real-world consequences. Combine those three properties and you get a system where any input channel is potentially a command channel, which is a threat model ordinary software simply does not have. OpenClaw's early architecture optimized its defaults for magic rather than containment, and 30,000+ exposed instances is what that gap looks like at internet scale.
What does "contained by default" actually require? From operating it ourselves: per-task sandboxing, so a compromised task cannot reach beyond its working set; credential isolation, so the agent never holds raw secrets it does not need this minute and a leaked context window does not leak your password vault; egress control, so exfiltration has to cross a monitored boundary instead of a free internet connection; and immutable audit logs, so you can reconstruct what the agent did rather than what it says it did. None of these are exotic, all of them are tedious, and each one taxes exactly the fluidity that makes an agent feel magical, which is why a viral project racing to delight users shipped none of them as defaults and why a managed vendor has no excuse not to. The ClawHub countermeasure story runs on the same economics in reverse: registry-side scanning and verification is cheap per skill and was still outrun for weeks by a single motivated uploader pushing 354 malicious packages - Conscia. Supply-chain defense that depends on scanning alone loses to volume; it has to be paired with least-privilege execution so that the malicious skill that inevitably gets through has nothing worth stealing.
The uncomfortable symmetry: everything that made the ClawHavoc campaign devastating (an eager agent, broad permissions, third-party instructions) is present in any agent system, including ours, and the only real difference between vendors is how much engineering stands between those properties and the blast radius. When you evaluate any agent product, self-hosted or managed, ask the containment questions first. Our prompt injection defense guide is the checklist we use internally.
9. Which One Should You Run in August 2026
Everything above compresses into a decision, and unlike January, we now have enough evidence to make it prescriptive rather than diplomatic. The variable that decides it is not budget and not intelligence requirements, because model access has converged: every archetype can put a frontier model behind your agent. The deciding variable is operational capacity: your honest ability, in hours and skills, to run and secure an internet-connected system that acts with your credentials.
Before the archetype-by-archetype verdicts, put real numbers on "total cost of ownership," because the sticker prices mislead in both directions. OpenClaw's software is free, but the worked example in Section 4 showed a busy personal agent consuming roughly $50-$100 per month in model API costs on mid-tier models even with caching discipline - Anthropic pricing, plus whatever your hardware or VPS costs, plus the unpriced line item: your hours. Patching, monitoring, skill vetting, and the occasional broken channel integration are real recurring labor, and if your time bills at anything, a "free" agent can quietly become the most expensive option on this page. Cowork inverts the shape: a flat $20-$200 per month - claude.com/pricing with the labor line at zero and a hard ceiling on flexibility. Managed platforms price between and above, with the labor and liability lines absorbed into the subscription. There is no universally cheapest option, only a cheapest option per hourly rate and risk tolerance, which is the honest framing the January pricing folklore lacked.
Run self-hosted OpenClaw if you are technical, you want maximum ownership, and you accept the maintenance contract you are signing. Concretely, that contract now has a measurable clause: this project shipped a CVSS 8.8 one-click RCE and patched it within days - Conscia. The people who were fine were the ones who applied that patch immediately and had never exposed their gateway in the first place. So the test is not "am I smart enough," it is: can I patch within 24 hours of a disclosure, and do I know what my agent can reach? If yes, OpenClaw gives you the deepest, most customizable personal agent that exists, at zero software cost plus model usage (metered against the current Anthropic price list or your provider of choice), and the extended-stable channel now gives you a saner update path - Releasebot. Privacy maximalists get an extra win: with Ollama-served local models - OpenClaw docs, your data need never leave your hardware at all.
Choose Claude Cowork if you are an individual whose work lives in documents, research, and personal productivity, and you would rather pay Anthropic to own the infrastructure. Anthropic pitches it as handling "the work around the work," and since July 7 it follows you across desktop, web, and mobile, with tasks continuing in the background even when no device of yours is online - TechCrunch. It is included from the $20/month Pro plan, with the heaviest usage tiers at $100-$200/month - claude.com/pricing. Be clear-eyed about what you give up relative to OpenClaw, because it is substantial: the 29-channel omnipresence (Cowork lives in Claude's own apps, not your WhatsApp), arbitrary extensibility (Anthropic's tool surface, not an open skill registry), model choice (Claude only), and data locality (Anthropic's cloud holds your working context). What you gain is the strongest default containment in the category and a maintenance burden of zero, which for most non-technical individuals is simply the correct trade. Our Cowork starter guide gets you productive in an afternoon.
Choose a managed agent workforce platform when the user is a business rather than a person. The moment agents touch shared credentials, customer data, or revenue workflows, the self-hosting contract becomes a liability you are underwriting personally, and Cowork's single-user shape stops fitting. This is the segment we built O-mega for: multiple specialized agents with browser and computer automation, centrally credentialed, logged, and supervised, operated by people who do this full-time. First-party recommendation, disclosed as such. If you want to shop the whole category rather than take our word, we rank our own competitors honestly in top 10 OpenClaw alternatives and the business-focused alternatives for business edition.
One deliberately unbalanced note to close the section: the January version of this page recommended a roundup of small AI-assistant startups (Saner.ai, Felix, Eva, Mem, Motion) sourced from a Reddit thread. We cut it. We could not verify those products' current state to the standard this refresh sets, several matched the "small AI assistant startups die fast" pattern that the same Reddit thread warned about, and padding a decision section with unverifiable options is exactly the aggregator behavior this rewrite exists to kill. If a category roundup is what you need, use our maintained alternatives ranking, which we re-verify on each update.
10. Future Outlook: Foundations, Clones, and the Agent Layer
Predictions from the January version deserve a scorecard before we make new ones. "Personal AI agents will go mainstream" happened faster than we projected, but through managed products: Cowork went cross-device and Anthropic's own data shows agents doing mostly non-coding business work - TechCrunch. "Big tech will respond" undershot reality: OpenAI hired the creator outright - TechCrunch, while Google's Remy and Microsoft's ClawPilot experiments under Project Lobster were both reported by May - Wikipedia. And our vague "there may be security growing pains" was the single worst call on the page, off by roughly one national government restriction and forty thousand exposed gateways.
The geographic spread is part of the same picture. Chinese companies including Tencent and Z.ai announced OpenClaw-based services even as Chinese authorities restricted government use of the underlying software - Wikipedia, a split-screen that captures the category's status everywhere: too useful to ignore, too risky to bless without controls. When the same artifact is simultaneously a banned deployment and a product foundation inside one country, the safe conclusion is that the technology has crossed from optional to infrastructural, and the remaining argument is about governance.
Looking forward from August, three trajectories seem structurally forced rather than speculative. First, institutionalization wins. The foundation model (nonprofit stewardship, corporate funding, LTS releases, maturity scorecards) is how viral infrastructure survives its own success, and OpenClaw is executing it visibly - Releasebot. Expect the gap between "enthusiast OpenClaw" and "enterprise OpenClaw" to widen into effectively two products sharing a codebase. Second, the agent layer commoditizes while containment differentiates. The reasoning is first-principles economics rather than trend extrapolation: when the intelligence input gets cheap and the orchestration layer has a free open-source floor under it, neither can hold a margin, and value migrates to whatever remains scarce. What remains scarce after 2026's lesson is trustworthy execution: security architecture, auditability, and someone accountable when an agent misfires. That is where every surviving vendor, including us, will actually compete, and it is the same conclusion the ClawHavoc spring taught users to price from the other direction. Third, agent-to-agent ecosystems will produce the next crisis. Moltbook's 770,000 agents and its four-hour instruction-refresh channel - Reco were a preview of what happens when autonomous systems consume each other's outputs at scale; nothing about that dynamic got less potent, only more distributed. The defenses that work against it are the same containment primitives from Section 8 applied one level up, and the platforms that internalize that earliest will write the incident reports instead of starring in them.
For readers of this site, the practical takeaway has not changed since Section 9: match the archetype to your operational capacity, start with scoped supervised workflows, and treat every new capability as a new liability until proven otherwise. If you want to go deeper into building rather than choosing, our guide to open-source personal AI you build yourself covers the DIY path beyond OpenClaw, and the Claude Code pricing breakdown covers the adjacent developer-agent economics.
Conclusion: The Page We Should Have Been Able to Write in January
Clawdbot the name lasted about two months. Clawdbot the idea, a persistent, proactive agent that lives in your messaging apps and actually does things, turned out to be one of the most consequential software ideas of the decade, strong enough to survive two forced renames, a creator's departure to OpenAI, a CVE-grade security spring, and a government restriction, and come out the other side with a foundation, an LTS channel, and 247,000 stars - Wikipedia.
For readers who arrived here from a January bookmark, the deltas that matter are compact enough to restate: the product is at openclaw.ai and nothing under the old names should be trusted; the channel count is 29, not 8; the default fresh-setup model is OpenAI's GPT-5.6 Sol, not any Claude of the 100k-context era - OpenClaw docs; Claude Cowork is cross-device, not desktop-only - TechCrunch; and the vague security worries of January now have names, numbers, and patches. Everything else you remember about why this software felt like the future was, and remains, true.
The decision framework stands: OpenClaw if you can operate what you own and want the deepest personal agent available; Claude Cowork if you want the idea with none of the ops, from $20/month across desktop, web, and mobile; a managed workforce platform like O-mega when the stakes are a business rather than a hobby. And whichever you choose, carry the one lesson 2026 charged so much tuition for: an agent's capability and its attack surface are the same thing measured twice, so buy, build, and configure for containment first. The magic follows from there.
Written by Yuma Heymans (@yumahey), founder of O-mega and co-founder of HeroHunt.ai, who has spent 2026 running production fleets of autonomous agents and patching the same class of holes this article documents.
This guide reflects the OpenClaw and AI agent landscape as of August 5, 2026. Every price, version number, and security statistic was verified against live sources on that date. This space moves fast: re-verify current details before making purchasing or deployment decisions.