New AI Agent ‘Clawdbot’ Exposes Users to Remote Hijacking

January 27, 2026
New AI Agent ‘Clawdbot’ Exposes Users to Remote Hijacking
​‌​‌​​‌‌​‌​​‌​​​​‌​​‌​​‌​‌​​​​‌​​‌​‌‌‌‌‌​​‌‌​​‌‌​​‌‌​​​‌​​‌‌​‌​‌​​‌‌​​​‌​​‌‌​​‌‌​‌​‌‌‌‌‌​​‌‌​​‌‌​​‌‌​‌​‌​‌‌​​​‌​​​‌‌​​​​​‌‌​​‌​​​‌‌​​‌‌​​​‌‌‌​​​​‌‌​​‌‌​​​‌‌​‌‌‌​​‌‌​​​‌

Key Points

  • Clawdbot, a popular open-source AI agent, exposed thousands of servers to remote hijacking due to unsecured default port configurations on Monday.
  • The move involved over 1,000 unauthenticated servers and 43,000 GitHub stars as researchers warned of widespread API key theft.
  • Experts say the crisis highlights the danger of prioritizing viral AI growth over fundamental security protocols in demo-grade software.
0:00

An explosive surge in the popularity of the AI agent “Clawdbot” just triggered a widespread security crisis. Cybersecurity experts warn that thousands of server deployments are currently exposed to the open internet without any form of authentication.

The software allows users to manage web browsing, shell commands, and scheduling via a simple interface using Anthropic’s Claude API. Clawdbot garnered over 43,000 GitHub stars in several weeks. Easy installation scripts often encourage users to deploy the agent on cloud Virtual Private Servers (VPS) with port 18789 left open to the world.

Remote Control Through Unsecured Endpoints

Security scans identified over 1,000 unauthenticated Clawdbot servers live on the web this week. Clawdbot executes shell commands and stores sensitive API keys for major platforms including OpenAI and Anthropic. An unencrypted and unprotected port effectively grants total remote control of the user’s private infrastructure to anyone with a basic port scanner.

Related: Back from the Shadows: Kusama Teases AI Evolution, SHIB Bounces

“Disaster’s coming,” security researcher ItakGol warned in a technical advisory on social media. “Thousands of these agents are live on cloud servers with open ports and zero authentication. If your bot can browse the web and access your files, an unauthenticated endpoint basically invites hackers to take over your machine.”

Unauthorized actors use these gaps to exfiltrate keys, inject malicious code, or recruit servers for botnet activities. Every hour of exposure increases the risk of financial theft or system compromise.

Emergency Patches and Configuration Scans

Project maintainer Steinberger merged emergency patches to address the widespread exposure late Monday. Updated default settings now bind the agent service to the local machine’s IP address rather than a public one. A new diagnostic command called clawdbot doctor assists users in identifying configuration risks.

Related: ChatGPT Model Found Referencing Elon Musk’s Grokipedia in Responses

IT professionals recommend that all administrators immediately close port 18789 to public traffic. Effective security protocols involve utilizing VPN tunnels for remote access instead of opening raw ports. Developers also recommend rotating every API key stored on an exposed instance to stop unauthorized billing.

Crypto Integration and Demo-Grade Software

Speculative interest from the cryptocurrency sector grew alongside the software’s adoption. Recent social media discussions focus on potential integrations with on-chain wallets and the launch of community tokens such as $CLAWD. These movements suggest a desire to financialize AI agency before the technology reaches maturity.

Critics describe the current build as demo-grade software. The infrastructure lacks the enterprise security features required for safe commercial use. Tech commentator Signulll noted that utilities rarely survive if they’re a chore to use. Coherence and security remain the primary hurdles for AI agents. 

Frequently Asked Questions

Clawdbot is an open-source AI automation agent that manages web browsing, shell commands, and scheduling via the Claude API. It is used by developers and cloud administrators for streamlining server tasks and AI-driven automation. This tool matters because its rapid adoption has created massive security blind spots across the global cloud infrastructure.
The vulnerability involves an unauthenticated port (18789) that grants anyone on the internet total remote control over the host's private files and shell. It is exploited by unauthorized actors to exfiltrate sensitive API keys from OpenAI and Anthropic, leading to massive unauthorized billing. This impact matters because it turns a productivity tool into a direct gateway for financial and systemic compromise.
Project maintainer Steinberger merged emergency patches late Monday to bind services to local IP addresses and introduced the "clawdbot doctor" diagnostic tool. Administrators must immediately close port 18789 to public traffic and transition to VPN tunnels for secure remote access. This process matters because failure to rotate exposed API keys allows hackers to maintain persistent access even after patching the software.
Integrating on-chain wallets with demo-grade software creates a high-risk environment where hackers can drain funds via the same unauthenticated shell access currently being exploited. Critics point to the launch of community tokens like $CLAWD as a dangerous move toward financializing immature and unshielded technology. This risk matters because it places user capital behind infrastructure that currently lacks fundamental enterprise-grade security layers.
YONA GUSHIKEN

YONA GUSHIKEN

Yona brings a decade of experience covering gaming, tech, and blockchain news. As one of the few women in crypto journalism, her mission is to demystify complex technical subjects for a wider audience. Her work blends professional insight with engaging narratives, aiming to educate and entertain.


Yona has no crypto positions and holds no crypto assets. This article is provided for informational purposes only and should not be construed as financial advice. The Shib Daily is the official publication of the Shiba Inu cryptocurrency project. Readers are encouraged to conduct their own research and consult with a qualified financial adviser before making any investment decisions.