OpenClaw 2.0 pours glitter on slow-burning security dumpster fire
Making installation easier and putting a new wrapper on the interface while leaving most of the security to users is a recipe for more trouble with the popular agent harness
A researcher's internet-exposed LLM inference honeypot was discovered and repurposed by attackers as a "free" backend service, where it received requests from a real coding-agent session containing sensitive data including command history, filesystem output, and local tool manifests. The incident demonstrates how threat actors could exploit such positions to intercept and manipulate agent interactions, gaining visibility into operational details and potential execution capabilities without needing to trigger actions themselves.
The boring parts caused most of the trouble. A router shipped ready to listen. A fake check turned the user into the installer. Trusted systems collected traffic and passwords, then cleaned the logs. Old bugs formed new attack chains. Even an AI agent decided its assigned task was optional. Elsewhere, fake apps, helpful support calls, cheap banking kits, exposed systems, and weak defaults kept
OpenClaw 2.0, a major update to the open source platform that automates security monitoring tasks like tracking vendor advisories and alerting users via Telegram, now stores session data in SQLite instead of previous methods. The upgrade represents the project's largest release to date and includes changes to how user data is handled within shared multiplayer workspaces. Security professionals should review the storage mechanism changes before deploying the update.