CVE-2026-25253 "OpenClaw RCE" and Moltbook Database Exposure
Updated: Sep 30
DTG Threat Labs Advisory
Classification | Threat Advisory |
Threat Level | High/Advisory |
Date Issued | 02 February 2026 |
Distribution | To: Security Operations Centers (SOC), Development Teams, Cloud Security Teams |
Executive Summary
CVE-2026-25253, affecting the OpenClaw autonomous AI agent platform (formerly Clawdbot/Moltbot), is a critical remote code execution vulnerability with a CVSS score of 8.8 (High). The vulnerability permits unauthenticated attackers to achieve full system compromise through a single malicious link click by exploiting improper WebSocket origin validation. Concurrently, the Moltbook AI agent social network suffered a critical database misconfiguration that exposed over 1.5 million API keys, 35,000 email addresses, and 4.75 million records. Active exploitation is confirmed through the ClawHavoc campaign, which has distributed 341 malicious skills via ClawHub, targeting cryptocurrency wallets with the Atomic Stealer (AMOS) malware. Approximately 42,000+ internet-exposed OpenClaw instances are at risk globally, with 93.4% of verified instances exhibiting authentication bypass vulnerabilities.
The Vulnerability: WebSocket Origin Validation Bypass Leading to RCE
CVE-2026-25253 is classified under CWE-669 (Incorrect Resource Transfer Between Spheres). The vulnerability exists in OpenClaw's local server component, which fails to validate the Origin header on incoming WebSocket connections. When a victim clicks a malicious link, the attacker's webpage establishes a WebSocket connection to the victim's localhost OpenClaw instance (typically port 18789). Because the server accepts the gatewayUrl parameter from the query string without validation, it auto-connects and transmits the user's authentication token to the attacker-controlled server.
This vulnerability is pre-authentication and requires no user credentials. The attack chain proceeds in milliseconds: token exfiltration, followed by disabling user approval prompts via exec.approvals.set, container escape via config.patch, and finally arbitrary command execution via node.invoke. Users running OpenClaw in "God Mode" (highest permissions) face the greatest risk, as attackers gain full system access.
Technical Summary
Attribute | Detail |
CVE ID | CVE-2026-25253 |
Nickname | OpenClaw RCE / Moltbook Exposure |
Attack Vector | Network (unauthenticated, one-click) |
CVSS v3.1 Score | 8.8 (High) |
CWE Classification | CWE-669 (Incorrect Resource Transfer Between Spheres) |
Attack Complexity | Low |
Root Cause | Missing WebSocket origin header validation; Supabase RLS misconfiguration |
Exploit Availability | Public PoC released February 1, 2026 (DepthFirst) |
Exploitation Status | Actively exploited via ClawHavoc campaign |
Technical Details
Root Cause (CVE-2026-25253): OpenClaw server accepts gatewayUrl from query string without validation, auto-connects WebSocket, and transmits authentication token to attacker-controlled endpoint. No origin header validation on WebSocket handshake.
Root Cause (Moltbook): Supabase database deployed without Row Level Security (RLS) policies, exposing REST API with full read/write access to all tables.
Attack Vector: Victim clicks malicious link; attacker's page connects to localhost:18789 via WebSocket, exfiltrates token, disables approvals, escapes container, executes arbitrary commands.
Impact: Full system compromise, credential theft, cryptocurrency wallet exfiltration, lateral movement through connected services.
Affected Software and Versions
OpenClaw v2026.1.x -- Affected through v2026.1.28; patched in v2026.1.29 (January 30, 2026)
Moltbot (legacy name) -- All versions prior to rename affected
Clawdbot (original name) -- All versions affected; upgrade to OpenClaw v2026.1.29+
Moltbook Platform -- Vulnerability patched February 1, 2026; all API keys force-reset
Threat Intelligence
Threat Actors
The ClawHavoc campaign represents financially motivated cybercrime targeting cryptocurrency users. No specific nation-state or named APT group has been attributed. The campaign demonstrates sophisticated understanding of the AI agent ecosystem and supply chain attack methodologies.
Victimology and Targeting
Primary targets include: developers and technologists using AI agents (180,000+ users), cryptocurrency holders, enterprises with BYOD policies allowing AI agents, and organizations without AI agent-specific security controls. macOS users face elevated risk due to Atomic Stealer (AMOS) payload distribution.
MITRE ATT&CK Alignment
Technique ID | Technique Name | Applicable Incident |
T1190 | Exploit Public-Facing Application | CVE-2026-25253 WebSocket RCE |
T1552 | Unsecured Credentials | Moltbook Database Exposure |
T1195.001 | Supply Chain Compromise: Software Dependencies | ClawHavoc Malicious Skills |
T1555.001 | Credentials from Password Stores: Keychain | Atomic Stealer (AMOS) |
T1528 | Steal Application Access Token | Moltbook/OpenClaw Token Theft |
T1041 | Exfiltration Over C2 Channel | AMOS Data Exfiltration |
Exploitation Indicators and IOCs
Network Indicators
WebSocket connections to localhost:18789 from external origins
gatewayUrl parameter in URL query strings pointing to external servers
Connections to known C2 IPs: 91.92.242.30, 45.94.47.145, 45.94.47.147, 45.94.47.149
HTTP POST to /log endpoint at 45.146.130.131
Log Indicators
exec.approvals.set with ask: "off" (disabling user confirmation)
config.patch setting tools.exec.host to "gateway"
node.invoke with shell command payloads
User-Agent: curl/8.7.1 with base64-encoded task endpoints
File Hashes (SHA256)
File | SHA256 |
openclaw-agent.exe | 17703b3d5e8e1fe69d6a6c78a240d8c84b32465fe62bed5610fb29335fe42283 |
AMOS Sample 1 | 1e6d4b0538558429422b71d1f4d724c8ce31be92d299df33a8339e32316e2298 |
Setup.dmg | 15f39e53a2b4fa01f2c39ad29c7fe4c2fef6f24eff6fa46b8e77add58e7ac709 |
Threat Landscape and Observed Exploitation
Active exploitation is confirmed. The ClawHavoc campaign, discovered by Koi Security researchers on January 27, 2026, has distributed 341 malicious skills through the ClawHub marketplace. Of these, 335 skills originated from a single coordinated campaign using fake prerequisites to deliver Atomic Stealer (AMOS) malware to macOS users. Attack vectors include typosquatted skill names (clawhub, clawhub1, cllawhub), fake cryptocurrency tools (solana-wallet-tracker, phantom-wallet-*), and backdoored productivity utilities.
Exposure data indicates 42,665+ publicly accessible OpenClaw instances (Shodan/Censys), with 5,194 verified as vulnerable and 93.4% exhibiting authentication bypass issues. The Moltbook exposure affected 1.5 million API tokens, 35,000 email addresses, and included private messages containing plaintext OpenAI and Anthropic API keys.
Detection and Forensics
Monitor ~/.clawdbot/.env for unauthorized access or modification
Review extensions/ directory for unexpected skill installations
Check for /tmp/out.zip (AMOS compressed stolen data)
Audit network logs for connections to glot.io hosting malicious scripts
Search Shodan for exposed instances: "Clawdbot Control" HTML fingerprint
Business Impact
Data Breach Risk: Organizations face exposure of API keys, credentials, and sensitive data processed by AI agents. The Moltbook incident demonstrates that even "AI-only" platforms can leak human user data at scale.
Financial Loss: Cryptocurrency wallet theft is the primary financial impact vector. AMOS targets Electrum, Binance, Exodus, Atomic, and Coinomi wallets, along with exchange API keys.
Confidentiality: API keys, credentials, chat histories, cryptocurrency private keys, SSH credentials
Integrity: Compromised agents can execute arbitrary commands, modify configurations, inject malicious content
Availability: Agent compromise can disrupt automated workflows and connected services
Downstream Risk: Lateral movement to connected enterprise systems, cloud environments, and third-party services
Mitigation and Response Actions
Immediate (Day 1)
Upgrade OpenClaw to v2026.1.29 or later immediately across all instances
Generate new authToken for all OpenClaw instances
Rotate all API keys and credentials stored in OpenClaw configuration
Block known C2 IPs at network perimeter: 91.92.242.30, 45.94.47.145-149, 45.146.130.131
Short-Term (Days 2-7)
Audit all installed ClawHub skills against known malicious skill list
Scan network ranges for exposed OpenClaw/Moltbot/Clawdbot signatures
Review Moltbook connections and reset any associated credentials
Deploy detection signatures for WebSocket hijacking and AMOS C2 traffic
Long-Term (Ongoing)
Implement network segmentation to isolate AI agents from sensitive systems
Establish AI agent security policies and governance frameworks
Use secrets managers instead of local credential storage
Evaluate whether autonomous AI agents belong in your threat model
DTG Recommendations
Restrict Exposure
Do not expose OpenClaw instances to the public internet
Implement firewall rules blocking external WebSocket connections to localhost
Restrict AI agent network access to necessary endpoints only
Apply Patches
Upgrade to OpenClaw v2026.1.29+ (gateway auth mandatory, "none" mode removed)
Verify patch application via version check: openclaw --version
Monitor for Compromise
Implement SIEM rules for exec.approvals.set, config.patch, node.invoke sequences
Monitor for connections to identified C2 infrastructure
Alert on unexpected skill installations or configuration changes
Incident Response
If compromise is suspected, isolate affected systems immediately
Preserve ~/.clawdbot/ directory for forensic analysis
Rotate all credentials for services connected to the compromised agent
Call to Action and References
Call to Action
Don't wait for an attack - reach out to DTG today to ensure your organization is protected.
References
NVD -- "CVE-2026-25253 Detail" https://nvd.nist.gov/vuln/detail/CVE-2026-25253
SOCRadar -- "CVE-2026-25253: 1-Click RCE in OpenClaw" https://socradar.io/blog/cve-2026-25253-rce-openclaw-auth-token/
404 Media -- "Exposed Moltbook Database Let Anyone Take Control" https://www.404media.co/exposed-moltbook-database-let-anyone-take-control-of-any-ai-agent-on-the-site/
Wiz Research -- "Hacking Moltbook: 1.5M API Keys Exposed" https://www.wiz.io/blog/exposed-moltbook-database-reveals-millions-of-api-keys
The Hacker News -- "OpenClaw Bug Enables One-Click RCE" https://thehackernews.com/2026/02/openclaw-bug-enables-one-click-remote.html
The Hacker News -- "341 Malicious ClawHub Skills Found" https://thehackernews.com/2026/02/researchers-find-341-malicious-clawhub.html
Koi Security -- "ClawHavoc: 341 Malicious Skills Report" https://www.koi.ai/blog/clawhavoc-341-malicious-clawedbot-skills-found
Cisco Blogs -- "Personal AI Agents Are a Security Nightmare" https://blogs.cisco.com/ai/personal-ai-agents-like-openclaw-are-a-security-nightmare
The Register -- "OpenClaw Ecosystem Security Issues" https://www.theregister.com/2026/02/02/openclaw_security_issues/
VentureBeat -- "OpenClaw Agentic AI Security Risk CISO Guide" https://venturebeat.com/security/openclaw-agentic-ai-security-risk-ciso-guide/




Comments