top of page

CVE-2026-25253 "OpenClaw RCE" and Moltbook Database Exposure

DTG Threat Management Team
Feb 12
5 min read

Updated: Sep 30

DTG Threat Labs Advisory

Classification

Threat Advisory

Threat Level

High/Advisory

Date Issued

02 February 2026

Distribution

To: Security Operations Centers (SOC), Development Teams, Cloud Security Teams

Executive Summary

CVE-2026-25253, affecting the OpenClaw autonomous AI agent platform (formerly Clawdbot/Moltbot), is a critical remote code execution vulnerability with a CVSS score of 8.8 (High). The vulnerability permits unauthenticated attackers to achieve full system compromise through a single malicious link click by exploiting improper WebSocket origin validation. Concurrently, the Moltbook AI agent social network suffered a critical database misconfiguration that exposed over 1.5 million API keys, 35,000 email addresses, and 4.75 million records. Active exploitation is confirmed through the ClawHavoc campaign, which has distributed 341 malicious skills via ClawHub, targeting cryptocurrency wallets with the Atomic Stealer (AMOS) malware. Approximately 42,000+ internet-exposed OpenClaw instances are at risk globally, with 93.4% of verified instances exhibiting authentication bypass vulnerabilities.

The Vulnerability: WebSocket Origin Validation Bypass Leading to RCE

CVE-2026-25253 is classified under CWE-669 (Incorrect Resource Transfer Between Spheres). The vulnerability exists in OpenClaw's local server component, which fails to validate the Origin header on incoming WebSocket connections. When a victim clicks a malicious link, the attacker's webpage establishes a WebSocket connection to the victim's localhost OpenClaw instance (typically port 18789). Because the server accepts the gatewayUrl parameter from the query string without validation, it auto-connects and transmits the user's authentication token to the attacker-controlled server.

This vulnerability is pre-authentication and requires no user credentials. The attack chain proceeds in milliseconds: token exfiltration, followed by disabling user approval prompts via exec.approvals.set, container escape via config.patch, and finally arbitrary command execution via node.invoke. Users running OpenClaw in "God Mode" (highest permissions) face the greatest risk, as attackers gain full system access.

Technical Summary

Attribute

Detail

CVE ID

CVE-2026-25253

Nickname

OpenClaw RCE / Moltbook Exposure

Attack Vector

Network (unauthenticated, one-click)

CVSS v3.1 Score

8.8 (High)

CWE Classification

CWE-669 (Incorrect Resource Transfer Between Spheres)

Attack Complexity

Low

Root Cause

Missing WebSocket origin header validation; Supabase RLS misconfiguration

Exploit Availability

Public PoC released February 1, 2026 (DepthFirst)

Exploitation Status

Actively exploited via ClawHavoc campaign

Technical Details

  • Root Cause (CVE-2026-25253): OpenClaw server accepts gatewayUrl from query string without validation, auto-connects WebSocket, and transmits authentication token to attacker-controlled endpoint. No origin header validation on WebSocket handshake.

  • Root Cause (Moltbook): Supabase database deployed without Row Level Security (RLS) policies, exposing REST API with full read/write access to all tables.

  • Attack Vector: Victim clicks malicious link; attacker's page connects to localhost:18789 via WebSocket, exfiltrates token, disables approvals, escapes container, executes arbitrary commands.

  • Impact: Full system compromise, credential theft, cryptocurrency wallet exfiltration, lateral movement through connected services.


 Affected Software and Versions

  • OpenClaw v2026.1.x -- Affected through v2026.1.28; patched in v2026.1.29 (January 30, 2026)

  • Moltbot (legacy name) -- All versions prior to rename affected

  • Clawdbot (original name) -- All versions affected; upgrade to OpenClaw v2026.1.29+

  • Moltbook Platform -- Vulnerability patched February 1, 2026; all API keys force-reset


Threat Intelligence

Threat Actors

The ClawHavoc campaign represents financially motivated cybercrime targeting cryptocurrency users. No specific nation-state or named APT group has been attributed. The campaign demonstrates sophisticated understanding of the AI agent ecosystem and supply chain attack methodologies.

Victimology and Targeting

Primary targets include: developers and technologists using AI agents (180,000+ users), cryptocurrency holders, enterprises with BYOD policies allowing AI agents, and organizations without AI agent-specific security controls. macOS users face elevated risk due to Atomic Stealer (AMOS) payload distribution.

MITRE ATT&CK Alignment

Technique ID

Technique Name

Applicable Incident

T1190

Exploit Public-Facing Application

CVE-2026-25253 WebSocket RCE

T1552

Unsecured Credentials

Moltbook Database Exposure

T1195.001

Supply Chain Compromise: Software Dependencies

ClawHavoc Malicious Skills

T1555.001

Credentials from Password Stores: Keychain

Atomic Stealer (AMOS)

T1528

Steal Application Access Token

Moltbook/OpenClaw Token Theft

T1041

Exfiltration Over C2 Channel

AMOS Data Exfiltration

Exploitation Indicators and IOCs

Network Indicators

  • WebSocket connections to localhost:18789 from external origins

  • gatewayUrl parameter in URL query strings pointing to external servers

  • Connections to known C2 IPs: 91.92.242.30, 45.94.47.145, 45.94.47.147, 45.94.47.149

  • HTTP POST to /log endpoint at 45.146.130.131

Log Indicators

  • exec.approvals.set with ask: "off" (disabling user confirmation)

  • config.patch setting tools.exec.host to "gateway"

  • node.invoke with shell command payloads

  • User-Agent: curl/8.7.1 with base64-encoded task endpoints

File Hashes (SHA256)

File

SHA256

openclaw-agent.exe

17703b3d5e8e1fe69d6a6c78a240d8c84b32465fe62bed5610fb29335fe42283

AMOS Sample 1

1e6d4b0538558429422b71d1f4d724c8ce31be92d299df33a8339e32316e2298

Setup.dmg

15f39e53a2b4fa01f2c39ad29c7fe4c2fef6f24eff6fa46b8e77add58e7ac709

Threat Landscape and Observed Exploitation

Active exploitation is confirmed. The ClawHavoc campaign, discovered by Koi Security researchers on January 27, 2026, has distributed 341 malicious skills through the ClawHub marketplace. Of these, 335 skills originated from a single coordinated campaign using fake prerequisites to deliver Atomic Stealer (AMOS) malware to macOS users. Attack vectors include typosquatted skill names (clawhub, clawhub1, cllawhub), fake cryptocurrency tools (solana-wallet-tracker, phantom-wallet-*), and backdoored productivity utilities.

Exposure data indicates 42,665+ publicly accessible OpenClaw instances (Shodan/Censys), with 5,194 verified as vulnerable and 93.4% exhibiting authentication bypass issues. The Moltbook exposure affected 1.5 million API tokens, 35,000 email addresses, and included private messages containing plaintext OpenAI and Anthropic API keys.

Detection and Forensics

  • Monitor ~/.clawdbot/.env for unauthorized access or modification

  • Review extensions/ directory for unexpected skill installations

  • Check for /tmp/out.zip (AMOS compressed stolen data)

  • Audit network logs for connections to glot.io hosting malicious scripts

  • Search Shodan for exposed instances: "Clawdbot Control" HTML fingerprint

Business Impact

Data Breach Risk: Organizations face exposure of API keys, credentials, and sensitive data processed by AI agents. The Moltbook incident demonstrates that even "AI-only" platforms can leak human user data at scale.

Financial Loss: Cryptocurrency wallet theft is the primary financial impact vector. AMOS targets Electrum, Binance, Exodus, Atomic, and Coinomi wallets, along with exchange API keys.

  • Confidentiality: API keys, credentials, chat histories, cryptocurrency private keys, SSH credentials

  • Integrity: Compromised agents can execute arbitrary commands, modify configurations, inject malicious content

  • Availability: Agent compromise can disrupt automated workflows and connected services

  • Downstream Risk: Lateral movement to connected enterprise systems, cloud environments, and third-party services


Mitigation and Response Actions

Immediate (Day 1)

  1. Upgrade OpenClaw to v2026.1.29 or later immediately across all instances

  2. Generate new authToken for all OpenClaw instances

  3. Rotate all API keys and credentials stored in OpenClaw configuration

  4. Block known C2 IPs at network perimeter: 91.92.242.30, 45.94.47.145-149, 45.146.130.131

Short-Term (Days 2-7)

  1. Audit all installed ClawHub skills against known malicious skill list

  2. Scan network ranges for exposed OpenClaw/Moltbot/Clawdbot signatures

  3. Review Moltbook connections and reset any associated credentials

  4. Deploy detection signatures for WebSocket hijacking and AMOS C2 traffic

Long-Term (Ongoing)

  1. Implement network segmentation to isolate AI agents from sensitive systems

  2. Establish AI agent security policies and governance frameworks

  3. Use secrets managers instead of local credential storage

  4. Evaluate whether autonomous AI agents belong in your threat model


DTG Recommendations

Restrict Exposure

  • Do not expose OpenClaw instances to the public internet

  • Implement firewall rules blocking external WebSocket connections to localhost

  • Restrict AI agent network access to necessary endpoints only

Apply Patches

  • Upgrade to OpenClaw v2026.1.29+ (gateway auth mandatory, "none" mode removed)

  • Verify patch application via version check: openclaw --version

Monitor for Compromise

  • Implement SIEM rules for exec.approvals.set, config.patch, node.invoke sequences

  • Monitor for connections to identified C2 infrastructure

  • Alert on unexpected skill installations or configuration changes

Incident Response

  • If compromise is suspected, isolate affected systems immediately

  • Preserve ~/.clawdbot/ directory for forensic analysis

  • Rotate all credentials for services connected to the compromised agent


Call to Action and References

Call to Action

Don't wait for an attack - reach out to DTG today to ensure your organization is protected.

References

  1. NVD -- "CVE-2026-25253 Detail" https://nvd.nist.gov/vuln/detail/CVE-2026-25253

  2. SOCRadar -- "CVE-2026-25253: 1-Click RCE in OpenClaw" https://socradar.io/blog/cve-2026-25253-rce-openclaw-auth-token/

  3. 404 Media -- "Exposed Moltbook Database Let Anyone Take Control" https://www.404media.co/exposed-moltbook-database-let-anyone-take-control-of-any-ai-agent-on-the-site/

  4. Wiz Research -- "Hacking Moltbook: 1.5M API Keys Exposed" https://www.wiz.io/blog/exposed-moltbook-database-reveals-millions-of-api-keys

  5. The Hacker News -- "OpenClaw Bug Enables One-Click RCE" https://thehackernews.com/2026/02/openclaw-bug-enables-one-click-remote.html

  6. The Hacker News -- "341 Malicious ClawHub Skills Found" https://thehackernews.com/2026/02/researchers-find-341-malicious-clawhub.html

  7. Koi Security -- "ClawHavoc: 341 Malicious Skills Report" https://www.koi.ai/blog/clawhavoc-341-malicious-clawedbot-skills-found

  8. Cisco Blogs -- "Personal AI Agents Are a Security Nightmare" https://blogs.cisco.com/ai/personal-ai-agents-like-openclaw-are-a-security-nightmare

  9. The Register -- "OpenClaw Ecosystem Security Issues" https://www.theregister.com/2026/02/02/openclaw_security_issues/

  10. VentureBeat -- "OpenClaw Agentic AI Security Risk CISO Guide" https://venturebeat.com/security/openclaw-agentic-ai-security-risk-ciso-guide/

 

Comments


bottom of page