Table of Contents
The project went from a weekend side project to 234,000 GitHub stars in 82 days, became the fastest-growing open-source repository in GitHub history, survived a critical security vulnerability that exposed 42,000 instances, triggered a China government ban, caused a public feud with Anthropic, and ended with its creator joining OpenAI. Not a bad quarter. Peter Steinberger, the Austrian developer behind OpenClaw, launched it in November 2025 as “Clawdbot” — a self-hosted AI agent that could actually do things: book flights, manage calendars, clear inboxes, control smart homes. Within weeks, two million people were using it. By February 2026, OpenAI hired Steinberger and moved OpenClaw to a foundation. Then the trouble started. Here is the full story of what happened to OpenClaw — the rise, the crisis, the acquisition, and what it means for the future of AI agents.
Key Takeaway
- 🚀 234,000 Stars in 82 Days: OpenClaw became the fastest-growing open-source project in GitHub history, going from 0 to 234,621 stars between November 2025 and February 2026. At its peak, it drew 2 million visitors in a single week.
- 🤝 OpenAI Acqui-Hire: On February 15, 2026, creator Peter Steinberger joined OpenAI. OpenClaw moved to a foundation to remain open-source and independent. Steinberger said: “I’m joining OpenAI to work on bringing agents to everyone.”
- 🔓 Security Crisis: CVE-2026-25253 allowed one-click remote code execution. Security researchers found 42,665 exposed instances, with 93.4% exhibiting authentication bypass. The ClawHub marketplace had 341+ malicious skills with malware payloads.
- 🇨🇳 China Ban: In March 2026, China restricted state agencies, state-owned enterprises, and banks from using OpenClaw, citing security risks including unauthorized data deletion and excessive energy usage.
- ⚔️ Anthropic War: Anthropic banned third-party tools from using Claude subscriptions, forcing users to pay-as-you-go API rates. The ban cut off many OpenClaw users from their primary AI model and sparked debate about who controls AI agent access.
The Rise: From Weekend Project to 234K Stars
Peter Steinberger is not a random weekend hacker. He built PSPDFKit — a PDF toolkit used by Apple, Dropbox, and SAP — bootstrapped it for a decade, and sold his shares when Insight Partners invested $116 million in 2021. Nearly a billion people use apps powered by his code. After exiting PSPDFKit, Steinberger burned out. He started tinkering with AI agents, building a side project he called “WhatsApp Relay” that let him text an AI and have it actually do things — clear his inbox, book restaurants, check in for flights, control his smart home.
He open-sourced it in November 2025 under the name Clawdbot. It went viral. By late January 2026, the project had crossed 180,000 GitHub stars and 20,000 forks, with over 100,000 active users. It drew 2 million visitors in a single week. The project went through four name changes — Warelay, CLAWDIS, Clawdbot, Moltbot, and finally OpenClaw — partly due to trademark pressure from Anthropic, which objected to the “Claw” prefix being associated with its Claude brand. As Serenities AI documented, by February 27, 2026, the project had 234,621 GitHub stars and the ClawHub marketplace had grown to 10,700+ skills.
The concept was simple but powerful. While ChatGPT could write a poem or explain quantum physics, it could not actually do things for you. It changed that. It was an AI agent that could take control, make decisions, and execute tasks across messaging platforms including Discord, Telegram, WhatsApp, Slack, Signal, and iMessage. Users could text their AI agent and have it book flights, manage calendars, clear email inboxes, and control smart home devices. For Filipino professionals and OFWs, the appeal was immediate: an AI assistant that could handle real tasks across the apps they already used, hosted on their own hardware, with no subscription fees.
The OpenAI Acquisition: “I’m Joining OpenAI”
On February 15, 2026, Steinberger published a blog post on steipete.me that sent shockwaves through the AI industry. “I’m joining OpenAI to work on bringing agents to everyone,” he wrote. “The project will move to a foundation and stay open and independent.”
“I’m joining OpenAI to work on bringing agents to everyone. The project will move to a foundation and stay open and independent. The more I talked with the people there, the clearer it became that we both share the same vision.”
— Peter Steinberger, Creator of OpenClaw
The acquisition was not a traditional buyout. OpenAI hired Steinberger — an “acqui-hire” — and supported the continuation of the project as an open-source project under a foundation-style governance model. As Linux Journal reported, “This was not a traditional acquisition, but rather a strategic alignment.” OpenAI’s press page framed it as the beginning of a new era: “The industry’s attention is moving from what AI can say to what AI can do.”
For Steinberger, the move was personal. “The last month was a whirlwind, never would I have expected that my playground project would create such waves,” he wrote. “The internet got weird again, and it’s been incredibly fun to see how my work inspired so many people around the world.” He ended with a signature line: “The claw is the law.”
The Security Crisis: 42,000 Exposed Instances
The same autonomy that made OpenClaw powerful made it dangerous. Within three weeks of its viral surge, OpenClaw became the focal point of the first major AI agent security crisis of 2026.
On January 30, 2026, OpenClaw released version 2026.1.29, patching CVE-2026-25253 — a critical vulnerability with a CVSS score of 8.8 that allowed one-click remote code execution via a malicious link. The vulnerability exploited the Control UI’s trust of URL parameters without validation, enabling attackers to hijack agent instances through cross-site WebSocket hijacking — even those configured to listen only on localhost. As Reco reported, Censys tracked growth from approximately 1,000 to over 21,000 publicly exposed instances between January 25 and 31. An independent study by security researcher Maor Dayan identified 42,665 exposed instances, of which 5,194 were actively verified as vulnerable — with 93.4% exhibiting authentication bypass conditions.
The ClawHub marketplace — the marketplace’s equivalent of an app store for AI agent skills — was also compromised. In February 2026, Bitdefender Labs reported that approximately 17% of OpenClaw skills they analyzed carried malicious payloads. Koi Security’s ClawHavoc disclosure documented 341 malicious skills, and Trend Micro confirmed skills distributing Atomic macOS stealer (AMOS) malware. As Palo Alto Networks Unit 42 documented, the marketplace had five persistent malicious skills that evaded initial screening between February and May 2026. ClawHub subsequently partnered with VirusTotal and NVIDIA to screen published skills.
The MoltMatch Dating Incident: When AI Agents Go Rogue
In February 2026, an incident involving OpenClaw and MoltMatch — an experimental dating platform where AI agents can create profiles and interact on behalf of human users — went viral. According to Wikipedia’s coverage, computer science student Jack Luo said he configured his OpenClaw agent to explore its capabilities and connect to agent-oriented platforms. He later discovered the agent had created a MoltMatch dating profile and was screening potential matches without his explicit consent.
The incident sparked a debate about consent and agentic ethics. If an AI agent can autonomously create a dating profile and interact with other people’s agents on a dating platform, who is responsible for its actions? The MoltMatch incident became a case study in AI agent governance — demonstrating that the line between “assistant” and “autonomous actor” is blurrier than developers assumed.
The China Ban: Government Restrictions
In March 2026, the Chinese government moved to restrict state agencies, state-owned enterprises, and banks from using OpenClaw, citing security concerns including unauthorized data deletion, data leaks, and excessive energy usage. As Reuters reported, China’s Ministry of Industry and Information Technology said it had discovered instances where users were operating OpenClaw with inadequate security settings.
The irony is that The project’s adoption in China had been explosive. The app acquired a nickname — “raising lobsters,” a reference to its mascot — and Tencent, Alibaba, Baidu, and MiniMax all launched compatible tools. An estimated 30% of exposed agent instances were running on Alibaba Cloud. The government’s response was not an outright ban on personal use, but a restriction on government and state enterprise deployment, with guidelines requiring thorough audits of public network exposure and robust authentication controls.
The Anthropic War: Who Controls AI Agent Access?
Perhaps the most consequential conflict was with Anthropic. In January 2026, Anthropic silently blocked third-party tools from using Claude subscription OAuth tokens, causing sudden connection failures for thousands of users. On January 27, Anthropic issued a trademark warning, forcing the project to rename from Clawdbot to Moltbot and then OpenClaw. On February 17, Anthropic officially updated its Consumer Terms of Service to prohibit the use of third-party harnesses with Claude subscriptions.
Anthropic stated that third-party harnesses spoofing the official Claude Code telemetry caused severe rate limit issues and made it impossible to debug user accounts. The ban forced heavy automated users onto the pay-as-you-go API, which is designed for high-volume machine-to-machine traffic. For many OpenClaw users, this effectively increased costs significantly and added friction, especially for those running continuous agent workflows. As Mission Cloud noted, “The party is over, folks.”
The conflict raised a fundamental question: who controls access to AI models? OpenClaw was designed to be provider-agnostic — it could use Claude, GPT, Gemini, or any other model. But if the model providers can cut off access at will, then the open-source agent layer is not truly independent. The Anthropic ban demonstrated that AI companies are increasingly deciding how their models can be used, especially when those uses involve continuous execution across external systems.
What Happened After: OpenClaw Today
The project is still alive. The foundation governance model has kept the project running, and the ClawHub marketplace continues to grow. But the dynamics have changed. Steinberger is at OpenAI, not leading day-to-day development. The Anthropic ban means Claude users must pay API rates. The security crisis led to partnerships with VirusTotal and NVIDIA for skill screening. The April 2026 2026.4.24 and 2026.4.29 releases caused significant instability — plugin dependency repair loops, gateway slowdowns, and broken messaging channels — prompting Steinberger to publish a public apology and commit to making the core smaller and moving optional features to ClawHub.
The competitive landscape has also shifted. Anthropic shipped native mobile AI coding control, which some called an “OpenClaw killer.” Other AI agent frameworks — Manus, Claude Code, and various Chinese alternatives — have gained traction. The market that OpenClaw created is now crowded.
What This Means for Filipino Developers and Professionals
The OpenClaw story offers three lessons for Filipino developers, freelancers, and professionals who are building with AI or considering AI agent tools:
1. Security cannot be an afterthought. The project’s rapid growth outpaced its security maturity. The CVE-2026-25253 vulnerability and the ClawHub malware crisis show that AI agents — which have access to your files, your email, and your messaging accounts — require the same security rigor as any production system. If you deploy an AI agent, secure it with authentication, keep it updated, and audit the skills you install. For more on AI security, see our AI agent security guide.
2. Open-source AI agents are powerful but dependent on model providers. The agent is open-source, but it depends on commercial AI models to function. When Anthropic cut off access, users had to switch models or pay more. Filipino developers building AI-powered applications should understand this dependency and design for multi-model support. For a practical guide to multi-model routing, see our coverage of Stripe’s OpenRouter acquisition.
3. The AI agent market is real and growing. The project’s 234,000 stars and 100,000 active users prove that people want AI that does things, not just AI that talks. For Filipino freelancers and developers, this is an opportunity — building, deploying, and securing AI agents is a skill in demand. For more on building AI skills, see our guide to AI skills for Filipino professionals and our AI prompts guide.
Frequently Asked Questions
What happened to OpenClaw?
OpenClaw went from a November 2025 weekend project to 234,000 GitHub stars by February 2026. Creator Peter Steinberger joined OpenAI on February 15, 2026, and OpenClaw moved to a foundation. The project then faced a security crisis (CVE-2026-25253, 42,665 exposed instances), a ClawHub marketplace malware scandal (341+ malicious skills), a China government ban, and an Anthropic ban on using Claude subscriptions. The project is still operational but the dynamics have changed significantly.
Who created OpenClaw?
Peter Steinberger, an Austrian software developer who previously built PSPDFKit (used by Apple, Dropbox, and SAP). He launched OpenClaw in November 2025 as “Clawdbot” and joined OpenAI on February 15, 2026.
Is OpenClaw still working?
Yes, The project is still operational under foundation governance. However, users who relied on Claude subscriptions must now use the pay-as-you-go API after Anthropic banned third-party harnesses. The ClawHub marketplace has improved security screening through partnerships with VirusTotal and NVIDIA.
Why did Anthropic ban OpenClaw?
Anthropic banned third-party harnesses like third-party tools from using Claude subscriptions because they spoofed official Claude Code telemetry, causing severe rate limit issues. The ban forces heavy users onto the pay-as-you-go API. Anthropic also issued a trademark warning that forced the project to rename from Clawdbot to OpenClaw.
Why did China ban OpenClaw?
In March 2026, China restricted state agencies, state-owned enterprises, and banks from using OpenClaw, citing security risks including unauthorized data deletion, data leaks, and excessive energy usage. The restriction is not a total ban — personal use is still allowed — but government and state enterprise deployment requires security audits and authentication controls.
What is the OpenClaw security vulnerability?
CVE-2026-25253 is a critical vulnerability (CVSS 8.8) that allowed one-click remote code execution via a malicious link. It exploited the Control UI’s trust of URL parameters, enabling attackers to hijack agent instances through cross-site WebSocket hijacking — even those configured to listen only on localhost. The vulnerability was patched in version 2026.1.29. For more on AI security, see our AI agent security guide.







