HomeNewsClawdbot surge: exposed gateways, zero-auth risks and runaway token costs alarm users...

Clawdbot surge: exposed gateways, zero-auth risks and runaway token costs alarm users now!

-

Clawdbot, an open-source AI assistant released in January, lets users browse the web, run commands, manage files and place phone calls through common messaging apps. The tool has rapidly gained attention on developer channels and promises automation by connecting models to real-world actions via a local gateway (the project’s code on GitHub).

The system preserves user context on-device and supports WhatsApp, Telegram, Discord, Slack, Signal and iMessage, according to developer reports (developer Dan Peguine wrote). One user said it even completed a restaurant booking by calling a venue when an API failed (Alex Finn wrote).

Security researchers warn that some deployments left gateways exposed. A Shodan scan found open ports, and researcher Luis Catacora wrote _”Clawdbot gateways are exposed right now with zero auth… That means shell access, browser automation, API keys.”_ (Ed. note: the default binding can be changed to local and restarted.)

Responders advise restricting network access, adding authentication, rotating keys, and adding logging and rate limits, as outlined in a recommended response (stated here) and the project’s security guide. Users also report high token use; one account burned 180 million tokens in a week (reported), and another developer spent about $300 in two days.

Clawdbot was built by Peter Steinberger, founder of PSPDFKit (now Nutrient), aiming to deliver a continuously running personal assistant.

LEAVE A REPLY

Please enter your comment!
Please enter your name here

LATEST POSTS

Bitcoin Risk Grows as $60k Liquidity Gap Widens

Bitcoin's price declined to $65,800, raising concerns that last week's low near $60,000 may not be the market bottom. Analysts cite a growing liquidity gap...

Monad defies market downturn, rallies 13% amid social hype and rising TVL

The cryptocurrency Monad (MON) gained about 13% in 24 hours, outperforming a pressured broader market. The surge was attributed to a 140% spike in trading...

Robinhood stock plunges 12% after Q4 revenue misses estimates despite record $4.5B 2025…

Robinhood (HOOD) shares fell about 12% Wednesday after the trading platform reported fourth-quarter revenue that missed expectations. The company posted record 2025 revenue of $4.5...

Robinhood Chain Public Testnet Launches on Arbitrum

Robinhood has launched the public testnet for its financial-grade Ethereum Layer 2, Robinhood Chain, built on Arbitrum technology. The network is designed to support tokenized...

Most Popular

spot_img