HomeNewsClawdbot surge: exposed gateways, zero-auth risks and runaway token costs alarm users...

Clawdbot surge: exposed gateways, zero-auth risks and runaway token costs alarm users now!

-

Clawdbot, an open-source AI assistant released in January, lets users browse the web, run commands, manage files and place phone calls through common messaging apps. The tool has rapidly gained attention on developer channels and promises automation by connecting models to real-world actions via a local gateway (the project’s code on GitHub).

The system preserves user context on-device and supports WhatsApp, Telegram, Discord, Slack, Signal and iMessage, according to developer reports (developer Dan Peguine wrote). One user said it even completed a restaurant booking by calling a venue when an API failed (Alex Finn wrote).

Security researchers warn that some deployments left gateways exposed. A Shodan scan found open ports, and researcher Luis Catacora wrote _”Clawdbot gateways are exposed right now with zero auth… That means shell access, browser automation, API keys.”_ (Ed. note: the default binding can be changed to local and restarted.)

Responders advise restricting network access, adding authentication, rotating keys, and adding logging and rate limits, as outlined in a recommended response (stated here) and the project’s security guide. Users also report high token use; one account burned 180 million tokens in a week (reported), and another developer spent about $300 in two days.

Clawdbot was built by Peter Steinberger, founder of PSPDFKit (now Nutrient), aiming to deliver a continuously running personal assistant.

LATEST POSTS

Trump Nominates Kevin Warsh as Fed Chair, Aiming for Rate Cuts Amid Senate Pushback

President Donald Trump has nominated Kevin Warsh to replace Jerome Powell as Federal Reserve Chair, a move that follows months of Trump criticizing Powell's interest...

Bitcoin briefly reclaims $74k on crypto legislation hopes, momentum uncertain

Bitcoin briefly reclaimed the $73,952 level today, sparking a 5.6% 24-hour gain and lifting broader market sentiment. According to data from CoinGecko, this marks an...

Eric Trump Slams Banks’ “Anti-American” Opposition to Stablecoin Yields

Eric Trump criticized major banks for opposing stablecoin yield offerings, calling their stance "anti-retail, anti-consumer, and anti-American." This comes as the crypto industry's rift with...

Solana Reclaims Then Dips From $94; 24-Hour Gain Holds at 6%

Solana (SOL) reclaimed the $93.71 level before retreating to $90.61 as the broader crypto market rallied. According to CoinGecko data, SOL's price rose 6% in...

Most Popular

spot_img