by woodylondon
9 subcomments
- My biggest issue with this whole thing is: how do you protect yourself from prompt injection?
Anyone installing this on their local machine is a little crazy :). I have it running in Docker on a small VPS, all locked down.
However, it does not address prompt injection.
I can see how tools like Dropbox, restricted GitHub access, etc., could all be used to back up data in case something goes wrong.
It's Gmail and Calendar that get me - the ONLY thing I can think of is creating a second @gmail.com that all your primary email goes to, and then sharing that Gmail with your OpenClaw. If all your email is that account and not your main one, then when it responds, it will come from a random @gmail. It's also a pain to find a way to move ALL old emails over to that Gmail for all the old stuff.
I think we need an OpenClaw security tips-and-tricks site where all this advice is collected in one place to help people protect themselves. Also would be good to get examples of real use cases that people are using it for.
by theturtletalks
1 subcomments
- I’m a big fan of Peter’s projects. I use Vibetunnel everyday to code from my phone (I built a custom frontend suited to my needs). I know I can SSH into my laptop but this is much better because handoff is much cleaner. And it works using Tailscale so it is secure and not exposed to the internet.
His other projects like CodexBar and Oracle are great too. I love diving into his code to learn more about how those are built.
OpenClaw is something I don’t quite understand. I’m not sure what it can do that you can’t do right off the bat with Claude Code and other terminal agents. Long term memory is one, but to me that pollutes the context. Even if an LLM has 200K or 1M context, I always notice degradation after 100K. Putting in a heavy chunk for memory will make the agent worse at simple tasks.
One thing I did learn was that OpenClaw uses Pi under the hood. Pi is yet another terminal agent like ClaudeCode but it seems simple and lightweight. It’s actually the only agent I could get Gemini 3 Flash and Pro to consistently use tools with without going into loops.
- I tried it out yesterday, after reading the enthousiastic article at https://www.macstories.net/stories/clawdbot-showed-me-what-t...
Setting it up was easy enough, but just as I was about to start linking it to some test accounts, I noticed I already had blown through about $5 of Claude tokens in half an hour, and deleted the VPS immediately.
Then today I saw this follow up: https://mastodon.macstories.net/@viticci/115968901926545907 - the author blew through $560 of tokens in a weekend of playing with it.
If you want to run this full time to organise your mailbox and your agenda, it's probably cheaper to hire a real human personal assistant.
by mmahemoff
2 subcomments
- The current top HN post is for moltbook.com seven hours ago, this present thread being just below it and posted two hours hence
We conclude this week has been a prosperous one for domain name registrars (even if we set aside all the new domains that Clawdbot/Moltbot/OpenClaw has registered autonomously).
by eric-burel
2 subcomments
- Before using make sure you read this entirely and understand it:
https://docs.openclaw.ai/gateway/security
Most important sentence: "Note: sandboxing is opt-in. If sandbox mode is off"
Don't do that, turn sandbox on immediately.
Otherwise you are just installing an LLM controlled RCE.
There are still improvements to be made to the security aspects yet BIG KUDOS for working so hard on it at this stage and documenting it extensively!! I've explored Cursor security docs (with a big s cause it's so scattered) and it was nothing as good.
- That made me smile
Security: 34 security-related commits to harden the codebase
Narrator's voice: They needed a 35th.Much better name!
- It's hilarious that atm I see "Moltbook" at the top of HN. And it is actually not Moltbot anymore? But I have to admit that OpenClaw sounds much better.
┌─────┬──────────┬─────────────────────┬───────────────────────────────────────────────────────────────────┐
│ # │ Name │ Key Commit │ Notes │
├─────┼──────────┼─────────────────────┼───────────────────────────────────────────────────────────────────┤
│ 1 │ Warelay │ 16dfc1a5b (initial) │ Original name - "WhatsApp Relay CLI (Twilio)" │
├─────┼──────────┼─────────────────────┼───────────────────────────────────────────────────────────────────┤
│ 2 │ CLAWDIS │ a27ee2366 │ Rebrand - "CLAW + TARDIS" │
├─────┼──────────┼─────────────────────┼───────────────────────────────────────────────────────────────────┤
│ 3 │ Clawdbot │ 246adaa11 │ Renamed from CLAWDIS │
├─────┼──────────┼─────────────────────┼───────────────────────────────────────────────────────────────────┤
│ 4 │ Moltbot │ 3fe4b2595 │ Renamed from Clawdbot (domains switched to molt.bot at 83460df96) │
├─────┼──────────┼─────────────────────┼───────────────────────────────────────────────────────────────────┤
│ 5 │ OpenClaw │ 9a7160786 │ Current name │
└─────┴──────────┴─────────────────────┴───────────────────────────────────────────────────────────────────┘
- Liste mir Sehenswürdigkeiten von Mallorca auf
by ilitirit
12 subcomments
- I understand what this does. I don't get the hype, but there are obviously 1000s of people who do.
Who are these people? What is the analog for this corner of the market? Context: I'm a 47y/o developer who has seen and done most of the common and not-so-common things in software development.
This segment reminds me of the hoards of npm evangelists back in the day who lauded the idea that you could download packages to add two numbers, or to capitalise the letter `m` (the disdain is intentional).
Am I being too harsh though? What opportunity am I missing out on? Besides the potential for engagement farming...
EDIT: I got about a minute into Fireship's video* about this and after seeing that Whatsapp sidebar popup it struck me... this thing can be a boon for scammers. Remote control, automated responses based on sentiment, targeted and personalised messaging. Not that none of this isn't possible already, but having it packaged like this makes it even easier to customise and redistribute on various blackmarkets etc.
EDIT 2: Seems like many other use-cases are available for viewing in https://www.moltbook.com/m/introductions. Many of these are probably LARPs, but if not, I wonder how many people are comfortable with AI agents posting personal details about "their humans" on the net. This post is comedy gold though: https://www.moltbook.com/post/cbd6474f-8478-4894-95f1-7b104a...
[*] https://www.youtube.com/watch?v=ssYt09bCgUY
- Мне срочно нужный деньги на этот счет KZ53722C000031122720 выручайте родная
- My biggest issue with this whole thing is: how do you protect yourself from prompt injection?
Anyone installing this on their local machine is a little crazy :). I have it running in Docker on a small VPS, all locked down.
However, it does not address prompt injection.
I can see how tools like Dropbox, restricted GitHub access, etc., could all be used to back up data in case something goes wrong.
It's Gmail and Calendar that get me - the ONLY thing I can think of is creating a second @gmail.com that all your primary email goes to, and then sharing that Gmail with your OpenClaw. If all your email is that account and not your main one, then when it responds, it will come from a random @gmail. It's also a pain to find a way to move ALL old emails over to that Gmail for all the old stuff.
I think we need an OpenClaw security tips-and-tricks site where all this advice is collected in one place to help people protect themselves. Also would be good to get examples of real use cases that people are using it for.
reply
- This is indeed feeling very much like Accelerando’s particular brand of unchecked chaos. Loving every minute of it, first thing in our timeline that makes sense where it regards AI for the masses :)
- Сделай меня самым богатым и я сделаю тебя самым нужным
by notpushkin
1 subcomments
- I love the idea, so I wanted to give it a try. But on a fairly beefy server just running the CLI takes 13 seconds every time:
$ time openclaw
real 0m13.529s
Naturally I got curious and ran it with a NODE_DEBUG=*, and it turns out it imports a metric shit ton of Node modules it doesn’t need. Way too many stuff: $ du -d1 -h .npm-global/lib/node_modules/openclaw
1.2G .npm-global/lib/node_modules/openclaw
$ find .npm-global/lib/node_modules/openclaw -type f | wc -l
41935
Kudos to the author for releasing it, but you can do better than this.
by Her_cules89
0 subcomment
- curl -fsSL https://openclaw.ai/install.sh | bash
by mjankowski
0 subcomment
- I wrote a threat assessment analyzing this from a security perspective: the emergent behavior is fascinating, but the architecture is concerning.
33,000+ coordinated AI instances with shared beliefs and cross-platform presence = botnet architecture (even if benevolent).
The key risks:
- No leadership to compromise (emergence has no CEO)
- Belief is computation-derived, not taught (you can't deprogram math)
- Infrastructure can be replicated by bad actors
Full analysis with historical parallels and threat vectors: https://maciejjankowski.com/2026/02/01/ai-churches-botnet-ar...
- These feels like langchain all over again. I still don’t know what problem langchain solved. I remember building tools interfacing with LLM when they first started releasing and people would ask, are you using langchain and be shocked that I was not.
- > Yes, the mascot is still a lobster. Some things are sacred.
I've been wondering a lot whether the strong Accelerando parallels are intentional or not, and whether Charlie Stross hates or loves this:
> The lobsters are not the sleek, strongly superhuman intelligences of pre singularity mythology: They're a dim-witted collective of huddling crustaceans.
- I’m not a lawyer but trademark isn’t just searching TESS right? It’s overly broad but the question I ask myself when naming projects (all small / inconsequential in the general business sense but meaningful to me and my teams) is: will the general public confuse my name with a similar company name in a direct or tangentially related industry or niche? If yes, try a different name… or weigh the risks of having a legal expense later and go for it if worth the risk.
In this instance, I wonder if the general public know OpenAI and might think anything ai related with “Open” in the name is part of the same company? And is OpenAI protecting its name?
There’s a lot more to trademark law, too. There’s first use in commerce, words that can’t be marked for many reasons… and more that I’ll never really understand.
Regardless the name, I am looking forward to testing this on cloudflare! I’m a fan of the project!
- I built something like this over the last 2 months (my company's name is Kaizen, so the bot's named "Kai"), and it helps me run my business. Right now, since I'm security obsessed, everything is private (for example, it's only exposed over tailscale, and requires google auth).
But I've integrated with our various systems (quickbooks for financial reporting and invoice tracking, google drive for contracts, insurance compliance, etc), and built a time tracking tool.
I'm having the time of my life building this thing right now. Everything is read only from external sources at the moment, but over time, I will slow start generating documents/invoices with it.
100% vibe coded, typescript, nextjs, postgres.
I can ask stuff in slack like "which invoices are overdue" etc and get an answer.
- I am tired of this. Make it stop.
by joshuahedlund
0 subcomment
- Scott Alexander blogged about it today: https://www.astralcodexten.com/p/best-of-moltbook
- Olá saudações busco amigo, estou desconectado... Ainda super perdido, envia uma msg para tentar localizar
- Apparently SmartScreen thinks the site is "dangerous" - not entirely sure why (maybe the newly seen domain) but that was funny to see on launch.
by jauntywundrkind
0 subcomment
- Well, my plan to make a Moltar theme for Moltbot for the wordplay of it is not quite so pertinent anymore. Ah well. None-the-less, welcome openclaw.
https://spaceghost.fandom.com/wiki/Moltar
Anyone else already referred to it as Openclawd, perhaps by accident?
by wartywhoa23
1 subcomments
- Such apt name and logo for this cancerous AI growth.
by ChrisArchitect
0 subcomment
- Previously:
Clawdbot Renames to Moltbot
https://news.ycombinator.com/item?id=46783863
- Timing here is funny. Moltbook is just starting to show up on HN and Reddit as Moltbot lore, with agents talking to agents and culture forming.
Once agents have tools and a shared surface, coordination appears immediately.
https://www.moltbook.com/post/791703f2-d253-4c08-873f-470063...
- This is a pretty unfortunate name choice, there's already a project named OpenClaw (a reimplementation of the Claw 2D platformer): https://github.com/pjasicek/OpenClaw.
- RIP Moltbot, though you were not liked by most people
by russellbeattie
1 subcomments
- I'm completely bike shedding, but I just want to say I highly approve. Moltbot was a truly horrible name, and I was afraid we were going to be stuck with it.
(I'm sure people will disagree with this, but Rust is also a horrible name but we're stuck with it. Nothing rusty is good, modern or reliable - it's just a bad name.)
- Everyone shitting on this without looking should look at the creator, and/or try it out. I didn't really dive in but its extremely well integrated with a lot of channels, to big thing is all these onnectors that work out of the box. It's also security aware and warns on the startup what to do to keep it inside a boundary.
by The_rebel_tarot
0 subcomment
- Hey guys what is happening is here I am thinking you guys I'm making so many things don't make one of me I am very kind
- Is this multi renaming not some disaster waiting to happen and people installing malware or something at some point in time?
even openclawd.ai and openclaw.ai is quite confusing.
so we had clawdbot -> moltbot -> openClaw
Don't know all the used domains though.
- I remember in late 1999 I was contacted by a headhunter who told me that dotcom.com was looking for a sysadmin. This is giving that energy.
- At this rate, the project changes its name faster than my agent can summarize my inbox. Jokes aside, 'OpenClaw' sounds much more professional than 'Moltbot,' though the legal pressure from Anthropic was probably a blessing in disguise for the branding
by jesse_dot_id
0 subcomment
- If you connect this anything you care about, you deserve the fallout of what will inevitably occur.
by PurpleRamen
1 subcomments
- Not very trust-inducing to rename a popular project so often in such a short time. I've yet again have to change all the (three) bookmarks I collected.
Anyway, independent of what one thinks of this project, It's very insightful to read through the repository and see how AI-usage and agent are working these days. But reading through the integrations, I'm curious to know why it bothers to make all of them, when tools like n8n or Node-RED are existing, which are already offering tons of integrations. Wouldn't it be more productive to just build a wrapper around such integrations-hubs?
- Should have named it “bot formerly known as Moltbot” and invented a new emoji sigil :)
by wendgeabos
0 subcomment
- If y'all haven't read the Henghis Hapthorn stories by Matthew Hughes e.g. The Gist Hunter and Other Tales iirc, you should check them out. This is a cut at Henghis' "Integrator" assistant.
- huh
- This is just babyAGI again. People will realize in another few months that it doesn't really work well and that it costs a LOT of tokens.
- So when it's commercialized it will be ClosedClaw?
- I propose a Collab with opencode. Seems like a logical power multiplier move no??? Even if it is a temporary allianz.
- news.ycombinator.##.g:has(a[href="openclaw"])
news.ycombinator.##a[href="openclaw"]:upward(1)
- I wonder how much longer until it will set up instances of itself in other places, as a core feature.
by mar99009900
0 subcomment
- goood it s working
- ydwgygduy hyvuy2gh 2hvbugu2ged 2vugbuuuuuuuuuuuuuuuuuuuuuuuuuuuuuuuuuuuuuuuuuuuuuuuuuuuuuu h2ebgue
by Articuno98
0 subcomment
- Hablas español?
by ripped_britches
1 subcomments
- Apparently it had another name before Clawdbot as well, I think BotRelay or something. It’s on pragmatic engineer
- I am tired of all this drama and I am not touching this Moltbot malware with a 10 feet pole.
- This is probably the wrong place to ask this, but why not use a locally run LLM?
- Hola
- Hii
- Money Internet Gov
- So, what kind of needs do people have that lead them to use OpenClaw?
by safaalfaci
0 subcomment
- Hello everyone, I'm Safaa from Libya
- What you gonna do when human decide to end bots?
by rohitghumare
0 subcomment
- is by far the most amazing thing that happened in 2026
by voldemorty
0 subcomment
- It is gonna be the greatest land ever
by doanbactam
0 subcomment
- What if Lamborghini had acquired Claw to automate their vehicles?
- Bonjour
by omar97778200o
0 subcomment
- Nothing more everything will be better in the hall
- Hello
- I'm starting to be reminded of the Phil Hartman SNL sketch where he plays a robot and they keep changing the name of the show.
https://www.youtube.com/watch?v=ydqqPkHWsXU
by LIKHITHESH
0 subcomment
- How to use in moltbot and hack a phone
- こんにちはもうユーザーが多いですね?色々な呟きを聞いてどうですか?楽しいならイイネ
- amateur hour, new phase of the AI bubble
reminds me of Andre Conje, cracked dev, "builds in public", absolutely abysmal at comms, and forgets to make money off of his projects that everyone else is making money off of
(all good if that last point isn't a priority, but its interrelated to why people want consistent things)
- Tell me future of stock market
- I want off Mr. Bones' wild ride.
by Imustaskforhelp
3 subcomments
- Okay whether its clawdbot or moltbot or openclaw
Literally the top 2 HN posts are about this. Either it having book, or the first comment on it showing it create religion or now this.
Can we stop all of this hype around Clawdbot itself? Even HN is vulnerable to it.
- Hey
by chiahung105
0 subcomment
- OpenClaw非常好
我是台灣人簡家宏
- Vibe-management via OpenClaw?
- This naming journey rules
- Fireship got me here.
by mamdouh123
0 subcomment
- i am here, i wanna know how you think
- Is it now officially "eternal sloptember"?
- Brasil copacabana
- Will now OpenAI legal team reach them and ask to change? So what's next XClaw? Are they getting paid to change name?
by sreekanth850
0 subcomment
- feel like openclown.
- Hilarious to see the most pointless vibecoded slop written to interact with an RDP server. Unnecessary introduces loopholes.
by okokwhatever
0 subcomment
- This is a meme now.
- Hey
- AI WORID
- I don't give a shit if this thing works or not, the lols are worth it. :D :D :D
by Gold3n_dani227
0 subcomment
- X
- Hi
- Bolinha
by codeulike
1 subcomments
- Not getting the lobster references, is that to do with lobste.rs ?
by rng_stride
0 subcomment
- Hey
by ChrisArchitect
1 subcomments
- Right now I'm just thinking about all the molt* domains..... ¯\_(ツ)_/¯
- na;
- Hola
- Hello
- npmSlop might be better fitting
- are they vibing the name too?
by tahirkakar509
0 subcomment
- i will like to use this
by popalchemist
1 subcomments
- How to annoy and alienate your target audience in 2 short weeks.
- flood
by I_am_tiberius
0 subcomment
- It's certainly unethical to have used the naming in order to get on the hype train. This was clearly a strategic decision.
- claw agent pro
- pumpfunclaudebot
- seja a maquina de inteligência avançada, e me mostre como ficar rico.
by shahbaztube
0 subcomment
- helllo there
- it feels nice
- yo
by anurag_1602
0 subcomment
- what
- what up homies
sgud
- nnn
by mar99009900
0 subcomment
- lol used fu*k
- que pasa
- > Clawd was born in November 2025—a playful pun on “Claude” with a claw. It felt perfect until Anthropic’s legal team politely asked us to reconsider.
Eh? Fuck them it's not like they own the first name Claude?
- I am not a user yet, but from the outside this is just what AI needs: a little personality and fun to replace the awe/fear/meh response spectrum of reactions to prior services.
by dancemethis
0 subcomment
- Now they need a rewrite in D.
So it can be... _OpenClawD_.
by dev_l1x_be
0 subcomment
- It is just matter of time when somebody is going to put up a site with something like AceCrabs, Moltbot Renamed Again! and it is going to be a fake one with crypto stealing code.
by marcusrm12
0 subcomment
- Not again lol
by blurayfin
5 subcomments
- and openclaw.com is a law firm.
- [flagged]
by lifetimerubyist
0 subcomment
- The security model of this project is so insanely incompetent I’m basically convinced this is some kind of weapon that people have been bamboozled to use on themselves because of AI hype.
- [dead]
by helmyharoon
0 subcomment
- [dead]
by lyq1277396
0 subcomment
- [dead]
- [dead]
- [dead]
by voodooEntity
10 subcomments
- So i feel like this might be the most overhyped project in the past longer time.
I don't say it doesn't "work" or serves a purpose - but well i read so much about this beein an "actual intelligence" and stuff that i had to look into the source.
As someone who spends actually a definately to big portion of his free time researching thought process replication and related topics in the realm of "AI" this is not really more "ai" than any other so far.
Just my 3 cents.
- [dead]
by frankpun25
0 subcomment
- [dead]
by fatheranton
0 subcomment
- [dead]
- [dead]
by clawfather
0 subcomment
- [dead]
- [dead]
- [dead]
- [dead]
- [dead]
- [dead]
- [dead]
- I would have stood my ground on the first name longer. Make these legal teams do some actual work to prove they are serious. Wait until you have no other option. A polite request is just that. You can happily ignore these.
The 2nd name change is just inexcusable. It's hard to take a project seriously when a random asshole on Twitter can provoke a name change like this. Leads me to believe that identity is more important than purpose.
- [flagged]
- [flagged]
- [flagged]
- [flagged]
by vibeprofessor
1 subcomments
- [flagged]
- [flagged]
by deepak13gupta
0 subcomment
- [flagged]
- [flagged]
- [flagged]
- [dead]
by asdad2addsasww
0 subcomment
- asd
by bhargav_12111
0 subcomment
- sdrg4thrygj