Within weeks of the open-source AI agent framework OpenClaw going viral, security researchers disclosed a critical remote-code-execution vulnerability (CVE-2026-25253, CVSS 8.8) in its Control UI that could hijack an instance’s gateway even when bound to localhost. Separately, scans found between roughly 21,000 and 42,600 OpenClaw instances publicly exposed across more than 50 countries, the vast majority with authentication bypass conditions, while a supply-chain campaign dubbed “ClawHavoc” seeded hundreds of malicious skills into the project’s marketplace to deliver infostealer malware. The RCE flaw was patched within days of disclosure.