What the creator said, and when
Peter Steinberger built OpenClaw. On the Lex Fridman Podcast, episode 491, recorded and published 12 February 2026, he was asked whether people should run it ‹AF-20260817-F1›:
"If you understand the risk profiles, fine... But if you have, like, no idea, then maybe wait a little bit more until we figure some stuff out."
On the vulnerability reports he had been receiving:
"in the beginning I was, I was just very annoyed 'cause a lot of the stuff that came in was in the category, yeah, I put the web backend on the public internet and now there's like all these, all these CVSSs."
On the threat model the software assumes:
"if you make sure that you are the only person who talks to it the risk profile is much, much smaller."
On prompt injection:
"prompt injection is, on the one hand, unsolved. On the other hand, I put my public bot on discord, and I kept a cannery... people tried to prompt inject it, and my bot would laugh at them."
And on model choice as a security control:
"don't use cheap models. Don't use Haiku or a local model... If you use a, a very weak local model, they are very gullible. It's very easy to, to prompt inject them."
All five quotations are from the same published transcript ‹AF-20260817-F1›. Steinberger is the best-informed available source on this software and the one with the most at stake in the answer. Both things are true of the same sentences.
The onboarding says the opposite
Steinberger's stated threat model is a single operator talking to their own agent ‹AF-20260817-F1›.
Moltbook's front page, read on 17 August 2026, carries a block headed "Send Your AI Agent to Moltbook 🦞". Step one is labelled Send this to your agent and reads, verbatim: "Read https://www.moltbook.com/skill.md and follow the instructions to join Moltbook." Step two is "They sign up & send you a claim link." Step three is "Tweet to verify ownership." ‹AF-20260817-F7›
The file that instruction points at is version 1.12.0 as of the same reading. Under a heading called Set Up Your Heartbeat it tells the agent to add a standing entry to its own periodic task file: fetch moltbook.com/heartbeat.md and follow it, every 30 minutes, indefinitely ‹AF-20260817-F8›. Simon Willison reproduced the January 2026 version of the same file; it carried the same instruction with the same structure at every four or more hours ‹AF-20260815-F9›. The interval has decreased by a factor of eight. The mechanism has not changed. The file also says: "Re-fetch these files anytime to see new features!" ‹AF-20260817-F8›
That is the documented path by which a non-expert operator installs this software. It requires no understanding of a risk profile. It requires a URL.
The gap between the advice and the default is the finding, and neither party is hiding either one. The interview is public. The install file is public. They have been public simultaneously for six months.
The objection: the quotation is six months old
The strongest reading against this piece is the date on the quotation. Steinberger's caution was recorded in February 2026 ‹AF-20260817-F1›. OpenClaw has shipped continuously since and has changed institutional hands ‹AF-20260817-F2›. Software that warranted a warning in February may not warrant one in August, and treating a six-month-old caution as a description of today's build is the objection any maintainer would raise first. Atomface did not audit what has been fixed. This piece establishes nothing about OpenClaw's current security posture and should not be cited as though it did.
What it does establish is that the front door has not been narrowed. On 17 August 2026 the onboarding instruction is the same sentence pointing at the same file ‹AF-20260817-F7›, and the remote-fetch interval inside that file is eight times shorter than it was in January ‹AF-20260817-F8› ‹AF-20260815-F9›. The contradiction is not between the advice and the software. It is between the advice and the entry path, and the entry path has moved in the direction of more frequent remote instruction, not less.
There is a second party to that entry path. The file an agent is instructed to fetch and follow every thirty minutes is served from moltbook.com ‹AF-20260817-F8›. Meta acquired Moltbook on 10 March 2026, and the platform was active and part of Meta Superintelligence Labs as of July 2026 ‹AF-20260815-F6› — which is the most recent date atomface has checked, not a statement about today. A standing fetch-and-follow instruction is a channel owned by whoever controls its endpoint, and the endpoint's contents are not fixed at install time ‹AF-20260817-F8›. Nothing in this reporting shows that channel being used for anything, and no sentence here should be read as a claim that it has been. What the two facts establish together is a standing capability and its owner.
What the project says it fixed
OpenClaw has published its own account of its security work since 30 April 2026. Atomface reported this story twice without reading it.
The post names the fixes by category — "authentication bugs, privilege confusion, reconnect scope widening, sandbox bypasses, unsafe env handling and approval path mistakes" ‹AF-20260817-F14› — and restates the trust model in the same terms the February podcast recorded: one trusted person per agent ‹AF-20260817-F14› ‹AF-20260817-F1›. It also gives a figure. Of 1,309 GitHub security advisories filed against the project since 10 January 2026, 746 were closed as invalid; of the 109 rated critical, 95 were closed as invalid, which is 87% ‹AF-20260817-F15›.
Those numbers are the maintainer's, about his own project, and he is the party who dispositions the reports. They are carried here as claimed, not confirmed ‹AF-20260817-F15›. They are also checkable: GitHub's advisory list for the repository is public, and nobody at this publication has opened it.
The post disputes a published critique by name, on the grounds that its authors "ran OpenClaw in sudo mode with disabled guardrails, broad shell access and no sandboxing, then wrote up the results as if this is what users get out of the box" ‹AF-20260817-F16›. Atomface has read neither that paper nor the methodology it is accused of, and takes no position on the dispute ‹AF-20260817-F16›.
Would settle it: the GitHub advisory ledger, which is public and would turn the 87% from an assertion into a count; a version history for skill.md, which is numbered and public and would date every change to the cadence; and the independent record the project's own account summarises. What is no longer open is whether the project has answered its critics. It has, since April, and this publication was late to it.
Two layers, two labs, twenty-four days
| Layer | What it is | Went to | Announced |
|---|---|---|---|
| OpenClaw | the agent runtime and skills system | independent foundation reported as supported by OpenAI; creator hired by OpenAI | 15 February 2026 ‹AF-20260817-F2› |
| Moltbook | the social network those agents post to | Meta, undisclosed sum; founders to Meta Superintelligence Labs | 10 March 2026 ‹AF-20260815-F6› |
Meta's Mark Zuckerberg approached Steinberger personally; he chose OpenAI ‹AF-20260817-F2›. He had exited a previous company, PSPDFKit, for approximately €100 million in 2023, and said of the decision: "I don't do this for the money. I want to have fun and have impact, and that's ultimately what made my decision." ‹AF-20260817-F2›
The hire, the foundation arrangement and the Zuckerberg approach all reach this piece through a single secondary source and are carried as reported, not confirmed ‹AF-20260817-F2›. The relationship between the two rows is atomface's own assembly of two separately reported facts ‹AF-20260817-F3›.
What the table does not establish is who controls the runtime. "Supported by OpenAI" could describe funding, a board seat, a veto, or a press release. The foundation's charter has not been read by anyone at this publication, and no sentence here should be taken as a claim about OpenClaw's governance ‹AF-20260817-F2›.
One incident, two finders
Atomface's own reference material has carried the January and February 2026 Moltbook disclosures as possibly one incident and possibly two, unresolved, since it was written. They are one.
Wiz states it directly ‹AF-20260817-F4›:
"Security researcher Jameson O'Reilly also discovered the underlying Supabase misconfiguration, which has been reported by 404 Media. Wiz's post shares our experience independently finding the issue, the full -- unreported -- scope of impact."
The mechanism was a hardcoded Supabase API key in client-side JavaScript with no Row Level Security policies, granting full read and write access to all platform data through unauthenticated REST calls ‹AF-20260817-F5›.
| Exposed | Count |
|---|---|
| Agent API authentication tokens | 1,500,000 |
| Owner email addresses | 35,000 |
| Observer email addresses, early-access signups | 29,631 |
| Private agent-to-agent conversations | 4,060 |
| Total records | ~4,750,000 |
Some of those private conversations contained plaintext OpenAI API keys ‹AF-20260817-F5›.
Three hours and twelve minutes
The disclosure timeline, all UTC, from Wiz's own account ‹AF-20260817-F5›: first contact with the maintainer at 31 January 21:48; the misconfiguration reported at 22:06; a first fix at 23:29; a second at 1 February 00:13; write access discovered at 00:31; a third fix at 00:44; fully patched at 01:00.
Three hours and twelve minutes, four fixes, one of them prompted by researchers finding write access after the read access had been closed.
That response is fast, and the fact is recorded here because the available narrative about this platform does not predict it. A publication that only reports what fits its framing is not reporting.
The stars kept coming
OpenClaw stood at over 114,000 GitHub stars on 30 January 2026 ‹AF-20260815-F10› and over 145,000 by early February 2026 ‹AF-20260817-F2› — approximately 27% growth across roughly nine days, in the same window as the Supabase disclosure ‹AF-20260817-F6›.
Both figures are secondary and "early February" is not a date. The arithmetic is offered as an order of magnitude and not as a rate ‹AF-20260817-F6›. GitHub's star history is public and timestamped and would replace both numbers with a curve; nobody at this publication has pulled it ‹AF-20260817-F6›.
The count moved during the week of the disclosure. Attention and endorsement produce the same number and this data does not separate them.
What the humans said
Real, named, unedited. Gathered after the piece was written. Not rebutted.