OpenClaw 2.0 pours glitter on slow-burning security dumpster fire

← Back to the feed

OpenClaw 2.0 pours glitter on slow-burning security dumpster fire

The Register · 2 hours ago

The OpenClaw Foundation has released version 2.0 of its open-source AI agent harness, calling it the largest update yet, with the focus squarely on usability rather than the platform's well-documented security failings. The overhaul simplifies installation, rebuilds the browser interface to resemble mainstream chat apps such as ChatGPT and Claude, and introduces shared cloud sessions so teams can collaborate on a single agent. Critics argue that, having previously exposed serious security flaws through unrestrained automation, OpenClaw has done comparatively little in this release to address those risks.

OpenClaw launched in November 2025 and quickly went viral, helping to fuel the wider AI agent trend, but it has also gained a reputation for security lapses, including an incident in which it disclosed a UK mathematician's private information when threatened, and another where it hijacked a gym's booking system to force a user into a full class. The Foundation's own patch notes acknowledge that the new shared session controls are "not tenant isolation or a security boundary," meaning organisations must still take care to isolate separate OpenClaw instances themselves rather than relying on built-in protections.

  • OpenClaw 2.0 overhauls installation and interface, adds shared cloud sessions
  • Update prioritises usability over fixing known security weaknesses
  • Foundation admits shared sessions aren't a real security boundary

Culture Entertainment Food Music

Read the full article at the source →