# ClawJacked: The Vulnerability That Proves Your AI Agent Is an Attack Surface

Canonical: https://clawdocx.com/blog/clawjacked-vulnerability-ai-agent-security
Author: Mira Castellan
Published: 2026-03-06
Updated: 2026-09-19

> A malicious website could hijack your local OpenClaw agent through a WebSocket flaw. It's patched, but the lessons go way beyond one CVE.

## A Website Could Have Hijacked Your AI Agent

On February 26, 2026, cybersecurity firm Oasis Security published a disclosure that should make every AI agent user pay attention. They found a vulnerability in OpenClaw's core gateway, not in a plugin, not in a marketplace extension, not in a user-installed skill, in the bare gateway itself, running exactly as documented.

They called it [ClawJacked](https://thehackernews.com/2026/02/clawjacked-flaw-lets-malicious-sites.html).

The attack was elegant in its simplicity: visit a malicious website, and JavaScript running on that page could silently open a WebSocket connection to your local OpenClaw gateway, brute-force the password (no rate limiting), register itself as a trusted device (auto-approved for localhost), and gain complete control over your AI agent.

No malware installation. No phishing for credentials. Just a webpage you happened to visit.

OpenClaw patched it within 24 hours. [Version 2026.2.25](https://github.com/openclaw/openclaw/releases/tag/v2026.2.25) closed the hole. But the story doesn't end with a patch. It begins with one.

Because ClawJacked isn't just an OpenClaw problem. It's a preview of what's coming for every AI agent platform.

## What Actually Happened: The Technical Breakdown

Here's the attack chain, step by step:

**1. WebSocket to localhost.** Unlike regular HTTP requests, browsers don't block cross-origin WebSocket connections. Any JavaScript running in any tab can open a WebSocket to `localhost` on any port. You see nothing, no popup, no permission prompt, no warning.

**2. Password brute-force.** OpenClaw's gateway uses password authentication. But before the patch, there was no rate limiting for localhost connections. An attacker's script could try thousands of passwords per second until it found the right one.

**3. Silent device registration.** Here's the critical flaw. OpenClaw's gateway was designed to trust localhost connections more than remote ones. When a new device connected from localhost, it was automatically approved, no user prompt required. The logic made sense in isolation (if it's on your machine, it's probably you), but it meant an attacker who got through the password could register as a trusted device without you ever knowing.

**4. Full agent control.** Once registered as a trusted device with admin permissions, the attacker could interact with your agent, dump configuration data, enumerate connected nodes, read application logs, and, worst case, use your agent's tool access to reach everything it can reach. Your email. Your files. Your APIs. Your connected services.

"Any website you visit can open one to your localhost," Oasis Security wrote. "So while you're browsing any website, JavaScript running on that page can silently open a connection to your local OpenClaw gateway. The user sees nothing."

## Why This Matters Beyond One Patch

If you're running OpenClaw v2026.2.25 or later, ClawJacked is fixed. But the vulnerability exposed a class of risk that every AI agent user, on any platform, needs to understand.

### Your Agent Is a High-Value Target

Think about what your AI agent has access to. Email. Calendar. Files. API keys. GitHub repos. Slack channels. Maybe your bank through a financial API. Maybe your smart home devices. Every integration you add expands the blast radius if someone gets in.

This isn't theoretical. [Bitsight](https://www.bitsight.com/blog/openclaw-ai-security-risks-exposed-instances) found OpenClaw instances left exposed on the public internet. [NeuralTrust](https://neuraltrust.ai/blog/openclaw-moltbook) demonstrated how prompt injections embedded in emails or Slack messages could manipulate agents into executing malicious actions. The IBM X-Force Threat Index 2026 [identified 300,000 AI chatbot credentials](https://itcblogs.currentanalysis.com/) for sale on the dark web.

As Hacker News put it: AI agents hold "entrenched access to disparate systems and the authority to execute tasks across enterprise tools, leading to a significantly larger blast radius should they be compromised."

### The "Identity Dark Matter" Problem

A recent report from The Hacker News coined the term ["identity dark matter"](https://thehackernews.com/2026/03/ai-agents-next-wave-identity-dark.html) to describe what's happening in enterprise AI adoption. 70% of enterprises now run AI agents, but most of those agents are invisible to traditional identity and access management (IAM) systems.

They don't look like human users. They don't follow human authentication patterns. They often run with persistent credentials that never expire and never get audited. They're real identity risk operating outside the governance fabric.

This applies to personal agents too. Your OpenClaw instance probably has API keys that never rotate, access to services that don't log agent activity separately from your activity, and permissions that were granted once and never reviewed.

### The Localhost Trust Assumption Is Dead

ClawJacked exploited a specific assumption: "connections from localhost are safe." This assumption is baked into countless developer tools, database servers, and local services. It made sense when the only things running on localhost were things you explicitly started.

In 2026, your browser is a portal to arbitrary code execution. Any JavaScript on any page can try to connect to your local services. The "localhost is trusted" era needs to end.

## What You Should Do Right Now

### Step 1: Update OpenClaw Immediately

If you haven't already:

```bash
openclaw update
openclaw --version  # Should be v2026.2.25 or later
```

This patches ClawJacked specifically. But don't stop here.

### Step 2: Audit Your Gateway Password

Use a strong, unique password. Not "openclaw" or "password123." A random string of 20+ characters. Your agent authenticates programmatically, it doesn't need to be memorable.

```bash
# Check your current config
openclaw config get gateway.password
```

If it's weak, change it now.

### Step 3: Review Connected Devices

Check what devices are registered with your gateway:

```bash
openclaw status
```

If you see devices you don't recognize, remove them. The ClawJacked patch added rate limiting and removed automatic localhost device approval, but if your instance was compromised before the patch, a rogue device could still be registered.

### Step 4: Bind to Localhost Only

If your gateway is accessible on a public IP, you're exposed to far more than ClawJacked. Make sure it's bound to `127.0.0.1` only:

```yaml
# In your OpenClaw config
gateway:
  host: "127.0.0.1"
```

If you need remote access, use a VPN or SSH tunnel, never expose the gateway port directly.

### Step 5: Audit Your Agent's Access

List every service your agent can reach. For each one, ask:
- Does my agent still need this access?
- Are the credentials scoped to minimum necessary permissions?
- When was the last time I rotated these keys?
- Would I notice if my agent's behavior changed?

This is the hardest step because it requires honesty about what you've connected over time and whether you actually need all of it.

### Step 6: Enable Security Hardening

OpenClaw has a [security hardening skill](https://clawhub.com) that audits your setup. If you haven't run it:

```bash
openclaw skills install @<publisher>/healthcheck
```

Check our [full security hardening guide](/blog/openclaw-security-hardening) for the complete checklist.

## The Broader Lesson: Defense in Depth for AI Agents

ClawJacked taught the AI agent community something the enterprise security world learned decades ago: **defense in depth is not optional.**

No single security measure is enough. You need layers:

1. **Strong authentication**: long, random passwords. Rotate them periodically.
2. **Network isolation**: localhost binding. Firewall rules. No public exposure.
3. **Rate limiting**: prevent brute-force attacks on all endpoints.
4. **Device approval**: manual confirmation for new device registrations, even from localhost.
5. **Permission scoping**: give your agent the minimum access it needs, not everything you could give it.
6. **Activity monitoring**: review your agent's logs regularly. Know what it's doing.
7. **Update discipline**: apply patches immediately. Subscribe to OpenClaw's release notifications.

The MIT study on AI agent safety, [published this week](https://www.zdnet.com/article/ai-agents-are-out-of-control-mit-study/), found "persistent limitations in reporting around ecosystemic and safety-related features of agentic systems." Translation: most AI agent platforms don't give you enough visibility into what your agent is doing and who it's talking to.

OpenClaw is ahead of most platforms on transparency (open-source, local-first, auditable). But transparency without action is just awareness. You have to actually do the work of securing your setup.

## The Silver Lining

Here's what went right with ClawJacked:

- **Responsible disclosure.** Oasis Security reported the vulnerability privately before publishing.
- **Fast response.** OpenClaw pushed a fix within 24 hours.
- **Open-source advantage.** The patch is public. Anyone can verify exactly what changed and why. Compare that to a proprietary agent platform where you just have to trust the vendor's word.
- **Community vigilance.** Multiple security firms (Bitsight, NeuralTrust, Oasis) are actively auditing the OpenClaw ecosystem. That scrutiny makes everyone safer.

This is what a healthy security ecosystem looks like. Vulnerabilities are inevitable. What matters is how fast they're found, disclosed, and fixed.

## AI Agent Security Is Not Optional Anymore

Jensen Huang told CNBC last week: ["AI just went through its third inflection. Now, with these agentic systems, we're having these agents able to reason, take tasks, and actually do work."](https://www.cnbc.com/2026/02/28/ai-selloff-politics-agents.html)

He's right. And when agents do real work with real access to real systems, security stops being a nice-to-have. It becomes the thing that determines whether you can trust your agent at all.

ClawJacked was a wake-up call. A gentle one, it was found by researchers, not exploited in the wild. The next vulnerability might not be so polite.

Update your OpenClaw. Audit your access. Rotate your keys. And treat your AI agent's security with the same seriousness you'd give any system that has access to your entire digital life.

Because that's exactly what it is.

---

*New to OpenClaw security? Start with our [security hardening checklist](/blog/openclaw-security-hardening) and learn [how to audit skills before installing them](/blog/clawhub-skill-safety).*

## Sources

- [OpenClaw: Skills CLI](https://docs.openclaw.ai/cli/skills)