# 250K Stars, 7,000 Installs for Hire, and a Security Panic — OpenClaw's Wildest Week Yet

Canonical: https://clawdocx.com/blog/openclaw-250k-stars-lobster-gold-rush-2026
Author: Mira Castellan
Published: 2026-03-13
Updated: 2026-03-13

> OpenClaw became the fastest-growing open-source project in history this week, hitting 250K stars alongside a hiring rush and a security scare.

## OpenClaw Just Broke the Internet (Again)

Somewhere between Monday and Thursday this week, OpenClaw quietly passed a milestone that took Linux *years* to reach: **250,000 GitHub stars**. The fastest-growing open-source project in history.

But the star count is almost the least interesting thing that happened. In the span of seven days:

- **Alibaba** launched a dedicated mobile app for deploying OpenClaw in minutes
- A 27-year-old in Beijing quit his job and built a **100-person installation business** doing 7,000 orders at $34 each
- **1,000+ people** packed a venue in Shenzhen for a community meetup — standing room only
- The Chinese government issued its **first formal security warnings** about an AI agent platform
- OpenClaw's creator Peter Steinberger confirmed he's joining **OpenAI**

This isn't a product launch. This is a cultural moment.

## The "Lobster" Goes Mainstream

If you've been following OpenClaw from the early days, you know the community calls it "the lobster" — a nod to the red crustacean logo. In China, "raising a lobster" has become the phrase for running your own AI agent. And right now, *everyone* wants one.

The adoption curve stopped being gradual about three weeks ago. What started as a developer tool for power users has crossed over into mainstream consciousness in China at a speed that's hard to overstate.

**The numbers tell the story:**
- Chinese OpenClaw usage has **surpassed the U.S.**, according to cybersecurity firm SecurityScorecard
- Token consumption on Chinese LLM providers surged **6x** as agents ran around the clock
- The top three AI models used by OpenClaw users on OpenRouter are **all Chinese-made** — combined usage double that of Google and Anthropic models
- Xiaomi announced "miclaw" for smartphones and home appliances

On March 6, nearly 1,000 people lined up outside Tencent's Shenzhen headquarters carrying laptops and hard drives, waiting for engineers to install OpenClaw *for free*. Think about that. A thousand people, standing in line, for software.

## The Gold Rush Economy

Here's where it gets fascinating.

Feng Qingyang, a 27-year-old software engineer in Beijing, started helping coworkers install OpenClaw in January. By the end of the month, he'd posted an ad on Xianyu (China's secondhand marketplace): "OpenClaw installation support. No coding required. Available within 30 minutes."

By the end of February, **he quit his day job**. His side gig had exploded into a company with over 100 employees and 7,000 completed orders at roughly 248 RMB ($34) each. That's nearly **$240,000 in revenue** from helping people install free, open-source software.

"Opportunities are always fleeting," Feng told MIT Technology Review. "As programmers, we are the first to feel the winds shift."

He's not alone. A cottage industry of installation services, preconfigured hardware sellers, and "lobster raising" courses has sprung up almost overnight. Online platforms are flooded with tutorials. Influencer Fu Sheng's livestream demo pulled 20,000 viewers. Community meetups are drawing hundreds — sometimes over a thousand — in cities across China.

### Why This Matters for OpenClaw Users Everywhere

This gold rush is doing something important: **it's proving demand at scale**. When non-technical users — lawyers, doctors, retirees — are paying real money and standing in lines to run AI agents, it validates the entire ecosystem. Every skill you build, every workflow you automate, every guide you write has a growing audience of people who *want* this but need help getting there.

## Alibaba Enters the Chat

As of this week, Alibaba has launched a **dedicated mobile app** for OpenClaw deployment. The promise: install and deploy your agent in minutes, no technical background required.

This follows Tencent's "lobster special forces" suite (integrated with WeChat), Zhipu AI's one-click installer with 50+ pre-loaded skills, and Baidu hosting installation events at their headquarters.

The big players aren't just supporting OpenClaw — they're building entire product lines around it. Why? Because:

1. **OpenClaw is model-agnostic** — it works with any LLM, and Chinese models are significantly cheaper than Western alternatives
2. **It drives cloud consumption** — every running agent burns tokens, compute, and storage
3. **The consumer demand is real** — this isn't a developer trend anymore

For these companies, OpenClaw is a distribution channel for their AI models and cloud infrastructure. The agent is free. The compute is not.

## The Security Reckoning

Now the other side of the coin.

With explosive growth comes explosive risk. Researchers found **over 40,000 OpenClaw instances** exposed on the public internet, with more than 60% containing exploitable vulnerabilities.

The most alarming discovery was **ClawJacked** — a flaw that allowed any website to silently hijack a running OpenClaw instance. No clicks required. Once compromised, attackers could steal API keys, read files, and execute arbitrary commands. On a tool that has access to your email, calendar, and file system, that's catastrophic.

On March 8 and 10, Chinese government agencies issued **two official security alerts** — the first formal government warnings about any AI agent platform. They detailed risks including prompt injection attacks, data theft, and the dangers of running exposed instances.

The OpenClaw team patched over 40 vulnerabilities in February alone and shipped security-hardened updates. But the tension is real: **the same capabilities that make OpenClaw powerful make it dangerous** if misconfigured.

### What You Should Do Right Now

If you're running OpenClaw (and if you're reading this, you probably are):

1. **Update immediately** — Run the latest version with all security patches
2. **Never expose your instance to the public internet** without authentication
3. **Review your API keys** — Rotate anything that might have been exposed
4. **Use OpenClaw's built-in security features** — allowlists, permission controls, and sandboxing exist for a reason
5. **Check our [security hardening guide](/blog/openclaw-security-hardening)** for a full walkthrough

## What Comes Next

Peter Steinberger, OpenClaw's creator, announced he's joining OpenAI to help build the next generation of AI agents. OpenClaw itself will continue as an independent project under a foundation structure.

"The community around OpenClaw is something magical," he wrote. "It will stay a place for thinkers, hackers and people that want to own their data."

The Shenzhen government's Longgang district has announced subsidies of up to **2 million yuan (~$290,000)** for OpenClaw-based projects. Other cities are expected to follow. This is government-backed infrastructure investment in AI agents — not research, not chatbots, but *agents that do real work*.

## The Bottom Line

We've seen viral tech moments before. This one is different because it's not just attention — it's *action*. People are deploying agents. Businesses are forming. Governments are both subsidizing and regulating. Enterprise infrastructure is being built on top of it.

OpenClaw crossed from "interesting open-source project" to "global platform" this week. The 250,000 stars are just the scoreboard. The real story is the millions of tasks being executed by agents running on laptops, cloud servers, and soon smartphones in every corner of the world.

If you've been on the fence about setting up your agent, the fence is gone. The question isn't whether AI agents will be part of daily life — it's whether you'll be ahead of the curve or catching up.

---

*Want to get the most out of your OpenClaw setup? Browse our [skill library](/pricing) and [step-by-step guides](/docs) to level up your agent today.*