Another update; another headache 2026.9.3 : r/openclaw
A user report describes an upgrade problem and recovery steps, reflecting active community troubleshooting around the 9.3 rollout. (reddit.com)
OpenClaw intel for builders — signal, not hype.
OpenClaw is an open-source AI agent platform that can autonomously operate your computer — browsing the web, running apps, managing files, and executing multi-step workflows on your behalf. It was originally released as "Clawdbot," later rebranded to Moltbot, and is now known as OpenClaw.
OpenClaw can be installed via npm (npm install -g openclaw), Docker, or by cloning the GitHub repo. See our full installation guide for step-by-step instructions on every platform.
Yes. OpenClaw is fully open-source under the Apache 2.0 license. You can use, modify, and distribute it freely. Some cloud-hosted versions or premium ClawHub skills may have separate pricing.
OpenClaw grants broad system permissions by design, so caution is warranted. The project has integrated VirusTotal scanning for ClawHub skills, but security researchers continue to find malicious packages. Always review a skill's source, limit permissions, and keep OpenClaw updated. See our troubleshooting guide for security tips.
Skills are plugin-like extensions distributed via ClawHub that add new capabilities to your OpenClaw agent — like browsing the web, managing cloud infrastructure, or interacting with APIs. Think of them like npm packages but for agent actions.
In February 2026, OpenClaw creator Peter Steinberger joined OpenAI. OpenClaw remains open-source under a community foundation, and OpenAI has committed to keeping it that way. Read our timeline for details.
OpenClaw competes with platforms like BitBuddies, Adept, and Moltbot/Emergent. Its key differentiators are the open-source model, the ClawHub skill ecosystem, and broad OS-level control. See our alternatives comparison.
Check out our ELI5 explainer for a beginner-friendly overview, our usage & tutorials page for hands-on guides, and our glossary for key terms.
A user report describes an upgrade problem and recovery steps, reflecting active community troubleshooting around the 9.3 rollout. (reddit.com)
The 9.4 release adds built‑in plugin discovery, guided skill learning from past conversations, GPT Image 2.5 support, more controlled cloud sessions, interactive terminal questions, and numerous fixes to updates, memory, and messaging. Release notes emphasize reliability and operator controls. (github.com)
Reusable “allow‑always” approvals were not bound to the original working directory, so the same command could later run in a different directory with unreviewed effects; patched in 2026.8.1 with guidance to re‑approve per directory. (github.com)
The WhatsApp login tool could access turns that did not belong to the initiating user, widening exposure until patched; maintainers advise updating to the fixed builds. (github.com)
The Prometheus diagnostics plugin didn’t enforce operator.read on an authenticated metrics endpoint, potentially exposing metrics to identities intentionally restricted below read scope; fixed in 2026.9.3. (github.com)
Emoji/sticker uploads could lose the sender‑scoped media policy and read a local path outside configured roots; maintainers patched this in 2026.9.3 and recommend upgrading the @openclaw/discord package. (github.com)
The official community post highlights unified plugin browsing, guided skill learning chats, GPT Image 2.5 variants, cloud‑session controls, and reliability fixes, with a link to the full notes. (reddit.com)
A third‑party briefing characterizes 9.4 as an operational release focused on bounded rollbacks, unified extension management, prepared cloud workers, and clearer operator controls. (senx.ai)
A one‑hour live session walks through personal and shared dashboards and shows how to build a mini‑app dashboard from a single prompt while fielding questions on stability and multiplayer use. (openclaw.ai)
This update rehearses upgrades before they activate, improves rollback and recovery, speeds session reconnects, enables live browser viewing, and adds read‑only share links and transcript search. It also tightens Node requirements and polishes Docker, Windows, and Mac behaviors. (github.com)
The announcement details pre‑activation rehearsal of upgrades, improved rollback, live browser streaming, and public read‑only session sharing, plus tightened Node requirements. (reddit.com)
Operators discuss stricter default guardrails in 2026.9.x that block higher‑risk tasks without explicit approvals, along with workarounds and tradeoffs. (reddit.com)
A concise official demo where Patrick Erichsen prompts OpenClaw 2.0 to generate a working release dashboard in minutes. (docs.openclaw.ai)
A hands‑on review of 2.0’s new UI, sub‑agents, skills and setup flow with candid notes on reliability and safer deployment choices. (tubescout.app)
Core contributors break down the 2.0 release with deep dives into the rebuilt Control UI, memory and skills, stability focus, and distributed compute. (openclaw.ai)
A step‑by‑step install/upgrade tutorial that emphasizes backing up, the 2.0 SQLite migration, using doctor/repair, and the updated security and permission model. (tubescout.app)
InfoWorld covers “OpenClaw 2.0,” noting changes across runtime, plugins, and secret handling and quoting the project’s framing that the overhaul touched “every part of OpenClaw.” (infoworld.com)
CSO Online highlights enterprise implications of the 2.0 security and operational changes, emphasizing trust boundaries, permissions, and isolation in agent workflows. (csoonline.com)
OpenClaw is an open-source AI agent platform that can autonomously operate your computer — browsing the web, running apps, managing files, and executing multi-step workflows on your behalf. Originally released under a different name, OpenClaw has rapidly become one of the most talked-about projects in the AI-agent space thanks to its extensible "skill" system (distributed via ClawHub) and its ability to chain actions across local and cloud environments.
Peter Steinberger releases Clawdbot, a personal AI-agent experiment that can control a desktop computer autonomously. The project garners early attention from the hacker community.
Word-of-mouth spreads fast. The project rebrands to Moltbot as download counts surge. Developers start building third-party "skills" — plugin-like extensions that chain agent actions.
A companion product, Moltbook, is teased for notebook-style agent workflows. Soon after, the entire project rebrands again to OpenClaw, emphasizing its open-source ethos and the new ClawHub skill marketplace.
Critical vulnerabilities surface — including CVE-2026-25253 (one-click RCE via Control UI) — prompting rapid patches and VirusTotal integration for ClawHub skills. Security researchers begin auditing the ecosystem extensively.
Reports emerge that multiple Big Tech companies, including OpenAI and Google, are in discussions about acquiring or integrating OpenClaw. The AI-agent space heats up as competitors race to match OpenClaw's capabilities.
OpenClaw creator Peter Steinberger joins OpenAI. Crucially, OpenClaw remains open-source under a community foundation — OpenAI commits to supporting, not acquiring, the project. The Verge, Financial Times, and Business Insider all cover the story.
A news hub that aggregates the latest OpenClaw updates, security advisories, release notes, and community chatter. We focus on signal over hype.
No. This is an independent publication. We are not affiliated with, endorsed by, or sponsored by the OpenClaw project or its maintainers.
ClawHub is OpenClaw's community marketplace for "skills" — plugin-like extensions that add capabilities to the agent. Think of it like a package registry (npm, PyPI) but for agent actions.
OpenClaw grants broad system permissions by design. The project has integrated VirusTotal scanning for ClawHub skills, but security researchers continue to find malicious packages. Always review a skill's source, limit permissions, and keep OpenClaw updated.
Content is refreshed periodically based on news flow. Check the "Last updated" timestamp at the top of the news section.
A critical remote-code-execution bug in OpenClaw's Control UI that allowed one-click token exfiltration via a malicious link. It was patched in v2026.1.29 (January 30, 2026). All users should update immediately.
Not yet — we're a static v0 site. Future versions may accept community submissions. For now, all content is manually curated and reviewed before each update.
We aggregate recent coverage from major tech and security outlets, then compile it into a structured feed.