Big news! This tweet could save you millions of dollars!
OpenClaw (the "crayfish" in the OpenClaw forum) has been targeted by hackers who are scanning your public IP addresses. If you have access to OpenClaw's private key, immediately disable public access!
A large number of clients are expected to be attacked!
This page, openclaw.allegro.earth, lists all publicly accessible active OpenClaw instances for your security protection. If you have deployed such an instance, please enable authentication, remove direct public exposure, and patch it immediately.
The main security risk comes from: If your OpenClaw instance is directly exposed to the public internet without any authentication enabled (or with only weak authentication), attackers can directly access the control panel and even execute arbitrary commands, operate your computer/server, steal files, call APIs, etc. (equivalent to remotely controlling your environment).