KELA REPORT
OpenClaw Threat Assessment
KELA's threat assessment of the OpenClaw agentic AI ecosystem: the one-click RCE, malicious skills, leaked tokens and the zero-trust controls that contain it.
Share:

Proven Vulnerability Analysis (CVE-2026-25253): KELA’s investigation into underground chatter has uncovered active exploitation of a high-severity “1-click” Remote Code Execution (RCE) vulnerability.
Supply Chain Poisoning: Analysis of the ClawHub marketplace reveals a massive supply chain risk, with over 10% (341) of audited “Skills” found to be malicious. These deceptive extensions deliver data-stealing payloads without triggering traditional antivirus alarms.
Enterprise Defense Blueprint: KELA provides a rigorous framework to neutralize these autonomous threats by moving beyond standard compliance toward active containment. The report outlines a “Defense in Depth” strategy to discover anomalies in agentic traffic.
Has your "productivity assistant" become a searchable entry point for global threat actors?
- Why OpenClaw is a systemic risk: a local-first AI agent combining private-data access, untrusted content and full system privileges (the “lethal trifecta”)
- The one-click RCE (CVE-2026-25253) with public proof-of-concept code, and the tens of thousands of exposed instances threat actors mapped with FOFA and Shodan
- Supply-chain attacks through unverified ClawHub “Skills”, the ClawHavoc campaign and infostealer-laced forks spread during the Clawdbot-to-Moltbot rebrand
- The Moltbook data leak of 1.5 million API tokens and how threat actors, including the pro-Russian DDoSia Project, discussed it
- Underground chatter on OpenClaw, the MoltRoad darknet market, and a zero-trust hardening framework for enterprises




