OpenClaw

OpenClaw is an open-source, self-hosted autonomous artificial intelligence (AI) agent software. The project allows users to interact with a powerful AI assistant through various instant messaging applications such as WhatsApp, Telegram, Discord, Slack, and many more. Known for its red lobster icon, OpenClaw is designed to act as an "operating system" for AI agents, capable of independently carrying out complex tasks on the user's computer. The project was first released in November 2025 by Austrian software developer Peter Steinberger, and quickly gained great popularity among developers and power users.

History and Development

The project's journey has been marked by several significant name changes. It was initially released under the name Clawdbot in November 2025, a pun on Anthropic's Claude chatbot. However, Anthropic objected to the use of a potentially confusing name, so the project was briefly renamed Moltbot in late January 2026. The name Moltbot, inspired by the process of a lobster shedding its shell, was considered unsuitable, and three days later the project finally settled on its permanent name, OpenClaw. The new name reflects the project's open-source spirit and its "lobster" heritage.

Another important milestone occurred in February 2026, when the project's founder, Peter Steinberger, announced that he would be joining OpenAI. To ensure the project's continuity as free and independent software, OpenClaw was transferred to a nonprofit foundation-based governance model, with Steinberger remaining in primary technical control. This step has been compared to the foundations behind other major open-source projects such as Linux and Apache, with the ambition of becoming "the Switzerland of AI" — a neutral party that all sides can rely on.

Architecture and How It Works

OpenClaw is designed with an architecture that prioritizes flexibility and user control. The core of the system is the Gateway, a process that runs as a daemon on the user's machine (macOS, Linux, or Windows via WSL2). This Gateway acts as a "bridge" or control center that connects various messaging platforms with the AI engine and the tools available on the user's local system. This architecture follows a hub-and-spoke model, in which the Gateway is the center coordinating all other subsystems.

OpenClaw's workflow begins when a user sends a message to the bot in their chosen chat application. The Gateway captures the message and sends it to the Context Orchestrator, which enriches the command with information from the user's long-term memory to create personal and relevant context. Next, the command is passed to a Large Language Model (LLM) through the LLM Routing layer, which supports various model providers such as OpenAI, Anthropic, Google, as well as local models through Ollama. After the LLM generates a response or decides to take an action, the command is executed in a secure Sandbox Environment through the AgentSkills system, preventing potential damage to the main system.

Main Features

OpenClaw has a number of features that distinguish it from conventional AI assistants:

· Multiple Communication Channels: One of OpenClaw's main selling points is its ability to connect to many chat applications at the same time, including Discord, Google Chat, iMessage, Matrix, Microsoft Teams, Signal, Slack, Telegram, WhatsApp, Zalo, and others through channel plugins. A single Gateway can serve all configured channels simultaneously.

· Data Sovereignty and Privacy: Because it is self-hosted, all configuration data, interactions, and memory are stored locally on the user's device. Users have full control over their data without having to depend on third-party cloud services.

· Long-Term Memory: OpenClaw uses a local vector database to store long-term memory, allowing the AI to remember the user's preferences, projects, and context over time.

· Autonomous Capabilities: More than just a chatbot, OpenClaw can act independently to complete tasks. This includes the ability to automate a browser (for example, for data scraping), write and execute its own code, and manage files and applications on the operating system.

· User Interface and Mobile Apps: OpenClaw is equipped with a web-based Control UI for managing sessions, workspaces, and usage. In mid-2026, the project also launched native apps for iOS and Android, allowing interaction through text and voice from mobile devices.

Security and Challenges

Although it offers great control and capability, OpenClaw also presents significant security risks, a challenge acknowledged by its developers.

· Prompt Injection Risk: As an autonomous agent with access to systems and tools, OpenClaw is vulnerable to prompt injection attacks, in which an attacker can insert harmful commands into input that appears legitimate in order to persuade the AI to take unwanted actions.

· Overly Broad Access: If not configured carefully, OpenClaw can be given overly broad permissions, which can potentially cause damage, such as a case in which OpenClaw accidentally deleted many emails.

· Malware Risk: A report from cybersecurity company Hudson Rock showed that infostealers (data-stealing malware) can steal OpenClaw identities and settings from infected machines, giving hackers full access to accounts and personal data.

To mitigate these risks, developers and security experts recommend running OpenClaw in an isolated environment (sandbox), applying the principle of least privilege, regularly monitoring activity logs, and always updating the software.

Recent Developments and the Future

OpenClaw continues to be actively developed with regular updates. Releases such as v2026.6.11 and v2026.7.1 show a focus on improving message delivery reliability across various channels, user interface updates, and support for the latest AI models.

One of the most significant developments is the announcement of OpenClaw's transition into a nonprofit foundation in July 2026. This step was taken to ensure the project's independence, sustainability, and neutrality in the future, with the goal of becoming a standard foundation for AI agent development. However, the step has also drawn skepticism because of the project founder's close involvement with OpenAI, raising questions about the true neutrality of the foundation. OpenClaw's future appears likely to remain a center of attention in the rapidly evolving AI landscape, both because of its great technological potential and because of the governance and security challenges it brings.

References

OpenClaw Docs, "OpenClaw".

QNA, "OpenClaw Launches AI App for iOS, Android", qna.org.qa.

Wikipedia (Bahasa Tionghoa), "OpenClaw", zh.wikipedia.org.

ThaiCERT, "น้องกุ้ง OpenClaw เอเจนต์ AI แบบโอเพ่นซอร์ส ที่สะดวกแต่แฝงความเสี่ยงไซเบอร์ที่ผู้ใช้งานต้องรู้", thaicert.or.th.

OpenClaw Docs, "Getting started".

OpenClaw Docs, "v2026.7.1 Release Notes".

Wikipedia (Bahasa Polandia), "OpenClaw", pl.wikipedia.org.

Mudrii, "openclaw-docs/ARCHITECTURE.md", GitHub.

OpenClaw Blog, "Introducing OpenClaw", openclaw.ai.

OpenClaw Docs, "v2026.6.11 Release Notes".

Wikipedia (Bahasa Portugis), "OpenClaw", pt.wikipedia.org.

AWS Samples, "OpenClaw Enterprise".

Computerworld, "OpenClaw becomes a nonprofit foundation as it seeks to be ‘the Switzerland of AI’".

Pustikom UINSS, "Mengenal OpenClaw: OS AI Agent Open-Source yang Mengubah Cara Kita Berinteraksi dengan Komputer", pustikom.uinssc.ac.id.

OpenClaw Docs (Bahasa Indonesia), "Jalur spesialis paralel".