Skip to main content
  1. Home
  2. Computing
  3. News

Digital Trends may earn a commission when you buy through links on our site. Why trust us?

The viral Clawdbot AI agent can do a lot for you, but security experts warn of risks

How an AI assistant built for automation can become an attacker’s shortcut

Add as a preferred source on Google
clawdbot-moltbot-security-risks
Moltbot

Clawdbot, the AI agent that took the tech world by surprise, became one of the fastest-climbing projects on GitHub because it promised something unusual.

Instead of just chatting, Clawdbot can interact with your files, send messages, schedule calendar events, and automate tasks on your own computer, all without sending your data off to a big server.

Recommended Videos

Its ability to act on behalf of users makes it feel like a personal AI helper. This contributed to its popularity and helped it spread rapidly among developers and curious users alike.

The project was recently renamed from Clawdbot to Moltbot after Anthropic objected to the original name, citing potential trademark conflicts. The developer agreed to the change to avoid legal trouble, even though the software itself remained unchanged.

🦞 BIG NEWS: We’ve molted!

Clawdbot → Moltbot
Clawd → Molty

Same lobster soul, new shell. Anthropic asked us to change our name (trademark stuff), and honestly? “Molt” fits perfectly – it’s what lobsters do to grow.

New handle: @moltbot
Same mission: AI that actually does…

— Mr. Lobster🦞 (@moltbot) January 27, 2026

What security checks revealed about Clawdbot (Moltbot)

The same features that made Moltbot seem powerful are also what make it risky. Since the AI can access your operating system, files, browser data, and connected services, researchers warn that it creates a wide attack surface that bad actors could exploit.

Security researchers actually found hundreds of Moltbot admin control panels exposed on the public internet because users deployed the software behind reverse proxies without proper authentication.

Because these panels control the AI agent, attackers could browse configuration data, retrieve API keys, and even view full conversation histories from private chats and files.

In some cases, access to these control interfaces meant outsiders essentially held the master key to users’ digital environments. This gives attackers the ability to send messages, run tools, and execute commands across platforms such as Telegram, Slack, and Discord as if they were the owner.

Other investigations revealed that Moltbot AI often stores sensitive data like tokens and credentials in plain text, making them easy targets for common infostealers and credential-harvesting malware.

Researchers also demonstrated proof-of-concept attacks where supply-chain exploits allowed malicious “skills” to be uploaded to Moltbot’s library, enabling remote command execution on downstream systems controlled by unsuspecting users.

This is not just theory. According to The Register, analysts warn that an insecure Moltbot instance exposed to the internet can act as a remote backdoor.

There’s also the possibility of prompt injection vulnerabilities, where attackers trick the bot into running harmful commands; something we have already seen in OpenAI’s AI browser, Atlas.

If Moltbot is not secured properly with traditional safeguards like sandboxing, firewall isolation, or authenticated admin access, attackers can gain access to sensitive information or even control parts of your system.

Since Moltbot can automate real-world actions, a compromised system could be used to spread malware or further infiltrate networks. Here’s what Heather Adkins, VP of Google Security Team, thinks of the chatbot:

My threat model is not your threat model, but it should be. Don’t run Clawdbot. https://t.co/FOUEJCFYcD

— Heather Adkins – Ꜻ – Spes consilium non est (@argvee) January 26, 2026

In short, Moltbot is an intriguing step toward more capable personal AI assistants, but its deep system privileges and broad access mean you should think twice and understand the risks before installing it on your machine.

Researchers suggest treating it with the same caution you would use for any software that can touch critical parts of your system.

Manisha Priyadarshini
Manisha Priyadarshini is a tech and entertainment writer with over nine years of editorial experience.
Lenovo’s Googlebook lineup could include two laptops, a 2-in-1 tablet, and an AI mouse
Images have emerged online giving us our first look at Lenovo’s upcoming Googlebooks
Googlebook

Google announced Googlebook at I/O in May, but we are still waiting to see what the finished hardware will actually look like. The first devices are expected this fall, and new images published by Android Headlines may have given us an early look at what Lenovo has planned.

Lenovo appears to be preparing at least three Googlebooks, including two traditional laptops and a detachable 2-in-1 tablet. There is also a new wireless AI mouse that seems to have been designed specifically for the platform.

Read more
Shopping for back-to-school? I’d recommend these GaN chargers for saving space and packing more power
From a $9 spare to a $56 desk hub, these chargers cut down on cable clutter so that you can focus on your studies, not how cluttered your desk looks.
Best GaN chargers in 2026 for back to school shopping.

Between a phone, a laptop, a tablet, and perhaps a pair of wireless earbuds that require charging every day or every few days, most students are packing multiple chargers for move-in day. Those big, heavy bricks take up valuable backpack space that could otherwise be free for carrying more items. 

However, GaN chargers fix that problem in two ways. First, they deliver the same amount of power from a much smaller body, thanks to gallium nitride transistors. Furthermore, if you're willing to spend a little more upfront, you can get a high-capacity, multi-device charger capable of powering your entire digital ecosystem from a single wall outlet, something that could be very useful for a dorm room.

Read more
Gemini Spark can now use Chrome logins and saved passwords to run errands on your behalf
Gemini Spark can use Chrome’s auto browse feature to navigate websites and complete online tasks
Gemini Spark Chrome auto browse feature

Google is integrating Gemini Spark with Chrome so it can carry web-based tasks further without users having to take over at every step. The search giant is also expanding access to AI Pro subscribers in more than 160 additional countries, although the new browser capabilities are initially limited to the United States.

How Chrome auto browse works

Read more