Clawdbot — a new AI assistant gaining traction, but it raises serious security issues. Despite the excitement among users, experts warn that running Clawdbot on your computer may expose you to risks of remote hacking and data theft. It exemplifies how rapid popularity can outpace the evolution of security standards, notes VI.
Although it showcases new possibilities in AI, its usage carries high risks.
What is Clawdbot?
- Clawdbot — an open-source AI project that emerged in January 2026.
- It is marketed as an “agent AI assistant” capable of executing tasks locally on the user's computer.
- The interface operates through popular platforms — Discord, WhatsApp, and other messaging apps.
- The project became a sensation, gaining over 9,000 stars on GitHub within a day, and later exceeding 43,000.
Why did it become popular?
- It received support from notable tech leaders, including Andrii Karpaty (former Tesla AI lead).
- The developer community is actively testing Clawdbot, as it offers a straightforward way to integrate AI into everyday tasks.
- Local execution creates an illusion of better privacy and control over data.
Security Issues
Despite the hype, Clawdbot has serious drawbacks:
- Vulnerability to remote hacking: researchers found that unsecured ports made thousands of servers accessible to outsiders, leading to instances of API key theft.
- Privacy risks: Clawdbot may store all user interaction history, posing a threat of confidential information leakage.
- Demo-level protection: experts stress that the project is more focused on rapid popularity than on fundamental security.
Should you run Clawdbot?
- For enthusiasts: it's an interesting experiment showcasing the potential of agent AI assistants.
- For average users: running Clawdbot on a primary computer is risky. Experts advise against using it if you value privacy and system stability.
- Alternative: consider waiting for official security updates or using established AI assistants with commercial support.