Moltbot Gets Another New Name, OpenClaw, And Triggers Security Fears And Scams
What began as a side project that quietly drew more than 100,000 GitHub stars has turned into one of the most viral experiments in AI. Built by Peter Steinberger, Clawdbot captured attention by promising something most AI tools still cannot do: use a message-based interface to take action, not just talk. That promise pushed the project from curiosity to phenomenon. It also pushed it into trouble.
After a trademark dispute with Anthropic earlier this week, Steinberger, founder of PSPDFKit, renamed the project Moltbot, then, in an announcement late Thursday, rebranded it again as OpenClaw. (I’ve contacted Steinberger for comment and will update the article if he responds.) Each name change widened its audience and its risk profile.
What was once framed as a clever, local AI assistant is now under scrutiny from security researchers, enterprises and regulators who see the same pattern emerging with tools that elicit rapid adoption, deep permissions and confusion that scammers know how to exploit.
Most AI tools respond with text in terminals or web browsers. OpenClaw is different. It is an agent, meaning it can carry out tasks on your computer, and you can interact with that agent using your favorite messaging platform such as WhatsApp, Telegram, Discord, Slack, Teams and others.
A simple message like “check my calendar and reschedule my flight” can trigger real actions such as opening a browser, clicking buttons, accessing files, sending messages or running commands. The system runs locally on a user’s machine but connects to cloud-based AI models for reasoning. The appeal is control. Your data stays with you. Your machine does the work.
For developers, that idea is powerful, but for everyday users, it is risky.
To function, OpenClaw often needs deep access to the system it runs on, sometimes........
