Clawdbot — a new AI assistant that raises serious security concerns. While it showcases impressive capabilities, experts advise caution. Running Clawdbot poses risks to your computer's security and your data. This serves as a prime example of how new technologies can create dangers that outweigh their advantages. V.I.
What is Clawdbot?
- Clawdbot is an open-source AI project that launched in January 2026.
- It is marketed as an “agent-based AI assistant” capable of performing tasks locally on the user's computer.
- The interface operates through popular platforms like Discord and WhatsApp.
- The project has gone viral, receiving over 9,000 stars on GitHub in just one day, and later surpassing 43,000.
Why has it become popular?
- It has been endorsed by well-known tech leaders, including Andrii Karpaty.
- The developer community is actively testing Clawdbot due to its ease of integrating AI into daily tasks.
- Local execution creates an illusion of greater privacy and control over data.
Security Issues
Despite the hype, Clawdbot has significant drawbacks:
- Vulnerability to remote hacking: researchers found that unsecured ports made thousands of servers accessible to outsiders, leading to cases of API key theft.
- Privacy risk: Clawdbot may store the entire history of user interactions, posing a threat of confidential information leaks.
- Demo-level security: experts emphasize that the project focuses more on rapid popularity growth than on fundamental security.
Should you run Clawdbot?
- For enthusiasts: it's an intriguing experiment showcasing the potential of agent-based AI assistants.
- For average users: running Clawdbot on a primary computer is risky. Experts advise against its use if you value data privacy and system stability.
- Alternative: it might be better to wait for official security updates or use established AI assistants with commercial support.