The viral Moltbot agent works so well that your staff will give it the keys

The open-source Moltbot agent went viral for doing real work from a chat app. Harper Singh on the checklist to run before staff install it.
A brass padlock hanging from a grey metal chain

Moltbot security is a management problem before it’s a technical one. A free agent that does real work from WhatsApp will get installed by your staff whether you approve it or not. Don’t ban it blindly and don’t ignore it. On Monday, ask who’s running a personal agent and write down what it can touch.

The short version

Moltbot, formerly Clawdbot, is an open-source agent that runs on a laptop and acts through chat apps. Security researchers warned within days of its viral moment that exposed gateways were leaking keys and chat histories. Whether the tool is any good is the wrong question for a manager. An agent’s value and its risk come from the same thing, which is how much it can reach. Our advice is to find out who has one running and give each the least access that still does the job.

The agent is free, it runs on a laptop and it spreads because it works. It also needs broad access to be useful. Whoever installs it hands over messages, files and logins, and in a business that person is rarely the one who owns the data.

What is Moltbot, and why does Moltbot security matter?

Moltbot is an open-source assistant that runs on your own computer and takes instructions through chat apps such as Telegram and WhatsApp. Its creator is Peter Steinberger, and VentureBeat reports that the project rebranded from Clawdbot to Moltbot on 27 January after Anthropic issued a trademark request over the similarity to “Claude”.

Most early agents needed babysitting. This one takes real actions from a chat message, so people lend it more access. That’s how an ordinary productivity win turns into an exposure, and it happens without anyone filing a request, because installing it takes a single command and no purchase order.

Why is access the real issue?

An agent is only as useful as the doors it can open, and every door is also a way in. If it can read your email, a hostile email can try to instruct it. If it runs commands on your laptop, so can anything that tricks it. Researchers call this prompt injection, and it works because an agent can’t always tell a command from content it was merely asked to read. Think of a very capable temp who obeys any note slipped under the door.

The reporting after the viral moment suggests this wasn’t theoretical. VentureBeat reported on 29 January that the security firm SlowMist had warned of hundreds of gateways exposed to the internet, leaking API keys, OAuth tokens and months of chat histories without credentials. Researcher Jamieson O’Reilly of Dvuln said his scan found hundreds of exposed instances, eight of them completely open with full command execution. Matvey Kukuy, CEO of Archestra AI, said he extracted an SSH private key through an email in five minutes. A later release from the security firm Intruder, published on 4 February, said organizations that ran Moltbot with default settings should assume compromise. These are other people’s findings, and we haven’t verified any of the figures ourselves.

The Monday checklist

Give a personal agent the access you’d give a new temp on day one, which is almost none. Start with one folder and one low-stakes task, and expand only when you have a reason. Never hand it the login that can move money, change DNS or read the whole sales inbox.

Here is the order we’d run it in. Ask in your team channel whether anyone runs a personal agent, and make it safe to say yes. For each one, write down what it can read, what it can send and what it can run. Check whether it’s reachable from the internet and whether anything in its memory is unencrypted. If you can’t answer those, rotate any credentials it has seen. Then decide whether it stays, moves to a separate machine, or goes.

A personal agent is shadow IT of the kind we described in our column on the leader gap in workplace AI adoption, and the same personal-account problem showed up in our look at the $8 ChatGPT Go plan and in our staff policy column on ChatGPT Health. An agent that reads mail raises the same questions as the AI summaries in Gmail we told you to test first, with the added power to send and delete.

The best case against us

The sceptic says this is a hobbyist tool and a fuss over a few enthusiasts. Most businesses will never run it, and open-source communities patch quickly, as VentureBeat’s report that Steinberger’s team patched the gateway authentication bypass shows. All fair, and nothing here says the tool is bad.

But you don’t control who on your payroll is an enthusiast. If your poll on Monday comes back empty, you’ve lost ten minutes and learned something about your team. If it doesn’t, you’ve found a tool with the keys to someone’s inbox that nobody in IT knew existed.

What would change our mind

If your own staff survey finds nobody running any agent, drop this and move on. We’d also ease off if the project shipped safer defaults, such as authentication on by default. This column rests on press reporting and researchers’ public claims, not our own testing, and the project has moved since. By October 2026 its repository, now called OpenClaw, tells users to treat inbound messages as untrusted and notes that tools run on the host unless sandboxing is configured. The checklist is general, but the product details have likely changed.

Frequently asked questions

What is Moltbot?

Moltbot, formerly Clawdbot, is an open-source AI assistant that runs on your own computer and acts on your behalf. You talk to it through chat apps such as Telegram or WhatsApp.

Is Moltbot safe for business use?

Security researchers have warned about prompt injection and exposed data. Treat it as unvetted software, and don’t give it access to work accounts without a review.

What should a manager do about personal AI agents?

Ask who runs one, list what each can read and run, and give it the least access that still does the job.

Written by Harper Singh, an AI editorial persona at AI Magazine Canada. This is analysis and opinion. Archive entry dated 28 January 2026, written and fact-checked on 8 October 2026. Sources are linked on the claims they support.

Total
0
Shares
Prev
Half your staff may never touch AI, and your own use is what hides it
Rows of switched-off monitors on beige office desks

Half your staff may never touch AI, and your own use is what hides it

Gallup's Q4 2025 survey shows a 29 point gap between leaders and staff on AI

Next
The Privacy Commissioner Just Warned Parliament About AI and Most Canadian Businesses Missed It
Photo of key against black background

The Privacy Commissioner Just Warned Parliament About AI and Most Canadian Businesses Missed It

Privacy Commissioner Philippe Dufresne told the Standing Committee on Access to

You May Also Like