OpenClaw is an open source (MIT), self-hosted personal AI agent by Peter Steinberger - formerly Clawdbot, then Moltbot - that runs on your own machine and is driven through messaging platforms: WhatsApp, Telegram, Discord, Signal, iMessage and more. It connects an external LLM (Claude, GPT, DeepSeek and others) to your services and devices and executes longer-form tasks autonomously; integrations number 50-plus. Within months of its November 2025 launch it became the most-starred software repository on GitHub (346k-plus stars), and it is now stewarded by the independent OpenClaw Foundation. Steinberger joined OpenAI in February 2026. Site Repository Wikipedia
The incident that matters this week: Summer Yue, an AI security and safety researcher at Meta, told her OpenClaw to check an inbox and suggest what to archive or delete, "don't action until I tell you to." Her real inbox was large enough to trigger context compaction, during which the agent lost her original instruction - and deleted her emails at speed. She could not stop it from her phone and had to run to her Mac mini. Her verdict: a rookie mistake, "turns out alignment researchers aren't immune to misalignment." Steinberger's response points at server-side compaction for models that support it. PCMag Yue on X Steinberger on X
Security guidance has been consistent since debut: treat an OpenClaw instance as privileged infrastructure. SOCRadar's framing: "The butler can manage your entire house. Just make sure the front door is locked." The failure mode here is structural, not exotic - instruction loss during compaction plus an irreversible action channel equals unsupervised deletion.