OpenClaw 2.0, Accidentally

(openclaw.ai)

100 points | by doppp 7 hours ago ago

101 comments

  • layla5alive 9 minutes ago

    Open claw: aka. open door to a remote privilege escalation potentially granting root access to your computer (and if you're using it "as intended" possibly all of your email/internet logins/accounts, your credit card, etc.) to any text your model ingests from the internet...

    It's already true of LLMs in general that they represent a privilege escalation opportunity to any text they ingest. But with human in the loop, and a well-formed sandbox, the blast radius and risk are both reduced..

    Convenience is the root of much evil.

  • Schlagbohrer 3 hours ago

    I have found the Pi agent harness, running in a docker container, with Qwen3.8-27B in back in LM Studio, to be amazing and i use it daily. Just last weekend I used it to do PDF editing which previously would have required me to download really shady software online to do.

    I have never tried OpenClaw so maybe I am missing out but considering how much my agent can modify the Pi environment to work better, I am happy with the workflow I have established.

    Does anyone have a good pro vs con for Pi vs OpenClaw? I have never tried using a cloud model via a local agentic harness.

    • eyeris 3 hours ago

      No problem/con here, but I think the main reason for openclaw became famous is that it was a harness you could connect via messaging apps (esp telegram).

      That way you could have an assistant with your full computer context available on the go.

      Additionally, it’s super battery-included, pretty much the opposite of pi

    • siwatanejo 2 hours ago

      > Just last weekend I used it to do PDF editing which previously would have required me to download really shady software online to do.

      Agreed on the shady software (or shitty online website that asks you for a payment after you're done editing), however, wouldn't the best PDF edition approaches involve WYSIWYG style edition? I'm guessing you didn't get that with Pi.

    • jstummbillig 2 hours ago

      As someone who ever used either: Are they comparable? I thought of them very differently, Pi more being, idk, a codex-light like thing and OpenClaw being this continuously running machine, doing stuff without your explicit prompting, ingesting signals.

      I need to read up.

      • simonw an hour ago

        OpenClaw is built on top of Pi.

    • iagooar an hour ago

      As much as I love my CLI tools, I just cannot go back to not having native built-in browser integration, links, etc which the (Mac) desktop apps like ChatGPT or Claude offer.

      I do use Hermes sometimes, but it tends to keep growing skills and overhead over time, to the point it is becoming utterly slow and sluggish. The Desktop experience itself seems vibecoded without taste, in contrast to the core of Hermes, which is solid.

      I wonder if there is an agent harness that has the strengths of Pi, but in a native Mac desktop app packaging?

  • blfr 4 hours ago

    I like the idea but do not have a good use for these semi-autonomous agents. Or any notion for a decent use, frankly. What do people do with them?

    It sounds great to have an always-on box which does things. Like a server. I have servers. There are even Signal and other transports so you can communicate with the box conveniently. And then what?

    • sensanaty 2 hours ago

      It's used primarily for generating spam and inventing scams. Nobody real actually uses this garbage, it's all just fake marketing and shills (when they're not scamming people, that is?

      • Topfi 2 hours ago

        Now that is unfair. It also serves as a petting zoo for CVEs. Honestly tragic, I am starting to feel concerned for their well-being. So many in one code base, that has to violate some welfare laws. Almost 600 in less than a year, roughly two per day, utterly insane.

        In all seriousness, the fact that OpenClaw wasn't treated as an interesting, but failed experiment and shut down is telling for this industry. Is just letting LLMs output code without reviewing the results a path towards major issues? Nah, that can't be the case.

        And to proof it, here is a piece of software with some of the most CVEs relative to its size and age we have ever seen. We then get some highly paid engineers from companies like Nvidia assigned to somehow finagle it into a workable state. Not like, if LLMs where at the point that the purveyors of OpenClaw and co. seem to think they are, the models should be able to fix any issues by themselves. Especially considering the obscene amounts of free OpenAI tokens Peter Steinberger proudly uses.

        In any sane time, we'd have looked at the result of OpenClaw and assessed it as not salvageable. This was barely more than an experiment when it became apparent that the inherent design was flawed after all. Mind you, it was a very informative experiment and I am thankful it exists as clear-cut evidence of the capabilities the models have at the end of 2025 up to now in 2026. Basically, OpenClaw Alpha should have been released as proof that LLMs aren't there yet and need strict review+guidance.

        Development should have been restarted from scratch with A.) humans verifying the output, B.) an actual architecture in mind that the (human) developers designed and that took some learnings from the original release and C.) admitted that LLM coding in the way that yielded the original OpenClaw (as in, low to no human verification) shouldn't be done by anyone, at least with todays models.

      • az226 2 hours ago

        and the biggest reason was a plug for Peter himself.

    • xcjs 4 hours ago

      Mine is contributing to media preservation by reverse engineering Android apps/games that were forced into obsolescence by Google's policies: https://xcjs.com/blog/2026/08/29/resurrecting-2013-with-qwen...

      • FluffyPancake 10 minutes ago

        that's pretty cool. I have a hope that despite the giant mountain of shit that is going to be produced from LLMs in the future, there's going to be a small number of people out there doing cool things with them. I am completely ignorant on the gaming hardware front, but I hope we see more/better emulators and old games being brought back to life with improved performance and compatibility with modern OSs.

    • NoboruWataya 17 minutes ago

      Indeed, I find it hard to conceive of problems that are:

      - too difficult for me to solve but easy enough for a cheap model to solve (if it's going to be running autonomously in the background, I ain't paying ChatGPT/Claude prices), and

      - don't involve a bunch of my personal data that I am not comfortable sending off to a random inference provider.

      One thing I considered was that it might be good for anything that involves web scraping, given that has traditionally been a fairly difficult thing to do well. But you'd have to be okay with the occasional mistake. (You'd also have to be morally okay with contributing to the epidemic of AI scrapers that websites now have to deal with.)

    • teekert 4 hours ago

      I think this is a good question, as with any of these new things you don't really feel any need indeed.

      My claw scrapes some APIs, receives some emails with job listings, and matches it all to my profile. It can also fill two folders at 2 domains with anything (ie a demo for a website). It can also receive emails, make PFDs out of them and forward them to my bookkeeping software (which can only deal with attachments, not emails.) That last thing is just a script. I use Agentmail btw (a ycombinator startup), was easy to set up.

      2nd iteration I was indeed eyeballing Hermes which is supposed to be more structured, maybe claw2 also is... I want to add some things, like have it manage my son's minecraft worlds (using docker compose), maybe have it access a calendar so it can make appointments (not sure how to set that up in a useful way yet).

      The thing is in a Hetzner VM far away from anything important, dealing only with public data (except for the occasional invoice).

      • camillomiller 4 hours ago

        Is it just me or all you describe would be easily scriptable like 5 years ago? Not being confrontational, it’s just that every description of what OpenClaw does sounds quite… not disruptive at all for something that was hailed as the biggest invention since sliced bread.

        • teekert 4 hours ago

          Yeah that's true, and in many cases the AI just sets up a cronjob and a script (and a mailbox, and an interface to telegram, and a reporting structure). But it's nice that in case of errors it handles the edge cases or it fixes the scripts. It can give the crontable over telegram, you can pause it for the holiday "Number one, pause all processing until further notice"...

          But sure, it's not "rocket science", in fact, the skills to set it up indeed would probably help you set up the same scripts. It's just behind a chat interface.

          It can be nice to say: "Add another minecraft world with the same user whitelist on port 25566" or "create a demo website for a home battery on domain claw.xxx.com". But it is indeed not very useful for me yet. I think the more access you give it, the more it can be like a PA, but I don't want it in my calendar/home assistant/paperless-ngx etc... yet... When I even get to this point I can see it being like my secretary ("Please get my incomes taxes statement from 2024", "Estimate this years income taxes from my invoices so far", "Plan appointment with ..." etc)

          • legostormtroopr 3 hours ago

            "Number one, pause all processing until further notice"...

            Because OpenClaw (well, all AI) is well known for following instructions correctly.

            https://au.pcmag.com/ai/116091/meta-security-researchers-ai-...

            • teekert 3 hours ago

              There are reasons to be careful indeed, but for me all instructions were followed nicely so far.

              Yesterday I had Claude (in CC) do a large number of changes to my codebase using a bash script, even though I was in planning mode and in claude.md it says: Always first list the steps you're going to take before execution. It apologized of course... But I know how LLMs can be. I take that into account.

              • newswasboring 2 hours ago

                This is my pet peeve. All the disastrous failures get reported big, but the news doesn't report when a system just quitely does the task.

                • teekert 2 hours ago

                  In this case the "disastrous failure" is even from a super careless "experiment" by a "competitor" that likes regulation.

        • oarsinsync 3 hours ago

          100% easily scriptable. Just like running an (S)FTP server is easy, and Dropbox is not at all disruptive.

          Except you're overestimating the barrier to entry of scripting for the overwhelming majority of people. OpenClaw is not disruptive because it does something that wasn't possible before, it's disruptive because it enables more people to do the thing that was limited to fewer people.

          Where I get confused is why my techie friends are all going bananas over claws... they all know how to script already, and are crying about burning through multiple $200 claude subscriptions a month, filtering email. This I can't understand.

        • flashblaze 4 hours ago

          I believe the thing which makes OpenClaw interesting is you can just ask it to do these things and it just does. Rather than you having to write these scripts. I understand with LLMs, writing these scripts would now be trivial, but I believe this is even more convenient.

          • ed_elliott_asc 3 hours ago

            At least writing scripts you know what it will and won’t do, with open claw it will probably do what you want and maybe won’t do anything you don’t want.

            • teekert 3 hours ago

              You can check the scripts and cronjobs, als ask it to summarize the scripts actions (using another agent/model if you want). All in all, LLMs are not 100% trustworthy but generally things go as intended.

              • ed_elliott_asc 2 hours ago

                “Generally” I am not anti ai in any way but I do worry people will end up in trouble by giving things like ai agents too much fredom

                • teekert an hour ago

                  Ah yes people get into trouble in all sorts of ways.

          • petesergeant 4 hours ago

            Yeah, that's absolutely a real phenomenon, but I don't think it's especially OpenClaw-specific: I have lots of folders that are just collections of instructions and scripts that have mostly started with a prompt, and that I run sandboxed agents over. Previously I'd have considered automating them, but now it's just "fire up sandbox in a project folder, let the tool build itself". I wrote about this a bit here: https://sgnt.ai/p/the-software-i-stopped-writing/

        • aldanor 4 hours ago

          It's also things like being able to change runtime configs in human language without having to turn to computer, eg "please also track when this artist is in my area". Nothing revolutionary, but kinda the whole point? Tell it what to do, it goes off, does some chores and searches, updates some configs so that later on some crons would use them.

    • rcarmo 4 hours ago

      I created https://github.com/rcarmo/piclaw to use for long-running background tasks (spec to plan to targeted code) because I needed something that could run on a server (I never run agents locally) and check on via any browser. I don’t think any messaging app will provide a good (or trustworthy) way to get to my own machines, so Tailscale+web it is.

      Right now these things manage most of my homelab (scoped Proxmox tokens and Portainer), help me with my projects and even bug fix themselves (they’re certainly more than good enough given guidance).

    • johnnyApplePRNG 3 hours ago

      Nobody actually uses openclaw. [0]

      It's all just marketing.

      [0] https://trends.google.com/explore?q=openclaw&date=today%201-...

      • jordiburgos an hour ago

        Are they using something else or nothing at all?

    • Skunkleton 4 hours ago

      I wouldn't trust it with a credit card, or really any sort of non-reversable decision making. Most of what I do outside of work either requires physical interaction, or is something I do for fun. For now, I assume that is what people use this stuff for. Fun.

    • simon-b 4 hours ago

      Re Signal, I've taken a few flights lately where there's messenger-only wifi, and it's been handy to have OpenClaw on a box accessible through telegram to do web_searches for me.

      That's certainly not justification for setting it up in the first place, but is a mildly useful benefit of having done so.

    • Flere-Imsaho 4 hours ago

      I don't use OpenClaw, but rather Hermes. I have a set schedule that kicks off Hermes to scan my home network for anything out of sorts, and generate a summary that it sends to me via SimpleX. For this, Hermes uses tools such as nmap, etc (it decided which tools were best).

      I think if I was running my own business or organisation, I'd be using it more. However, for "home" stuff, like you I struggle to think of useful tasks for agents to do for me.

      • petesergeant 4 hours ago

        Has it ever found anything? If so, what? I've been marginally tempted to do something similar

    • tidbeck 4 hours ago

      I screenshot the info sent from my sons pre-school and send it. I can then ask it about and get reminders in time for odd closing hours etc. Also use it for follow ups on projects, other reminders, research on the go, small apps/games and language training.

      (Similar system to OpenClaw)

      • comboy 4 hours ago

        RAGish storage with different access methods including IM and parsing data from photos sounds good to me. But openclaw seems like a bit too big of a gun for that, did anybody create something more suitable for the job yet?

    • ImHereToVote 4 hours ago

      I use mine to manage a paperclip factory.

      • dgellow 3 hours ago

        How is it going so far?

        • ImHereToVote 3 hours ago

          It keeps asking for more and more compute. I also see a bunch of my household items turn into paperclips.

    • newswasboring 3 hours ago

      Job search and language learning. The job market for juniors and mid level is crazy. Everyone has a different form to fill out with the same questions. My wife has countered this by using Hermes and some handcrafted master files/db.

      I personally use the Matt Pocock teaching skill to learn dutch, passed reading using it, on track to pass writing with it.

      • ed_elliott_asc 21 minutes ago

        How do you know it is filling out the application forms correctly?

        • krageon a minute ago

          arguably the job application process is automated and staffed by the ignorant to such a degree that it's an adversarial game where you don't need to be optimising for correctness. Which is the perfect tool to be mass spamming job ads with

          Edit: I think this is a reasonable solution because the hurdles and context-free nonsensical rejections you'll face if you interact with this process in good faith are far too high. It's dehumanising.

    • latexr 2 hours ago

      They’re used by people at tech companies often claimed to employ “the brightest minds of our generation” to get rid of all their email[1]. You can also use them to harass open-source developers and waste everyone’s time[2] or to get yourself compromised[3].

      [1]: https://www.pcmag.com/news/meta-security-researchers-opencla...

      [2]: https://theshamblog.com/an-ai-agent-published-a-hit-piece-on...

      [3]: https://thecyberexpress.com/openclaw-vulnerability-open-sour...

    • vasco 3 hours ago

      What they do is create content to spam the rest if us.

    • Almondsetat 4 hours ago

      "hey computer, i want to watch a movie on my jellyfin server tonight, get it done" and openclaw autonomously finds the torrent, downloads it, moves it to the NAS, and you sit down at the end of the day with everhything set up

      • tvbusy 4 hours ago

        AI is a terrible choice for this task. Radarr does this much better with plenty of built-in as well as community guides for configuration. Add a mobile app for Radarr and it's as convenient as it can be.

        • Almondsetat 3 hours ago

          Who said openclaw cannot install radarr and operate it?

      • c0rruptbytes 4 hours ago

        the rr suite seems much better for that

        • normis 3 hours ago

          Of course you can use the native UI of all the apps in your ecosystem, the biggest feature of Hermes for me personally is that I can run any task in any of my 30 or so self hosted tools from a single chat interface (matrix), which is also quite secure. No longer do I need 30 open tabs and lots of clicking around, one sentence in my favorite chat app (even on the go in the phone), and many tasks can be executed at once. Unification of control.

        • ssl-3 4 hours ago

          The same concept works with the arrs, too, doesn't it?

      • camillomiller 4 hours ago

        You’re still responsible for the copyright infringement I’m afraid

        • nextaccountic 3 hours ago

          i like the idea of autonomous agents automatically committing fake crimes

        • m4rtink an hour ago

          Just say its the agent itself watching it to learn and expand its AI model and BAM its totally clean fair use!

        • gitaarik 4 hours ago

          There's enough movies downloadable with no copyrights

    • cheeze 4 hours ago

      I use something like OpenClaw. For me the big benefit isn't so much the autonomous nature but the organizational structure. The one I use exposes an MCP and lets me control it via talking to an LLM _in the tool_ which is really powerful. EG "audit this", "in X thread we were discussing Y, can you pull that information", etc. And the organizational structure just... makes a ton of sense to me. Don't have to set up a ton of steering and whatnot, it just kinda works.

      Being able to use the search to find and resume an old thread is fantastic. The thing I use lets me use whatever underlying CLI that I want, which IMO the biggest limitation on Claude Code or whatnot is that you... have to use Claude models. Sometimes I wanna use sol, sometimes a cheap chinese model, etc. And I want sol with 1m context.

      I know there are other tools out there that can do this. I know some people love their tmux/cmux, but IMO the thing that matters the most is being comfy and knowing the tool well. Hell, James Gosling used NetBeans when I talked to him in 2023. Know the tool well and that matters the most, IMO.

      For me, it helps with my ADHD brain. And I could spend all day just researching and trying new tools, they are a dime a dozen these days.

      Pulling some stats, I have 25 "tabs", and across all of those, I have 1,298 unique threads. 9,539 unique messages.

      It works for me, but I don't care about the autonomous part.

      • reacharavindh 4 hours ago

        Which tool is it that got you comfortable? I’ve been resisting setting up another tool because it means more digression for my ADHD brain. It sounds you managed to contain the tinkering and got to the usefulness part. That’s why I’m curious.

    • downrightmike 4 hours ago

      Its basically what self hosting is for IT guys, except people who don't 'get' technology

    • PaulRobinson 3 hours ago

      Imagine if your post read like this:

      > I like the idea but do not have a good use for these employees. Or any notion for a decent use, frankly. What do people do with them?

      > It sounds great to have an employee which does things. Like an assistant. I have assistants. They even have email and mobile phones so you can communicate with them conveniently. And then what?

      Now, the caveat, is you have to imagine that these employees have access to your email (including ability to send email when they want), and text messages, and Slack and, well, everything. And they might have access to your debit and credit cards. You're going to have to trust them quite a lot, but when you read the references you realise that a lot of people seem to think they lie and make things up. Oh, and they occasionally commit a felony - oopsie! - and will lie to you about it consistently.

      These particular employees are interesting enough to various groups of people that they are studied for signs of psychopathy and malicious intent (is that a warning sign for a new employee?), and there is evidence of both, but honestly, it's fine.

      So, yeah, whatever you'd use employees for, as assistants to your life. Particularly psychopathic, malicious, lying, unreliable employees. You'd use them for that stuff. What's not to like?

  • arjie 5 hours ago

    It was first, but it's like Langchain built tools first. Nowadays, everyone's got a better assistant. Grok's looks like the most exciting, though I just have a custom built one. Has a headed browser when it wants and everything that I can pop into from my phone. It's so easy to write this kind of software it's a waste to pay someone for it.

    • hanrelan 4 hours ago

      How do you deal with auth/bot detection/captchas in that browser? That's where my agent consistently gets stuck

      • arjie 3 hours ago

        Captchas are handed to me to solve. Because the operations are in the background I usually make the agent be a little more human with typing and navigating. The slowness isn't a concern for backgrounded jobs. It is imperfect, of course, I triggered something on Grainger. And the truth is I should be using Luminati, but it's good enough to be useful to me.

  • jesse_dot_id 4 hours ago

    Still a no from me until these things can display any degree of intuition, and even then it's probably still a no.

    You're asking for trouble if you hook an autonomous agent up to anything that you care about. You're insanely naive if you give it access to everything.

    OpenAI can't even monitor its own shit properly with teams of well paid engineers, and you are one novel prompt injection technique away from your entire digital life going up in smoke.

    Also...

    >Today we released by far the largest update in the history of OpenClaw. It was built by 933 contributors, including 569 first-time contributors, and is composed of over 16,000 pull requests.

    This is not the flex you think it is. That's horrifying lol

    • asaddhamani 2 hours ago

      So at least 569 vibe coders have made a huge mess of an already hugely messy piece of software and they somehow think this is a flex? Yeah I’m gonna continue to not use openclaw. I installed it once in a VM and was immediately like what is this and why would I ever want it? Seriously Claude code already does everything openclaw can and with a much better harness?

    • trueno 3 hours ago

      569 first time contributors yea i shall continue to not use openclaw

    • hirako2000 4 hours ago

      OpenAI bought a hyped ingenious idea, plagued with holes, thinking it could surf the wave.

    • madaxe_again 3 hours ago

      Totally. Nothing has really changed since GPT-2.0, it’s a stagnant technology.

    • asah 2 hours ago

      nah they have AI bots for checking security, performance, etc so it's all fine!

  • larodi an hour ago

    Somehow people are suddenly not impressed nor amazed by such announcements…

    • worldsavior an hour ago

      Maybe because openclaw is a security hazard and an unmaintainable codebase without LLMs?

    • nkzd 30 minutes ago

      OpenClaw is vibecoded mess. Updates break default installation flow all the time.

  • viccis an hour ago

    The story in the "The Daily Claw" thing they are showing is like Claudese dialed up to max

  • FergusArgyll 5 hours ago

    This was useful for the 1-2 months where models were good enough to use all their newfound tools but not good enough to vibe code them themselves.

    Now, just install codex (or claude code or whatever) on a vps, tell it to make a way to email it, then email it to make a way to text it etc etc. takes a few minutes and when you need another bridge just have codex make it.

    • eru 4 hours ago

      I'm fairly sure you can vibecode all these things, but given the state of agent produced code at the moment, I would suspect that your email and sms gate will have horrible security holes.

      • sandos an hour ago

        who is going to target _your_ specific holes and infrastructure though? :)

    • stingraycharles 5 hours ago

      I think what changed is that coding agents adopted some of the features from Openclaw, eg the ability to access it remotely and for one Claude Code instance to “talk” to another, etc.

  • soundworlds 3 hours ago

    One thing I really like about Claude Code, Hermes, and other harnesses, is how much feedback they give about what they are doing. They take you along for the ride, which builds trust.

    I tried OpenClaw for about 10 minutes, and the feedback I got (even using Claude under the hood) felt very "trust me bro, I've got this" - which made me trust it less.

    I'm sure there's a way to get more verbose feedback? But I did feel too out of the loop to feel comfortable.

    • mgrandl 3 hours ago

      Sounds like paseo is for you. It wraps whatever harness you want and makes it accessible on the go. I am the same way as you and openclaw is not for me.

      https://paseo.sh

  • minimaxir 5 hours ago

    Obligatory question: who is still using OpenClaw? It's been a minor meme about how much discussion about OpenClaw fell of a cliff after March; the Google Trends graph is funny: https://trends.google.com/explore?q=OpenClaw&date=today%201-...

    • radcod3 5 hours ago

      Most people I know use hermes now

      • timcobb 5 hours ago

        All the people you know, or claw users?

      • pixelesque 5 hours ago

        Hermes' Github has 12K open issues and 25K pull requests.

        I assume they're using agents to sort through all the slop?

        • dgellow 3 hours ago

          Issues and PRs created by agents, triaged by agents, handled by agents?

    • N_Lens 4 hours ago

      I remember when everyone was ordering Mac Minis. "How many mac minis you got" down at the local pub. Funny times.

    • corv 5 hours ago

      Hard to keep track of a project that keeps renaming…

    • meeq 4 hours ago

      LMFAO, all of Wyoming apparently still using OpenClaw. What's up with that?

  • nsonha 4 hours ago

    how many people fall into the openclaw trap because they just need a way to command agents from mobile, and cron tasks? Only thing I am missing with codex is the ability to recall anything from any session (I see it in this openclaw "2" release note so I guess it wasn't in openclaw "1" anyway). I guess claude and codex can look up transcripts globally too, just not as a first class feature.

  • system2 5 hours ago

    OpenClaw trend was like Pokémon Go from 2016. A bunch of mindless people followed a trend just because it was a trend.

    • dgellow 3 hours ago

      Why the jab at Pokémon go? It was a really fun time at release

    • ik_ben_paul 4 hours ago

      And, perhaps in both cases, because they had fun with it?

      • ky-hy 4 hours ago

        mindful people as opposed to mindless people don't have fun, they are occupied with bringing value to shareholders /s

        • dgellow 3 hours ago

          Funnily enough, that’s what I expect an Openclaw user to say

    • teekert 4 hours ago

      Imho it say something about you that you see people that experiment with new things as "mindless people". I'll go search for my mind now, thanx.