Early in 2026, according to Silverthread Labs, scans across the internet found OpenClaw gateways reachable by anyone in their tens of thousands. Many of them exposed API keys and tokens, the credentials that let an agent reach its model and its chat channels.
The main cause was a setup script for Docker that attached the gateway to every network interface rather than to loopback alone. People who followed the script put their agent on the open internet without ever choosing to. OpenClaw's own default listens on loopback only and requires a token, which is why the script mattered so much.
The guidance since has been consistent: keep gateway.bind on loopback, connect to the gateway through SSH or Tailscale, and run openclaw security audit to check the configuration. The sources do not say how many exposed gateways were later closed, or whether leaked keys were abused.
Who was affected
Self-hosters whose gateways faced the internet
The lesson: A self-hosted agent is only as private as its network settings. Bind the gateway to loopback, connect through SSH or Tailscale, and confirm the result with the built-in audit.