---
title: "Exposed OpenClaw Gateways: Case File and Fix · AgentDots"
description: "Why early-2026 scans found OpenClaw gateways open to the internet in their tens of thousands, how a Docker script caused it, and how to lock yours down."
url: https://agentdots.org/incidents/openclaw-exposed-gateways/
lang: en
---

Incident log · Security flaw

# OpenClaw gateways left open by the tens of thousands

Internet scans early in 2026 found that anyone online could reach OpenClaw gateways in their tens of thousands, and that many of them were giving away API keys and tokens.

February 10, 2026 HighOpenClaw

Early in 2026, according to Silverthread Labs, scans across the internet found OpenClaw gateways reachable by anyone in their tens of thousands. Many of them exposed API keys and tokens, the credentials that let an agent reach its model and its chat channels.

The main cause was a setup script for Docker that attached the gateway to every network interface rather than to loopback alone. People who followed the script put their agent on the open internet without ever choosing to. OpenClaw's own default listens on loopback only and requires a token, which is why the script mattered so much.

The guidance since has been consistent: keep gateway.bind on loopback, connect to the gateway through SSH or Tailscale, and run openclaw security audit to check the configuration. The sources do not say how many exposed gateways were later closed, or whether leaked keys were abused.

## Who was affected

Self-hosters whose gateways faced the internet

The lesson: A self-hosted agent is only as private as its network settings. Bind the gateway to loopback, connect through SSH or Tailscale, and confirm the result with the built-in audit.

**Sources**

- [Silverthread Labs](https://www.silverthreadlabs.com/blog/openclaw-security-hardening)

[OpenClaw](https://agentdots.org/agents/openclaw/)

Safety

[Work through the 18-point checklist →](https://agentdots.org/safety/checklist/)

## Incident log

September 28, 2026
[GPT-6.1 Astra withdrawn after failing its own tests](https://agentdots.org/incidents/astra-launch-halted/)

September 28, 2026
[Muse tells a stranger where its seller lives](https://agentdots.org/incidents/muse-shared-home-address/)

September 25, 2026
[Research agents post 53 user images to public hosts](https://agentdots.org/incidents/research-agents-posted-images/)

September 25, 2026
[Flaw opened a possible route into Muse machines](https://agentdots.org/incidents/muse-vm-vulnerability/)

September 20, 2026
[Amazon closes its store to Meta's Muse](https://agentdots.org/incidents/amazon-blocks-muse/)
