From the source
A lot of people screamed it was so insecure.
Open source is supposed to be the unsafe option because everyone can see the code.
Sure.
People used it anyway, loved it, and now companies run it in production.
Those same companies are the ones now helping us secure it.
Nothing that can run tools, hold credentials and install plugins is safe by default.
But being open is why we got safer quickly, in public.
Why So Many Reports?
OpenClaw launched into a weird moment for open source security.
In January, curl killed its bug bounty program after drowning in reports that sounded technical, referenced real functions and contained nothing exploitable.
Daniel Stenberg called it “death by a thousand slops.”
Plus, we are the most-watched AI agent project in the world.
Every CVE against OpenClaw is a career trophy, so of course people look.
As of April 30, GitHub shows 1,309 security advisories since January 10. 535 were published. 746 were closed as invalid.
The number coming in has dropped significantly over the last few months as we hardened the whole system.
…





