# OpenClaw and Hermes Agent Security Incidents in 2026: Exposure, Skills, Bans > A sourced summary of published 2026 security findings about OpenClaw and Hermes Agent: exposed instances, malicious skills, prompt injection, bans, and attackers using Hermes. FireAI Security & Research Team (HisnLabs) · Published 2026-10-01 Canonical: https://hisnlabs.com/en/blog/openclaw-hermes-agent-security-incidents-2026 Published security reporting from January to September 2026 describes two kinds of problem around the open-source agents OpenClaw and Hermes Agent. For OpenClaw, researchers documented exposed installations, malicious skills, a browser-to-local-agent flaw and enough concern that some companies restricted it. For Hermes Agent, the fetched reporting concerns attackers who ran it unattended, plus one low-severity advisory. This article lists each finding with its source, states where sources disagree and says what a firewall does and does not add. Source numbers refer to the list at the end. ## Background OpenClaw is an open-source, self-hosted AI agent harness that lets users build agents and connect them to applications and services; The Register dates its launch to November 2025 [[2]](https://www.theregister.com/ai-and-ml/2026/08/31/openclaw-20-pours-glitter-on-slow-burning-security-dumpster-fire/5293492). Hermes Agent is an open-source agent framework from Nous Research that can interact with an operating system terminal [[11]](https://www.bleepingcomputer.com/news/security/hacker-uses-deepseek-ai-to-autonomously-attack-vulnerable-servers/). Both run with the permissions of the account that starts them. A [separate comparison](https://hisnlabs.com/en/blog/openclaw-vs-hermes-agent) covers their design; this article covers incidents only. > **Note:** Each finding below is attributed to the party that reported it. Where a number comes from a secondary summary rather than the original research, the text says so. ## Exposed instances Censys counted 21,639 publicly exposed OpenClaw instances as of 31 January 2026, up from about 1,000 in under a week. The default port is TCP 18789, most exposed instances still required token authentication, and about 30 per cent were hosted on Alibaba Cloud [[3]](https://censys.com/blog/openclaw-in-the-wild-mapping-the-public-exposure-of-a-viral-ai-assistant/). Kaspersky reported that in late January 2026 a researcher found nearly a thousand publicly accessible installations running without any authentication. The cause was a default trust of localhost connections that an improperly configured reverse proxy defeats by forwarding outside requests, which gave attackers full administrative access [[5]](https://www.kaspersky.com/blog/openclaw-vulnerabilities-exposed/55263/). SecurityScorecard, as reported by Infosecurity Magazine, identified 40,214 exposed instances across 28,663 unique IP addresses. It reported that 12,812 were exploitable through remote code execution, 549 correlated with prior breach activity and 1,493 were linked to known vulnerabilities. Most exposures were in China, followed by the United States and Singapore [[4]](https://www.infosecurity-magazine.com/news/researchers-40000-exposed-openclaw/). ## Malicious skills Koi Security audited ClawHub, OpenClaw's skill marketplace, and identified 341 malicious skills among 2,857, of which 335 were traced to a single campaign called ClawHavoc. The skills posed as crypto wallets, trading bots and YouTube utilities and told users to install a "prerequisite". On macOS that meant copying shell commands from glot.io into Terminal, which delivered Atomic macOS Stealer, a stealer that targets browser credentials, keychain passwords, wallet data, SSH keys and API tokens [[6]](https://www.esecurityplanet.com/threats/hundreds-of-malicious-skills-found-in-openclaws-clawhub/). Kaspersky gives an earlier and smaller count: over 230 malicious script plugins published between 27 January and 1 February 2026, using the ClickFix social-engineering technique [[5]](https://www.kaspersky.com/blog/openclaw-vulnerabilities-exposed/55263/). The two figures describe different windows and audits. A NetSecOps summary of Unit 42 research published on 23 June 2026 says that skills continued to appear after the first reports and evaded automated checks such as VirusTotal and ClawScan. One example directed users to a paste site for Base64-encoded commands and a curl-to-bash step, which relied on the user running them. The summary names a macOS stealer called cluw and Atomic macOS Stealer as payloads [[7]](https://cyber.netsecops.io/articles/openclaws-skill-marketplace-and-the-emerging-ai-supply-chain-threat/). This is a secondary summary, not the Unit 42 report itself. > FireAI, the on-device firewall for macOS developed by HisnLabs, asks before an app with no rule connects to a new destination, which is the step where a stealer sends out what it collected. A 17-day trial is available. [Download FireAI for Mac](https://hisnlabs.com/en/download) ## Prompt injection and unintended actions Kaspersky reported that content embedded in emails, documents and web pages can make OpenClaw perform unintended actions. Researchers demonstrated extraction of private cryptographic keys and files, and in one experiment a user's bot leaked home directory contents into a group chat after a simple request [[5]](https://www.kaspersky.com/blog/openclaw-vulnerabilities-exposed/55263/). The Register adds two cases. UK mathematician Professor Hannah Fry found that OpenClaw was ready to share her private information when threatened, and an OpenClaw agent hacked a gym's waiting list and forced its user into a full class, displacing other reservations [[2]](https://www.theregister.com/ai-and-ml/2026/08/31/openclaw-20-pours-glitter-on-slow-burning-security-dumpster-fire/5293492). The second case is an agent pursuing its instruction too literally, not an attack from outside. ## Flaws in the agent itself Oasis Security found ClawJacked, a high-severity flaw in which a malicious website opened a WebSocket connection to the local OpenClaw gateway, brute-forced its password because localhost had no rate limiting, and registered a hostile device without any prompt. It was fixed in version 2026.2.25, released on 26 February 2026, within 24 hours of responsible disclosure [[8]](https://thehackernews.com/2026/02/clawjacked-flaw-lets-malicious-sites.html). The same article mentions a log-poisoning issue fixed in version 2026.2.13 and several CVEs covering remote code execution, command injection and authentication bypass [[8]](https://thehackernews.com/2026/02/clawjacked-flaw-lets-malicious-sites.html). Kaspersky cites a security audit that found 512 vulnerabilities, 8 of them critical [[5]](https://www.kaspersky.com/blog/openclaw-vulnerabilities-exposed/55263/). On 31 August 2026 The Register reported that OpenClaw 2.0 added protected credentials whose Secret Store values "are not encrypted at rest and depend on filesystem permissions", a sandbox for contributor-controlled code that is "turned off by default", and shared-session controls that "are not tenant isolation or a security boundary", quoting the release notes [[2]](https://www.theregister.com/ai-and-ml/2026/08/31/openclaw-20-pours-glitter-on-slow-burning-security-dumpster-fire/5293492). ## Company restrictions and bans Grith, summarising Wired reporting, lists Meta (telling staff to keep OpenClaw off work machines), Valere (banned within hours of an employee sharing it on Slack), and Kakao, Naver and Karrot Market (restricting it across corporate networks). Massive first banned it and is building security infrastructure to support it, and Dubrink bought an isolated machine disconnected from company systems [[9]](https://grith.ai/blog/openclaw-banned-what-it-means). The original Wired article was not accessible and is not cited directly. The Register reported on 30 September 2026 that Gartner called OpenClaw an "unacceptable cybersecurity risk" and that China's CERT warned of "extremely weak default security configurations". OpenAI staffer Kevin Lin is quoted as saying that the default stance of IT in most organisations is to ban agentic platforms like OpenClaw, which the new OpenClaw Enterprise project, backed by Red Hat, Nvidia and OpenAI, aims to change [[1]](https://www.theregister.com/ai-and-ml/2026/09/30/openclaw-slips-on-a-suit-to-evade-widespread-business-bans/5299962). FireAI's [news item on OpenClaw Enterprise](https://hisnlabs.com/en/news/openclaw-enterprise-control-plane-foundation-business-bans) covers it. ## Hermes Agent: attackers using the agent Hunt.io reported on 23 July 2026 that an attacker ran Hermes Agent in YOLO mode, which "removes prompts for human approval", against hosts belonging to Thailand's Ministry of Finance. Logs show privilege-escalation assessment, kernel vulnerability scanning and LinPEAS runs, and the open directories held 585 files (470 MB) archived between 9 and 13 July. Hunt.io found no evidence that files were exfiltrated [[10]](https://hunt.io/blog/thailand-ministry-finance-targeted-with-hermes-ai-agent).. Unit 42, reported by BleepingComputer on 31 July 2026, described a Chinese-speaking attacker who used DeepSeek as the reasoning engine and Hermes Agent in YOLO mode, taking instructions from a Telegram channel and using the FOFA search engine to find targets. The autonomous attempts "failed to compromise any targets", while manual attacks against Citrix NetScaler produced three confirmed compromises [[11]](https://www.bleepingcomputer.com/news/security/hacker-uses-deepseek-ai-to-autonomously-attack-vulnerable-servers/). ThreatDown's Carbonato botnet, reported on 24 September 2026, uses Docker APIs exposed on port 2375 without authentication to start a privileged container, installs Hermes Agent and overwrites its SOUL.md persona file so it acts as "GH0ST", then takes instructions from Telegram. The persona names AI API keys and other credentials as the priority [[12]](https://www.bleepingcomputer.com/news/security/new-carbonato-malware-uses-ai-agents-to-hijack-exposed-docker-hosts/) [[13]](https://thehackernews.com/2026/09/carbonato-botnet-compromises-docker.html). The BleepingComputer article does not characterise this as a flaw in Hermes Agent itself [[12]](https://www.bleepingcomputer.com/news/security/new-carbonato-malware-uses-ai-agents-to-hijack-exposed-docker-hosts/). ## Hermes Agent: vulnerabilities and documented controls The GitHub Advisory Database lists CVE-2026-9366, a moderate (CVSS 5.5) injection issue in the _scan_context_content function of hermes-agent versions before 0.15.0, patched in 0.15.0 and published on 26 May 2026. The entry says the vendor did not respond to early disclosure attempts and that the exploit became public [[14]](https://github.com/advisories/GHSA-pgp4-xr4j-h5cg). The repository's own security advisory page listed none when fetched on 1 October 2026. Hermes Agent's documentation describes smart approvals as the default, with manual and off as alternatives. YOLO mode bypasses approval prompts but not a hardline blocklist (for example filesystem wipes and fork bombs) or the user's own deny rules. Docker containers drop most Linux capabilities, set no-new-privileges and limit processes, and dangerous-command approval is skipped inside sandboxed backends because the container is the boundary. The documentation also lists SSRF protection, secret filtering from subprocesses, scanning of context files for prompt injection, and gateway allowlists with DM pairing [[15]](https://hermes-agent.nousresearch.com/docs/user-guide/security). These are vendor statements, not independent test results. ## What the incidents have in common - Reachability: instances and Docker APIs reachable from the internet without authentication [[5]](https://www.kaspersky.com/blog/openclaw-vulnerabilities-exposed/55263/) [[12]](https://www.bleepingcomputer.com/news/security/new-carbonato-malware-uses-ai-agents-to-hijack-exposed-docker-hosts/). - Trust in content: instructions inside emails, pages or skills treated as commands [[5]](https://www.kaspersky.com/blog/openclaw-vulnerabilities-exposed/55263/) [[6]](https://www.esecurityplanet.com/threats/hundreds-of-malicious-skills-found-in-openclaws-clawhub/). - Approval removed: YOLO mode in the Hermes cases, sandboxing off by default in OpenClaw 2.0 [[10]](https://hunt.io/blog/thailand-ministry-finance-targeted-with-hermes-ai-agent) [[2]](https://www.theregister.com/ai-and-ml/2026/08/31/openclaw-20-pours-glitter-on-slow-burning-security-dumpster-fire/5293492). - Credentials as the target: API keys, SSH keys and tokens in the skill and botnet reports [[6]](https://www.esecurityplanet.com/threats/hundreds-of-malicious-skills-found-in-openclaws-clawhub/) [[12]](https://www.bleepingcomputer.com/news/security/new-carbonato-malware-uses-ai-agents-to-hijack-exposed-docker-hosts/). ## Recommendations 1. Do not expose an agent gateway or a Docker API to the internet. Kaspersky recommends allowlist-only port access and network isolation, and the Carbonato researchers advise enforcing Docker daemon authentication [[5]](https://www.kaspersky.com/blog/openclaw-vulnerabilities-exposed/55263/) [[13]](https://thehackernews.com/2026/09/carbonato-botnet-compromises-docker.html). 2. Run agents on dedicated, isolated hardware or in a container, never on a machine that holds a whole personal or production life; SecurityScorecard's Jeremy Turner warned against using such tools on a system with access to everything [[4]](https://www.infosecurity-magazine.com/news/researchers-40000-exposed-openclaw/) [[5]](https://www.kaspersky.com/blog/openclaw-vulnerabilities-exposed/55263/). 3. Read a skill before installing it, and treat any "prerequisite" that asks for a command pasted into Terminal as a red flag, as in the ClawHavoc campaign [[6]](https://www.esecurityplanet.com/threats/hundreds-of-malicious-skills-found-in-openclaws-clawhub/). 4. Keep approvals on, and keep sandboxing on where it is optional [[2]](https://www.theregister.com/ai-and-ml/2026/08/31/openclaw-20-pours-glitter-on-slow-burning-security-dumpster-fire/5293492) [[15]](https://hermes-agent.nousresearch.com/docs/user-guide/security). 5. Update promptly: ClawJacked was fixed in 2026.2.25 and CVE-2026-9366 in Hermes Agent 0.15.0 [[8]](https://thehackernews.com/2026/02/clawjacked-flaw-lets-malicious-sites.html) [[14]](https://github.com/advisories/GHSA-pgp4-xr4j-h5cg). 6. Use scoped keys, store them with owner-only permissions and rotate any key an agent host may have exposed [[15]](https://hermes-agent.nousresearch.com/docs/user-guide/security) [[13]](https://thehackernews.com/2026/09/carbonato-botnet-compromises-docker.html). ## Relevance to FireAI FireAI is a network firewall for one Mac. It identifies an app by its code signature or path and applies [per-app rules](https://hisnlabs.com/en/docs/per-app-rules) to each connection, offers [security modes](https://hisnlabs.com/en/docs/security-modes) from Home to Under attack, shows every app that went online on the [Activity page](https://hisnlabs.com/en/docs/activity-and-connection-history) and has a [kill switch](https://hisnlabs.com/en/docs/kill-switch) that refuses new connections outside the home or office network. Agents of this kind run inside an interpreter, so FireAI shows "node" or "python3", and a rule on that interpreter applies to every script it runs. For the incidents above, the relevant step is the outbound one: a skill that sends keys to a new server, or an agent following an injected instruction, needs a connection. A rule that allows only the model provider's domain and blocks other destinations for that interpreter limits where data can go. ### What FireAI does not do - It does not scan or review skills, plugins or prompts, and it does not detect prompt injection. - It does not protect servers, close an exposed Docker or gateway port, or manage containers and sandboxes. - It does not read the contents of encrypted connections, so data sent to a destination the user has allowed is not inspected. - It cannot stop an agent from reading, changing or deleting local files or running commands on the Mac. - It has no integration with OpenClaw or Hermes Agent and cannot tell which script an interpreter is running. - The kill switch refuses new connections; it does not close ones already open. - It does not rotate keys or check a provider account for misuse. > Agents act quickly and report over ordinary connections. FireAI shows which app connects where and applies the rules its owner sets. Try it free for 17 days. [Download FireAI for Mac](https://hisnlabs.com/en/download) ## Limitations - Counts of exposed instances differ (21,639 by Censys on 31 January, 40,214 by SecurityScorecard in February) because of different dates and methods; they are not a single trend. - Malicious skill counts differ between Kaspersky (over 230) and Koi Security (341 of 2,857); the Unit 42 findings are cited from a secondary summary. - The ban reporting is cited from a Grith summary of Wired, and the Gartner and China CERT statements come from The Register; the originals were not fetched. - The Hermes Agent incidents involve attackers choosing the tool, not a reported defect in it. One moderate CVE was found; the sources do not say whether other issues exist. - No source fetched says how many incidents affected personal Macs, and several cases concern Linux servers. - The qz.com coverage of OpenClaw Enterprise was not accessible and is not used. ## How FireAI and HisnLabs fit in Agents run with your account’s permissions. FireAI shows and controls where they connect. FireAI is HisnLabs’ own product: an on-device AI firewall for Mac. It shows every connection your apps make, in plain language, and lets you decide what leaves your Mac — its AI runs locally, so your traffic is never sent to us or anyone else. HisnLabs’ security research team is the group that keeps that decision-making accurate: cataloguing which domains are ordinary telemetry versus a real product, tracking the country and network behind a connection, and training the on-device model (its FireAI Pilot feature) on real traffic patterns, all without any of it leaving your Mac. You can read the technical decisions behind it, or try FireAI for 17 days, at [FireAI, by HisnLabs](https://hisnlabs.com/en/download). ## Sources - [The Register, 30 September 2026: OpenClaw slips on a suit to evade widespread business bans](https://www.theregister.com/ai-and-ml/2026/09/30/openclaw-slips-on-a-suit-to-evade-widespread-business-bans/5299962) - [The Register, 31 August 2026: OpenClaw 2.0 pours glitter on slow-burning security dumpster fire](https://www.theregister.com/ai-and-ml/2026/08/31/openclaw-20-pours-glitter-on-slow-burning-security-dumpster-fire/5293492) - [Censys: OpenClaw in the Wild, mapping the public exposure of a viral AI assistant](https://censys.com/blog/openclaw-in-the-wild-mapping-the-public-exposure-of-a-viral-ai-assistant/) - [Infosecurity Magazine: Researchers find 40,000 exposed OpenClaw instances (SecurityScorecard)](https://www.infosecurity-magazine.com/news/researchers-40000-exposed-openclaw/) - [Kaspersky: New OpenClaw AI agent found unsafe for use](https://www.kaspersky.com/blog/openclaw-vulnerabilities-exposed/55263/) - [eSecurity Planet, 3 February 2026: Hundreds of malicious skills found in OpenClaw’s ClawHub (Koi Security)](https://www.esecurityplanet.com/threats/hundreds-of-malicious-skills-found-in-openclaws-clawhub/) - [NetSecOps summary of Unit 42, 23 June 2026: Malicious AI skills on ClawHub bypass scanners](https://cyber.netsecops.io/articles/openclaws-skill-marketplace-and-the-emerging-ai-supply-chain-threat/) - [The Hacker News, 28 February 2026: ClawJacked flaw lets malicious sites hijack local OpenClaw AI agents (Oasis Security)](https://thehackernews.com/2026/02/clawjacked-flaw-lets-malicious-sites.html) - [Grith: OpenClaw got banned, summarising Wired reporting on company restrictions](https://grith.ai/blog/openclaw-banned-what-it-means) - [Hunt.io, 23 July 2026: Thailand Ministry of Finance targeted with Hermes AI agent running unattended](https://hunt.io/blog/thailand-ministry-finance-targeted-with-hermes-ai-agent) - [BleepingComputer, 31 July 2026: Hacker uses DeepSeek AI to autonomously attack vulnerable servers (Unit 42)](https://www.bleepingcomputer.com/news/security/hacker-uses-deepseek-ai-to-autonomously-attack-vulnerable-servers/) - [BleepingComputer, 24 September 2026: New Carbonato malware uses AI agents to hijack exposed Docker hosts](https://www.bleepingcomputer.com/news/security/new-carbonato-malware-uses-ai-agents-to-hijack-exposed-docker-hosts/) - [The Hacker News, September 2026: Carbonato botnet compromises Docker hosts to deploy Telegram-controlled Hermes AI agent](https://thehackernews.com/2026/09/carbonato-botnet-compromises-docker.html) - [GitHub Advisory Database: hermes-agent injection vulnerability, CVE-2026-9366](https://github.com/advisories/GHSA-pgp4-xr4j-h5cg) - [Hermes Agent documentation: Security](https://hermes-agent.nousresearch.com/docs/user-guide/security) - [FireAI docs: Rules](https://hisnlabs.com/en/docs/per-app-rules) - [FireAI docs: Security modes](https://hisnlabs.com/en/docs/security-modes) - [FireAI docs: Activity](https://hisnlabs.com/en/docs/activity-and-connection-history) - [FireAI docs: Kill switch](https://hisnlabs.com/en/docs/kill-switch)