---
title: "大量 OpenClaw 网关暴露于互联网 · DotsAgent"
description: "Censys 统计显示，2026 年 1 月 31 日有 21,639 个 OpenClaw 网关可从公共互联网访问；OpenA2A 的索引显示，9 月 1 日这一数字达到 192,492。"
url: https://dotsagent.io/zh/security/incidents/2026-openclaw-gateways-exposed
---

2026年1月31日

# 大量 OpenClaw 网关暴露于互联网

Censys 统计显示，2026 年 1 月 31 日有 21,639 个 OpenClaw 网关可从公共互联网访问；OpenA2A 的索引显示，9 月 1 日这一数字达到 192,492。

## 事件经过

从 2026 年 1 月开始，研究人员开始统计可从公共互联网访问的 OpenClaw 网关。Censys 发现，1 月 31 日有 21,639 个，3 月 31 日有 63,070 个。SecurityScorecard STRIKE 在 2 月统计出约 40,000 到 42,900 个，其中约 15,200 个似乎容易受到远程代码执行攻击。到 2026 年 9 月 1 日，OpenA2A 的索引达到 192,492 个。

根据统计方法不同，数字最多相差十倍：可能是默认端口 18789 上 Shodan 扫描到的原始结果、经指纹确认的主机，或唯一 IP 地址。OpenA2A 在 3 月的扫描发现 Shodan 上有 249,366 条结果，其中约 30% 得到确认，据此估算约有 75,000 个。

## 攻击奏效的原因

默认情况下，网关绑定到 loopback；但在容器内，gateway.bind 会自动解析为 0.0.0.0，而设置为任何其他绑定值都会使网关暴露在网络上。OpenA2A 报告称，默认配置缺少身份验证；这适用于较早的版本，而当前文档要求配置令牌，并会在未配置时默认拒绝访问。

## 应对措施

- 仅将网关绑定到 loopback；如需远程访问，请使用 SSH 隧道或 Tailscale Serve。
- 在 Docker 中，仅将端口 18789 发布到 127.0.0.1，或完全不发布。
- 使用至少 24 个字符的网关令牌，例如通过 openssl rand -hex 32 生成。
- 运行 openclaw security audit --deep，并修复报告中指出的问题。
- 从网络外部扫描你的公网 IP 地址，检查端口 18789 是否开放。

[不要将控制面暴露到互联网](https://dotsagent.io/zh/security#noPublicControlPlane)[对代码和工具执行进行沙箱隔离](https://dotsagent.io/zh/security#sandboxing)

- [Moltbook 数据库泄露 1.5M 个 agent API token](https://dotsagent.io/zh/security/incidents/2026-01-moltbook-database-exposure)

- [OpenClaw Control UI 泄露 gateway token，导致一键 RCE](https://dotsagent.io/zh/security/incidents/2026-01-openclaw-control-ui-rce)

[查看安全检查清单 →](https://dotsagent.io/zh/security/checklist)

## 来源

1. [blog.cyberdesserts.com](https://blog.cyberdesserts.com/openclaw-exposure-numbers-explained/)/openclaw-exposure-numbers-explained/
2. [research.opena2a.org](https://research.opena2a.org/indices/exposure-prevalence)/indices/exposure-prevalence

为 AI agent 开发者提供的独立参考资料。与此处提及的任何厂商均无关联。

© 2026 DotsAgent · 事实核查日期：2026年10月1日
