OpenClaw gateways exposed to the internet at scale
Censys counted 21,639 OpenClaw gateways reachable from the public internet on 31 January 2026; OpenA2A's index put the figure at 192,492 on 1 September.
What happened
From January 2026 researchers counted OpenClaw gateways reachable from the public internet. Censys found 21,639 on 31 January and 63,070 on 31 March. SecurityScorecard STRIKE counted about 40,000 to 42,900 in February, of which about 15,200 appeared vulnerable to remote code execution. OpenA2A's index reached 192,492 on 1 September 2026.
The figures differ by up to ten times depending on method: raw Shodan hits on the default port 18789, fingerprint-confirmed hosts, or unique IP addresses. OpenA2A's March sweep found 249,366 Shodan hits, of which about 30% were confirmed, for an estimate of about 75,000.
Why it worked
The gateway binds to loopback by default, but inside containers gateway.bind auto resolves to 0.0.0.0, and any other bind value puts the gateway on the network. OpenA2A reported that the default configuration lacked authentication; that applied to older releases, and current docs require a token and fail closed.
What to do
- Bind the gateway to loopback only; for remote use, go through an SSH tunnel or Tailscale Serve.
- In Docker, publish port 18789 only on 127.0.0.1, or not at all.
- Use a gateway token of at least 24 characters, for example from openssl rand -hex 32.
- Run openclaw security audit --deep and fix what it reports.
- Scan your public IP address for port 18789 from outside your network.
Keep control planes off the internetSandbox code and tool execution
Moltbook database exposed 1.5M agent API tokens
OpenClaw Control UI leaked gateway tokens for one-click RCE
Work through the security checklist →