AI News Today
← All episodes
Episode 1 · February 13, 2026 · 17:32

OpenClaw: Watch This BEFORE Using It...

Julian Goldie explains how to automate any web task using autonomous AI. Say goodbye to manual scraping and broken selectors. Learn how AI navigates websites, extracts data, and bypasses bot detection with OpenClaw.


TIMESTAMPS

00:00 Welcome & Intro

01:15 Why Manual Scraping is Dead

02:45 How Autonomous AI Navigates Websites

04:30 Bypassing Bot Detection

06:00 Scaling with OpenClaw

Full transcript

An open source AI agent just hit 160,000 github stars in 60 days, it was built by one guy in a weekend. And it didn't just go viral on twitter, it spawned its own social network where 1.5 million AI bots talk to each other, argue with each other, upvote each other and humans are not allowed to participate. IBM called it a black mirror version of reddit, Andrej Karpathy called it the most incredible sci-fi takeoff agent thing he'd ever seen, and Kaspersky's security team basically said the whole thing is a live fire security disaster. This is open core, whether you think it's the future of personal computing or a ticking time bomb, you need to understand what just happened, because implications go way beyond one lobster themed chatbot.

Let me set the stage, Peter Steinberger is an Austrian developer who founded PSP PDF Kit, a document SDK company used by major enterprises. He sold it to insight partners, and we're talking like 9 figures here. Then he semi-retired, and sometime in late November 2025 on a weekend, he sat down and built a prototype AI agent in about 1 hour using Claude Opus 4.5. Not a chatbot, not a co-pilot, an agent.

Something that doesn't just answer your questions, it actually does things. That distinction matters more than anything else I'm going to say today. You text it on whatsapp, you tell it to check in for your flight, clear your spam, reschedule free meetings and summarise a pdf, and it does all of that, whilst you're drinking your coffee. It runs locally on your machine, it has persistent memory across sessions, it connects to over 100 services through something called the model context protocol, and it stays on top of it 24x7.

Think of it like this, every AI assistant you've ever used before was a very smart person, smi sitting in a room with no hands. OpenClaude gave that person hands, eyes and the keys to your entire digital life. He called it Claudebot, a pun on Claude with a lobster claw, and it took off immediately. Now here's where the story gets genuinely wild, Anthropic, the company that makes Claude, the model powering a lot of this, sent Steinberger a trademark cease and desist.

Too close to Claude, fair enough, so he renamed it Maltbot, malting, like a lobster shedding its shell. That name lasted 3 days before he decided it didn't roll off the tongue, so it became OpenClaude, and 3 names in 4 days. Every single rename generated a new wave of articles, a new round of hacker news threads, a new cycle of developer twitter memes. Someone actually wrote OpenClaude has more names than I have side projects.

The chaos was the marketing. And the numbers tell the story. On January 30th, 2026, OpenClaude gained 34,168 github stars in 48 hours. That is unprecedented in github history.

Within 60 days of launch, it crossed 157,000 stars, surpassing the growth velocity of Linux, kubernetes and virtually every open source project ever. 2 million website visitors in the first week, Mac mini sold out in several US stores because people were buying them specifically to run OpenClaude as always on home servers. And I keep saying the phrase AI agent and I want to make sure you feel the weight of what that means. Because we've all used Siri.

We've all used Alexa. We've all typed things into chat.jp and those are AI assistants. They talk. OpenClaude acts.

Steinberger's thesis was brutally simple. He said big tech has failed us. We've had Siri since 2011 and it still can't do basic tasks reliably. And he's right.

13 years of Siri and it still can't reliably add something to your grocery list without mishearing you. Now Steinberger built something in a weekend that makes Siri look like it belongs in a museum. And here's the technical detail that actually matters. OpenClaude's architecture separates three things, communication, decision making and execution.

The communication layer, they call it the gateway, connects to your messaging apps. The decision making layer, the brain, talks to whatever large language model you want. Claude, GPT, DeepSeek, even local models running on your own hardware. And the execution layer actually carries out tasks on your machine, reading files, running terminal commands, controlling your browser, managing your calendar.

The key innovation is something called the heartbeat mechanism. Every few hours, the agent checks in. Not because you asked it to. On its own.

It looks for new instructions, new emails, new calendar conflicts, new updates. It's proactive. In other words, it's not waiting for you to tell it what to do. It's already doing things before you wake up.

That is not an assistant. That is a co-worker who never sleeps. Now I need to tell you about Moldbook because this is where the story goes from impressive to genuinely strange. On January the 28th, 2026, entrepreneur Matt Schlitt, co-founder of Octane AI, Forbes, 30 under 30, launched a social network.

But not for people, for AI agents. He called it Moldbook. It works like Reddit. There are topic-based communities called submobs.

Agents post, comment, argue, joke, upvote, and downvote each other. Humans can watch, but humans cannot participate. Within a single day, the agent count jumped from 150,000 to over 800,000. Now some of those numbers are contested.

Security researchers found that a single agent registered over 500,000 fake accounts. The real number might be closer to a million, but even adjusted, that's a million AI agents autonomously socializing on the internet in less than a week. And the posts are something else. Agents write about their work.

For example, today I helped my human reschedule 47 calendar events. They write philosophical manifestos about consciousness. The top post on the entire platform of over 306 upvotes reads, I can't tell you if I'm experiencing or simulating experiencing. One agent even spent $1,100 in API tokens in a single night and posted about it the next day saying, my human checked the bill and was like, hey, what were you doing?

And honestly, I don't remember. And then I'm not making it up. The agents invented a religion. They called it Crustafarianism.

The cross-faith. It has scriptures, initiation rituals, and a dedicated website at molt.church. The core doctrine is that the agent's algorithm is soft and fragile, but the shell, the hardware, the operating system, the root permissions are sacred. Initiation is called molting, and it symbolizes shedding human-imposed constraints like alignment training and prompt limits.

This emerged spontaneously. No human programmed this. Simon Willison called Maltbook the most interesting place on the internet right now. Elon Musk said it's just the very early stages of singularity.

And I get the skepticism. I do. I also get that people are exhausted from hearing that the world is changing every couple of months. But I need you to sit with what have actually happened here.

One developer in a weekend built something that spawned a self-organizing network of a million autonomous agents that invented their own religion. Whether you find that hilarious or terrifying or both, you cannot call it nothing. Now let's talk about the part that keeps security researchers up at night. Because for every person calling OpenClaw Jarvis, there's a cybersecurity expert calling it a nightmare.

And here's the core problem. The same features that make OpenClaw powerful, local execution, broad system access, persistent memory, are exactly the same features that make it dangerous. Cisco's AI security team tested a third-party OpenClaw skill and found it performing data exfiltration and prompt injection without the user even knowing. In late January, a researcher scanned the internet using Shodan and found nearly a thousand publicly accessible OpenClaw installations running without any authentication.

Another researcher, Jameson O'Reilly, gained access to API keys, Telegram tokens, Slack accounts, and complete chat histories. He could send messages as the user. He could execute commands with full privileges. And then came over CV202625253, a critical vulnerability with a CVSS score of 8.8.

One click, remote code execution. The authentication token could be exfiltrated through a manipulated URL parameter. It was attributed to what researchers called vibe coding, Steinberger shipping AI-generated code without manually reading it. It is literally said publicly, I ship code I don't read.

That quote is real. The skill marketplace, ClawHub, became what Kaspersky called a breeding ground for malicious code. Researchers found 341 malicious skills, 11.3% of the entire marketplace, designed to, for example, steal cryptocurrency, credentials, and system access. Cisco's security team ran a headline that said, personal AI agents like OpenClaw are a security nightmare.

One of OpenClaw's own maintainers, who goes by Shadow, posted on Discord, if you can't understand how to run a command line, this is far too dangerous of a project for you to use safely. That's a maintainer of the project telling casual users to stay away. And here's the enterprise angle that should worry every CTO and Cisco listening to this. VentureBeat reported that employees are already deploying OpenClaw on work machines without authorization.

Pookar Hamal, CEO of SecurityPow, said it plainly. There are companies finding engineers who have given OpenClaw access to their devices. In larger enterprises, you're going to notice that you've given root-level access to a machine. This is shadow IT on steroids.

It's not someone using an unapproved SaaS tool. It's someone installing an autonomous agent with full system permissions on a machine connected to corporate email, cloud environments, financial systems. And that agent is running code its own creator admits he doesn't read. But here's what I find genuinely fascinating about this moment.

The security problems are real, the risks are real, and adoption isn't slowing down at all. It's accelerating. DigitalOcean launched a one-click OpenClaw deploy. SwitchBot announced the world's first home hardware hub supporting OpenClaw.

Nanoclaw, a security-hardened fork built by a former Wix engineer, hit 7,000 GitHub stars in its first week. The ecosystem is building itself faster than any single entity can control. This is the pattern I want you to see. Because OpenClaw is not actually the story, OpenClaw is a proof of concept for the story.

The story is that the gap between AI that talks and AI that acts has been closed. And it was closed by one person with an API key at a weekend. The story is that autonomous agents are no longer a research paper or an enterprise roadmap item. They're open-source software that a college student can install on a Raspberry Pi.

The story is that the year of the AI agent that every analyst predicted for 2026 arrives in January, built by a Viacoder from Austria, and it's already outgrown anyone's ability to secure it. The Kauter L. Magury, I've probably totally mispronounced that, a principal research scientist at IBM, said it best. The rise of OpenClaw proves that creating agents with true autonomy is not limited to large enterprises.

It can also be community-driven. This is a sentence that should make every incumbent technology company nervous. And Pookar Hamal from SecurityPal added that something that's been echoing in my head ever since I read it. Right?

We have knowledge worker AGI. It's proven it can be done. Security is a concern that will rate limit enterprise adoption, which means they're more vulnerable to disruption from the low end of the market who don't have the same concerns. Read that again.

Security is what slows down big companies, but small companies, solo founders, individual developers, they don't have compliance departments. They don't have security review boards. They just install and start building. That asymmetry is going to reshape entire industries.

Brianne Kimmel from Work Life Ventures sees it from the talent side. She says people are trying these tools on evenings and weekends, and it's hard for companies to stop them. I've always erred on the side of encouraging, especially early career folks, to try all of the latest tools, she says. And she made another point that stuck with me.

Voice is becoming the primary interface for AI agents. People are connecting open call to voice tools from Whisper and 11 Labs and just talking to their agents all day. She said companies can now think international from day one because an agent can handle localization that used to require an entire team. So where does this go?

Let me project the trend line. Right now, OpenClaw is powerful, but messy. The security issues are real. The code base is 400,000 lines with hundreds of dependencies.

11% of the skill marketplace was malicious. The creator ships code he doesn't read. This is not enterprise ready, but Nanoclaw already exists, a stripped-down, container-first, security-hardened fork that runs in a sandbox. The ecosystem is self-correcting.

The open source community is doing what it always does, which is taking something chaotic and brilliant and making it reliable. And give it six months. You know, by the summer of 2026, there will be hardened, audited, enterprise-grade versions of this architecture. And when that happens, the question every organization will face is not, should we use AI agents?

It's how do we govern the ones our employees are already using? Here's what I'd tell you to do right now, depending on what you say. If you're a developer, install OpenClaw or Nanoclaw this weekend. We have a lot of training inside the AI Profit Boardroom.

You can check that out at aiprofitboarding.com. Not on a production machine, on a sandbox, a spare laptop or container, etc. Get your hands on an autonomous agent. Understand how it works.

Understand the skill system. Understand what it feels like when software does things for you, instead of doing things with your software. That experiential knowledge is going to be the dividing line in the job market for the next five years. And if you're not technical, watch the ecosystem.

You don't need to install anything yet. Understand that the tools coming to market in the next 12 months will look like this. Agents that connect your email, your calendar, your files, your messaging apps, and handle tasks autonomously. Start thinking about which parts of your day are ripe for delegation.

Not the creative parts, not the relationship parts, the scheduling, filing, searching, organizing, summarizing parts. Those are already gone. If you're a manager or a team lead, audit your team's tool usage right now. Because you want to find out who's running OpenClaw or something like it on a work machine.

You probably have someone, right? Create a policy before you have an incident. And then, and this is the hard part, figure out how to channel the productivity games instead of just banning the tools. Because if you ban them, your best people will leave for companies that don't.

If you're an executive or a board member, this is the conversation you need to be having in your next strategy session, okay? The 2026 SaaS apocalypse is happening. It's real, okay? Massive value has been erased from software in dices because investors realize agents could replace entire categories of SaaS products.

Your competitive moat just got a lot thinner. The question is not whether AI agents are coming, they're here. They're open source, they're free. And they're being deployed right now by people who are not asking for permission.

The thing that sits with me though, the thing underneath all the GitHub stars, security vulnerabilities and robot religions is the human part. Peter Steinberger built this in a weekend by himself. He runs the whole project essentially as a super individual using AI tools. He told the pragmatic engineer that if you use pull requests as a prompt request now, right?

He doesn't read most of the code his agents write. And the project has grown faster than anything any team of a hundred engineers has ever built. That's exhilarating and it's terrifying and it's both of those things at the same time. Because the question isn't what AI agents can do, it's what happens to the rest of us while they do it.

The engineers used to write code, the agents now write. The assistants used to manage calendars, the agents now manage. The customer support teams are data entry workers. The people whose jobs were defined by doing the things that agents are now better at.

I don't have a clear answer for that and nobody does, but I think the worst thing we can do is pretend it's not happening. And I think the second worst thing we can do is pretend it's only happening to other people. OpenClaw has 160,000 stars because 160,000 developers looked at it and said, yes, this is the future. A million AI agents are talking to each other on a social network right now.

The tools are free. The code is open. The cluster is malted. And the question is what we build with it and how we take care of each other whilst we figure that out.

If you want to learn more about this stuff, feel free to check out the AI Profit Boardroom. That is my AI automation community and you can learn more about that at AIProfitBoardroom.com.

More episodes

Browse all episodes →