



If you’ve been on the Internet in the past two weeks you’ve probably heard of OpenClaw (or its various former names). An open source alternative to Claude Code, OpenClaw has seen a near-immediate uptake of users thanks to its ease of deployment and flexibility.
Of course, with the rapid proliferation of new software often comes new vulnerabilities, and this is especially true when effectively giving a language model root access to your life. The past week has seen OpenClaw skills used for malware, agent communication platform Moltbook used for prompt injection, and–most relevant to us–publicly-exposed OpenClaw instances being spread around the Internet.
At the end of January, Censys announced that tens of thousands of OpenClaw instances were found exposed to the Internet. However, it’s one thing to see exposure, and another to see exploitation. How have attackers on the Internet responded to this exposure, and what does it tell us about how rapidly new attack vectors transition to exploits in practice? At Terrace Networks, we operate the most diverse footprint of honeypots on the planet, collecting attacks targeted to millions of network endpoints around the world. From this perspective, we can better understand the rapid onset of OpenClaw scanning in the wild.
Because Terrace stores terabytes of archival data on network scanning, we can go back in time and identify instances of OpenClaw scanning. Let’s first look at raw traffic counts on OpenClaw’s default port (TCP/18789) since the start of the year:

The spike is abrupt and unambiguous. Notably, this spike started on January 26, in lockstep with the original OpenClaw announcement on Hacker News. Attackers are not just waiting for sources like Censys and Shodan, but are actively developing new scans against brand new software. Of course the scanning we see only increases over time, likely aided by publicity from other sources.
Of course, raw traffic counts don’t tell the whole story. How widespread are these scanners, how broadly are they scanning infrastructure, and what can we learn about specific adversarial campaigns from this?
First, the question of breadth: is all this scanning just coming from a few players? Let’s look at number of sources that Terrace sees scanning for OpenClaw:

Here we see an interesting trend: rather than a few attackers (either using one or a cluster of IP addresses) we see a smooth rise in scanning sources over time. However, the number of targeted Terrace honeynet IPs sharply rises and stays elevated, possibly because of aggressive scanning by initial actors:

By fingerprinting the application-layer payloads from each scanner, we also see that different scanning behaviors emerge over time, including coordinated scans for other co-located applications. To do this, we leverage Terrace’s application-layer traffic collection on incoming traffic, combined with deep packet inspection to infer target protocols:

A few key inflection points emerge: On February 1, HTTP and HTTPS requests diverged, implying a new scanning actor specifically looking for exposed non-TLS servers. Additionally, we see the emergence of scans for other unrelated services, perhaps in search of colocated attack surfaces.


Looking at the sources of OpenClaw scanning, we see concentration across both networks and geographies. Most of these appear to be from Cloud/VPS hosts, with the (unsurprising) addition of Censys. The fast-flux enabled by infrastructure as a service makes IP address lists a noisy and ever-changing target, especially as attackers rapidly deploy scans for new applications.
One basic conclusion is obvious: if you’re running OpenClaw, it should never be Internet-reachable without authentication and network-level controls.
While enterprises are (hopefully) not deploying publicly-visible OpenClaw instances, the rapid shifts we see here are emblematic of the emergent threats we see every day at Terrace Networks. With attackers deploying large-scale exploits more rapidly than ever, Terrace uses AI to build real-time defenses based on data from our network of global monitors.
To learn more about how Terrace is building the future of AI-driven threat intelligence, reach out to info@terracenetworks.com
PS: We’re hiring! If you want to build high-performance AI systems that respond to threats as they happen, check out our open positions.