OpenClaw released version 2026.8.1, branded OpenClaw 2.0, for its open-source AI-agent automation platform. The update moves sessions and transcripts into SQLite, adds credential discovery and validation during setup, and introduces masked credential prompts, destination-restricted secret substitution, shared team credential management, and optional 1Password brokering. It also strengthens plugin provenance and capability-consent checks, session permission modes, workspace filesystem restrictions, automation approvals, model allowlists, redacted configuration history, and protections against private prompt-context disclosure.
The release adds shared cloud sessions with role-based collaboration controls, although OpenClaw cautions these are not tenant isolation or a security boundary. Incognito sessions avoid standard disk transcripts and memory but remain accessible to the model provider, tools, and Gateway operator; an unencrypted transcript snapshot may also reside in the browser profile for startup performance. Operators should validate reported Gateway health because setup can finish without a reachable Gateway when service startup is skipped, and should roll out the extensive update in stages where production deployments handle credentials, plugins, integrations, or cloud workers.

Track how attackers are adapting to this technology.
2 events from the most recent confirmed update back to the earliest known activity.
OpenClaw released a native macOS app installer with guided onboarding and AI-access configuration detection. It also released Windows NVIDIA RTX onboarding that detects compatible GPUs, installs optimized local models, and manages local inference through llama-server.
OpenClaw released its largest update, migrating sessions and transcripts to SQLite and adding credential validation, shared-session controls, and Incognito mode. The release also introduced security measures for credentials, plugins, agent workspaces, automation approvals, model access, and redacted configuration history.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Follow how adversaries are adapting to this technology, and where it touches your stack today.
8 references tracked. Mallory keeps watching after this page renders.
openclaw.ai
Open sourceinfoworld.com
Open sourcetheregister.com
Open sourcecybersecuritynews.com
Open sourcehelpnetsecurity.com
Open sourceopenclaw.ai
Open sourcedocs.openclaw.ai
Open sourcedocs.openclaw.ai
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.