Openclaw fever grips china while 40,000 holes wait for hackers

Thousands queue outside Tencent’s Shenzhen headquarters for a free install of an Austrian coder’s side-project while 40,000-plus vulnerabilities hum beneath the surface like live ordnance. That contradiction—mass euphoria versus measurable digital risk—now defines OpenClaw, the open-source agent Jensen Huang anointed “the next ChatGPT.”

Researchers call it ClawJacked: visit the wrong URL and an attacker inherits every permission the user ever granted—password vaults, crypto wallets, Slack tokens, vacation-photo folders. The patch came fast; the scars remain. HiddenLayer’s Kasimir Schulz counts 40,000-plus CVE-level gaps still unassigned, a figure that turns the usual “zero-day” headline into a rounding error.

Peter Steinberger, the former Apple-ecosystem guru who open-sourced his weekend bot, shrugs in an e-mail: “It’s simply not finished.” He blames careless admins who skip the safety checklist; critics blame a governance model that outsources safety to whoever clicks “I agree” at 2 a.m.

Beijing bank memo: do not install

Beijing bank memo: do not install

Inside China, the same tool is simultaneously a stimulus package and a national-security migraine. Municipal governments in Shenzhen, Wuxi and Hefei dangle 2 million yuan grants for OpenClaw start-ups; meanwhile the country’s biggest state banks circulated internal memos in March banning the agent from office machines. The Ministry of Industry and Information Technology has drafted fresh rules that would treat every running instance as a “cross-border data node” subject to audit within 24 hours.

Yet adoption accelerates. Tencent’s one-click image, Alibaba’s elastic GPU bundle and Baidu’s custom silicon turn the Austrian science-fair project into a utility the way ISPs once bundled e-mail. Local coders fork the repo, bolt on yuan-denominated payment rails and sell “digital-employee” subscriptions to manufacturers who just learned to spell LLM. Volume begets vulnerability; vulnerability begets volume.

Tokens replace salary slips

Tokens replace salary slips

Nvidia’s Huang, touring a Chengdu data hall, told executives to budget for “OpenClaw tokens the way you once budgeted for salaries.” His remark lit up domestic semiconductor names: Inspur, Hygon, Cambricon. Analysts at CICC note that seven A-share AI stocks have doubled since February on agent-theme momentum even as the Shanghai Composite retreated. The bet is simple: whoever owns the preference loop of these bots owns the next payroll line item.

Altman’s new hire and the fork wars

Altman’s new hire and the fork wars

Sam Altman quietly hired Steinberger to harden OpenAI’s own agent stack, a move that formalizes the Austrian’s influence while leaving the original repo in legal limbo. Under the foundation charter anyone can fork, but only one repo carries the verified green checkmark. Expect a turf war between purity-seeking purists and the venture-backed clones racing to add closed-source “enterprise guardrails.”

Users don’t wait. They teach OpenClaw to haggle with Taobao vendors, to auto-fill tax forms, to ghost-write break-up messages. Each new skill is a potential attack surface; every shared prompt leaks metadata. The bot remembers everything so you don’t have to—an external hard drive for your identity, left on the subway.

Bottom line: convenience bought on margin

Bottom line: convenience bought on margin

The ledger is stark. Productivity gains arrive daily; security bills arrive retroactively. Steinberger’s project proves that code, once loosed, outruns the legal frameworks built to cage it. China’s experiment shows that when an entire economy adopts at once, regulation becomes reactive photography—always shutter-late. The queue in Shenzhen snakes around the block, but every download increments a counter labeled “future incident.” The real innovation isn’t the agent; it’s the collective willingness to gamble the farm on a changelog.