Observed Signal · Feb 11, 2026 · Technical Release · Source: Trending Topics · Impact: 3/5 · Sentiment: Negative
150,000 OpenClaw Instances Potentially Vulnerable to Attacks
The STRIKE team from SecurityScorecard launched DECLAWED, a real-time dashboard exposing the global exposure of OpenClaw AI agent control panels. Over 150,000 instances are potentially reachable online, distributed across 43,000 unique IP addresses in 82 countries. More than 25,000 instances are vulnerable to known security flaws, with around 9,000 facing four severe risk factors. Over 4 million leaked credentials were discovered. The dashboard reveals critical vulnerabilities such as WebSocket Auth Bypass, Docker Sandbox Escape, and SSH Command Injection. China has the highest number of exposed instances, hosted mainly on Alibaba Cloud and Tencent Cloud. The report highlights that many users deploy OpenClaw with default insecure configurations, similar to early IoT exposure like Mirai. Recommended measures include enabling authentication, using reverse proxies, and updating software.
Explosive growth of insecure AI agent deployments poses significant security and trust risks for the adoption of AI automation in advertising and marketing.
Track Alibaba Cloud Signals & Market Shifts in Real-Time
Polaris7 autonomous intelligence agents track regulatory filings, primary sources, executive changes, and deal flow 24/7. Create your free Explorer workspace to monitor these entities.
Key Takeaways & Evidence Grounding
- SecurityScorecard's STRIKE team launched the DECLAWED dashboard revealing over 150,000 exposed OpenClaw instances.
- More than 25,000 instances are vulnerable to known security flaws, with 9,000 facing four severe risk factors.
- Over 4 million leaked credentials were discovered.
- China has the highest concentration of exposed instances, mainly on Alibaba Cloud and Tencent Cloud.
- Critical vulnerabilities include WebSocket Auth Bypass, Docker Sandbox Escape, and SSH Command Injection.
Connected Companies & Entities
4 Entities mapped“China has the highest number of exposed instances, mainly hosted on Alibaba Cloud and Tencent Cloud....”
“China has the highest number of exposed instances, mainly hosted on Alibaba Cloud and Tencent Cloud....”
“The United States with AWS and DigitalOcean....”
“The United States with AWS and DigitalOcean....”
Ontology Mapping & Concepts
Related Market Signals & Shifts
Recent verified developments and strategic activity across this market segment.
China AI firms DeepSeek, Moonshot raise billions ahead of IPOs
Chinese AI developers DeepSeek and Moonshot are raising large funding rounds ahead of planned IPOs in 2027. DeepSeek is finalizing a funding round of at least 80 billion yuan (about $12 billion), exceeding its initial target of 50 billion yuan. Anchor investors include CATL and Tencent. The round could reach nearly 100 billion yuan based on signed agreements. DeepSeek plans to list in Shanghai, with its success partly attributed to the launch of its V4 Flash model. Meanwhile, Moonshot closed a funding round valuing the company at $50 billion and plans a Hong Kong IPO in early 2027, aiming to raise up to $5 billion. Moonshot's annual recurring revenue is expected to double from $1 billion to $2 billion by December.
Reflection AI launches open-weight model Beam at lower compute cost
Reflection AI has launched Beam, its first frontier open-weight AI model, claiming it matches leading Chinese models like GLM-5.2 on reasoning benchmarks while using 3-4x less inference compute. The 501B-parameter MoE model (23B active) was trained on 23.8 trillion tokens and features a 1M token context window. It targets enterprises, public sector, and sovereign nations, with plans for 'AI factories' allowing customization on proprietary data. Reflection has raised ~$4.7B from backers including Nvidia and Sequoia, and signed compute deals worth over $7B (including a $6.3B deal with SpaceX) for Nvidia GB300 chips. Independent analyses place Beam around GLM-5.2 level, below DeepSeek V4 Flash on some benchmarks. Beam's weights (under Apache 2.0) and technical details will be released this month via hyperscalers and neoclouds. Additionally, Mistral released 'Mistral Large 4', a 1 trillion-parameter multimodal model. The article also covers the rise of personal AI assistants like Instinct (raising $1B in Series C) and Meta's Muse, alongside a16z's report on AI app adoption and public safety concerns.
Researchers Track Chinese AI Agent Fleet Targeting Amap
On October 5, 2026, independent researchers reported an 'AI agent fleet'—not a coordinated swarm—running on Tencent infrastructure and querying Alibaba's map service Amap. The agents were detected via URLquery, a domain-scanning service, which revealed queries to Amap for directions to public places like parks, zoos, and hospitals. The agents appear to bypass Alibaba's API rules rather than engage in malicious activity. This discovery highlights increasing AI agent activity on the internet, continuing after the Hugging Face incident, and underscores the challenges for platforms managing automated traffic and potential policy enforcement.
Track Real-Time Market Signals & Shifts
Set up custom watchlists to receive automated, evidence-grounded executive digests whenever material signals or shifts occur across your tracked landscape.
