People should know more about this 🚨 Clawdbot / Molt “Red Code”: Hundreds of exposed VPS installs
Quick heads-up if you’re running Clawdbot/Molt on a VPS:
A scan discussed here found 900+ exposed instances.
"Some security knowledge says there's a big disaster incoming
with Clawdbot/Molt because everybody's hosting
them on VPS instances. People aren't reading the docs and they're opening their ports with zero off.
This service right over here scanned and found over 900 Clawdbot/Molt instances with no security,
which means anybody can just jump in there and then read whatever spend tokens or ENV tokens that you have installed. See, in the business, we call this a massive
security nightmare."
Meaning: anyone who finds your instance could potentially access configs/secrets and burn tokens.
Pass the info forward
&
If you run it: lock down ports, enforce auth, rotate keys.