# OpenClaw: Weekend Project to OpenAI Acquihire in 90 Days

**Plutonous** | February 17, 2026 | 8 min read

> OpenClaw hit 190K+ GitHub stars before OpenAI acquired it - despite 512 security vulnerabilities including an 8.8 CVSS remote code execution flaw.

Tags: OpenClaw, OpenAI, AI Agents, Peter Steinberger, Acqui-Hire, Open Source, AI Security

---

**TL;DR:** OpenClaw, the open-source AI agent that lets you run autonomous tasks through WhatsApp, Telegram, and Slack, went from zero to 190,000+ GitHub stars in under 90 days, making it the 21st most-starred repo in GitHub history<sup><a href="#source-1">[1]</a></sup>. Creator Peter Steinberger turned down a mid-nine-figure offer from Meta and chose OpenAI, where he'll join the ChatGPT division while OpenClaw moves to an independent foundation<sup><a href="#source-2">[2]</a></sup>. Sam Altman called him "a genius with a lot of amazing ideas about the future"<sup><a href="#source-3">[3]</a></sup>. But security researchers found 512 vulnerabilities, 8 of them critical, including a CVSS 8.8 remote code execution flaw that exposed plaintext API keys and full system access on nearly 1,000 unprotected installations<sup><a href="#source-4">[4]</a></sup>.

The real story of OpenClaw isn't the GitHub stars, and it isn't the acqui-hire. It's what this project reveals about where the AI industry is actually heading: the battle for the agent layer. Not who builds the smartest model, but who controls the software that sits between the model and the real world, the thing that books your flights, manages your email, and runs your shell commands.

OpenAI didn't hire Peter Steinberger because OpenClaw is technologically groundbreaking. Some AI researchers have publicly questioned whether it is<sup><a href="#source-5">[5]</a></sup>. They hired him because OpenClaw proved, with 1.5 million AI agents created by real users, that autonomous personal agents aren't a research concept anymore. They're a product category. And OpenAI wants to own it.


### Why This Matters Now

On February 14, 2026, Steinberger announced he's joining OpenAI. Sam Altman confirmed it the next day, stating that OpenClaw will "live in a foundation" and "we expect this will quickly become core to our product offerings"<sup><a href="#source-2">[2]</a></sup>. This is OpenAI's clearest signal yet that the next phase of AI competition isn't about model intelligence. It's about agent infrastructure: who builds the system that turns intelligence into action. Meta wanted the same thing and was willing to pay hundreds of millions for it<sup><a href="#source-6">[6]</a></sup>.


## From Weekend Hack to 190,000 Stars: The Fastest Rise in Open-Source History

The timeline of OpenClaw's growth is genuinely without precedent. React took four years to reach 100,000 GitHub stars. TensorFlow took three. OpenClaw crossed that threshold in under eight weeks<sup><a href="#source-1">[1]</a></sup>.


- label: GitHub Stars; value: 190K+; description: 21st most-starred repo in GitHub history
- label: GitHub Forks; value: 22K+; description: Active contributor ecosystem
- label: npm Downloads (30d); value: 416K+; description: 30-day download volume
- label: AI Agents Created; value: 1.5M; description: By real users on the platform
- label: Website Visits (1 week); value: 2M+; description: Week after January 30 rebrand
- label: Stars in First 24 Hours; value: 9,000; description: Day one viral moment


What makes this growth structurally different from typical open-source virality is that OpenClaw isn't a developer tool. It's a consumer product that happens to be open-source. The 1.5 million AI agents weren't created by engineers experimenting with a new framework. They were created by people who wanted an AI to manage their calendars, send WhatsApp messages, and browse the web on their behalf. Steinberger's stated mission is to "build an agent that even my mum can use"<sup><a href="#source-2">[2]</a></sup>. That consumer accessibility is precisely what makes it valuable to OpenAI.


8 weeks

Time to reach 100,000 GitHub stars

React took 4 years. TensorFlow took 3 years. OpenClaw did it in under 8 weeks, the fastest ascent in open-source history.


## The Triple Rebrand: Clawd, Moltbot, OpenClaw

The naming saga is worth understanding because it illustrates the gravitational pull that the major AI labs exert on the entire ecosystem. Steinberger originally named the project Clawdbot in November 2025, a deliberate play on Anthropic's Claude with a lobster theme<sup><a href="#source-7">[7]</a></sup>.


### The OpenClaw Timeline
- year: Nov 2025; milestone: Clawdbot Prototype; innovation: Steinberger builds first prototype in approximately one hour as a weekend project
- year: Jan 27, 2026; milestone: Renamed to Moltbot; innovation: Anthropic raises trademark concerns over phonetic similarity between 'Clawd' and 'Claude'
- year: Jan 29, 2026; milestone: Renamed to OpenClaw; innovation: Final rebrand. 'Moltbot never quite rolled off the tongue.' Open-source ethos emphasized
- year: Jan 30, 2026; milestone: 106K+ GitHub Stars; innovation: Hits 106,000+ stars within 48 hours of rebrand. 9,000 stars in first 24 hours
- year: Feb 2, 2026; milestone: 135K Stars, 200K npm; innovation: Crosses 135,000 GitHub stars and 200,000 npm downloads in under a week
- year: Feb 7-12; milestone: Acquisition Offers; innovation: Reports of offers from Meta (mid-nine figures) and OpenAI surface publicly
- year: Feb 14, 2026; milestone: Joins OpenAI; innovation: Steinberger announces joining OpenAI. OpenClaw to move to independent foundation
- year: Feb 15, 2026; milestone: Altman Confirms; innovation: Sam Altman confirms on X: 'a genius with a lot of amazing ideas about the future'


The irony is thick. Anthropic's trademark enforcement on the name "Clawd" may have inadvertently pushed the project toward a rebrand that made it sound more like a serious platform ("OpenClaw") rather than a cute bot, and that professional positioning is arguably what attracted Meta and OpenAI's attention at the scale it did.

## The Architecture: Why OpenClaw Actually Works

Here's what's often overlooked in the hype cycle: OpenClaw's architecture makes several genuinely smart technical decisions that explain its adoption, even if the underlying techniques aren't novel.


### OpenClaw Technical Architecture
- title: Gateway + Lane Queue; description: A single process holds all channel connections and the control plane. The Lane Queue defaults to serial execution to prevent race conditions, solving a core problem in autonomous agent systems.; examples: - Serial execution by default
- No concurrent mutation bugs
- Single control plane
- title: Messaging-First Interface; description: Uses WhatsApp, Telegram, Discord, Slack, Signal, and Teams as the primary UI. No custom app to install. The agent lives where the user already communicates.; examples: - WhatsApp integration
- Telegram bots
- Slack/Teams/Discord channels
- title: Local-First Memory; description: All memory stored as Markdown files on the user's machine. No cloud dependency for state. The user owns their data completely.; examples: - Markdown workspace files
- Full data ownership
- No cloud lock-in
- title: Heartbeat Daemon; description: A scheduled daemon that acts without user prompting, enabling truly autonomous workflows like monitoring, scheduled tasks, and proactive notifications.; examples: - Autonomous scheduling
- Proactive notifications
- Background monitoring


The Semantic Snapshots approach for web browsing deserves special attention. Instead of relying on screenshots (expensive in tokens, slow to process, and brittle), OpenClaw parses accessibility trees to understand web page structure<sup><a href="#source-7">[7]</a></sup>. This reduces token costs significantly and increases accuracy for navigation tasks. It's the kind of practical engineering decision that separates tools people actually use from tools that demo well.


Sam Altman, X/Twitter, February 15, 2026
He is a genius with a lot of amazing ideas about the future.


The LLM-agnostic design is strategically critical. OpenClaw works with Claude, DeepSeek, OpenAI models, and others. This means that even as Steinberger joins OpenAI, the framework itself isn't locked to GPT. Whether OpenAI will maintain that neutrality once OpenClaw becomes "core to our product offerings" is the question every current OpenClaw user should be asking.

## The Acqui-Hire: Why OpenAI Won and Meta Lost

Let's be clear about what happened here. Both Meta and OpenAI made acquisition offers. Meta reportedly floated a mid-nine-figure cash-and-stock package, potentially in the hundreds of millions<sup><a href="#source-6">[6]</a></sup>. Steinberger's non-negotiable condition was that OpenClaw remain open-source. OpenAI agreed. Meta, presumably, either didn't or couldn't match the structural arrangement.


- OpenAI Offer
- Meta Offer

- feature: Structure; values: - Acqui-hire + Foundation
- Traditional acquisition
- feature: Open-Source Commitment; values: - Yes, independent foundation
- Unclear / not committed
- feature: Financial Terms; values: - Undisclosed
- Mid-nine figures (reported)
- feature: Integration; values: - ChatGPT division
- Unknown
- feature: Steinberger's Choice; values: - Accepted
- Declined

1


The financial dynamics are remarkable. OpenClaw had no venture funding. Steinberger built it as a solo weekend project, self-funded from the proceeds of his previous exit (PSPDFKit sold to Insight Partners for over $100M)<sup><a href="#source-8">[8]</a></sup>. The project had approximately $20,000 in running losses. And it attracted offers valued in the hundreds of millions to billions<sup><a href="#source-9">[9]</a></sup>.


~$20K

OpenClaw's total running losses before billion-dollar bids

The gap between a weekend project's operating costs and the acquisition offers it attracted is one of the starkest expectation gaps in AI history.


Steinberger's stated reasoning is worth taking at face value: "What I want is to change the world, not build a large company, and teaming up with OpenAI is the fastest way to bring this to everyone"<sup><a href="#source-2">[2]</a></sup>. For OpenAI, the strategic logic is equally clear. The company that controls the agent layer, the software that translates model intelligence into real-world action, controls the most valuable piece of the AI stack.

## The Security Problem: 512 Vulnerabilities and Counting

Here's the uncomfortable truth that the acqui-hire celebration is overshadowing. OpenClaw has a security problem that ranges from concerning to disqualifying, depending on how it's deployed.


- label: Total Vulnerabilities; value: 512; description: Found in security audit
- label: Critical Flaws; value: 8; description: Classified as critical severity
- label: CVE-2026-25253 CVSS; value: 8.8; description: Remote code execution via crafted link
- label: Exposed Installations; value: ~1,000; description: Running without authentication
- label: Data Exposed; value: API Keys; description: Plaintext Anthropic/Telegram tokens found
- label: Chat Histories; value: Months; description: Full conversation logs accessible


The CVE-2026-25253 vulnerability is particularly alarming. OpenClaw's Control UI automatically trusts a `gatewayURL` query parameter and establishes a WebSocket connection including the user's auth token without verifying the origin<sup><a href="#source-10">[10]</a></sup>. An attacker can craft a single malicious link that, when clicked, gives them full control of the victim's OpenClaw installation.

Researchers demonstrated extracting plaintext API keys (including Anthropic API keys), Telegram bot tokens, Slack credentials, months of chat histories, and full system administrator privileges from exposed installations<sup><a href="#source-4">[4]</a></sup>.


### The Fundamental Security Paradox

OpenClaw's core value proposition, an AI agent that autonomously browses the web, reads your email, and executes shell commands, is inherently at odds with security best practices. The agent must process untrusted content (web pages, emails, messages) to do its job. But processing untrusted content is exactly how prompt injection attacks work. This isn't a bug to be fixed. It's a fundamental architectural tension that every AI agent framework must navigate, and one that OpenAI now owns<sup><a href="#source-4">[4]</a></sup>.


## The Strategic Play: OpenAI's Agent Layer Ambitions

The acqui-hire of Steinberger fits into a broader OpenAI strategy that's been building since late 2025. The company has been steadily expanding from "best model" to "best platform," and the agent layer is the next logical frontier.


### The AI Agent Stack OpenAI Is Building
- title: Foundation Models; description: GPT-5, GPT-5.2, o3: the intelligence layer that understands and reasons
- title: Agent Infrastructure; description: OpenClaw integration: the layer that translates intelligence into autonomous action
- title: User Interfaces; description: ChatGPT, API, messaging platforms: where users interact with and direct agents
- title: Memory & State; description: Local-first memory, workspace context, persistent agent identity across sessions


What's often overlooked is why this matters more than model improvements. A 2% improvement in benchmark performance changes nothing about how enterprises use AI. An agent that can reliably book flights, manage email, and execute multi-step workflows across platforms changes everything. The agent layer is where model intelligence becomes economic value, and OpenClaw proved that 1.5 million people are ready for it right now.

The competitive implications are significant. Google has been building agent frameworks into Gemini. Anthropic has Claude Code and Model Context Protocol. Meta has been investing heavily in open-source AI tools. By acquiring the team behind the most popular open-source agent framework, OpenAI is making a preemptive move to define the category before competitors can.

## Peter Steinberger: The Builder Behind the Bot

Understanding Steinberger is essential to understanding why OpenClaw succeeded where dozens of similar projects didn't. He's not an AI researcher. He's a product builder who stumbled into the AI agent space and brought consumer product instincts to a field dominated by research lab thinking.

His previous company, PSPDFKit, is instructive. He bootstrapped a PDF SDK into a B2B product used by Apple, Disney, and Dropbox, then sold it to Insight Partners for over $100M<sup><a href="#source-8">[8]</a></sup>. After the sale, he went through what he describes as a period of soul-searching, including travel, therapy, and ayahuasca. He rediscovered his passion by diving into AI in 2024.

The OpenClaw prototype was built in approximately one hour as a weekend project<sup><a href="#source-7">[7]</a></sup>. What turned a weekend hack into a phenomenon wasn't technical sophistication. It was the insight that the best interface for an AI agent isn't a custom app or a command line. It's the messaging platforms people already use every day. That's a product insight, not a technical one.


### What OpenClaw's Rise Tells Us About AI Agents
- title: The agent layer is now a product category, not a research concept; description: 1.5 million AI agents created by real users proves that autonomous personal agents have crossed from research demo to genuine consumer demand. Every major AI company will need an agent strategy.; tip: If you're building AI products, start thinking about agent workflows now, not next year
- title: Open-source agents will coexist with proprietary ones; description: Steinberger's non-negotiable demand that OpenClaw remain open-source, and OpenAI's agreement to it, signals that the agent layer will be a hybrid ecosystem. Proprietary models powering open-source agent frameworks.; tip: Watch whether OpenAI maintains OpenClaw's LLM-agnostic design or gradually locks it to GPT
- title: Security is the unsolved problem that could derail everything; description: 512 vulnerabilities in the most popular agent framework means the entire AI agent category has a security credibility problem. Enterprise adoption will be gated by security improvements.; tip: Do not deploy any autonomous AI agent in production without a thorough security audit and network isolation
- title: Consumer distribution beats technical sophistication; description: OpenClaw's messaging-first approach (WhatsApp, Telegram, Slack) drove adoption faster than any technically superior but interface-poor alternative. The best agent is the one people actually use.; tip: Build AI agents that meet users where they already are, not where you think they should be
- title: The acqui-hire model is the new AI talent acquisition playbook; description: Build a viral open-source project, attract hundreds of millions in offers, join the highest-bidder while keeping the project open. Steinberger's path from weekend hack to OpenAI is now a template.; tip: For AI founders: open-source distribution can be more valuable than revenue as a negotiating lever


The uncomfortable truth is that OpenClaw's success has less to do with AI innovation and more to do with distribution and product instincts. Some AI researchers have publicly questioned whether the project represents genuine technical advancement<sup><a href="#source-5">[5]</a></sup>. That criticism misses the point. The battle for the agent layer won't be won by the most sophisticated architecture. It will be won by the framework that the most people actually use. And right now, that's OpenClaw by a massive margin.


### The Bottom Line

OpenClaw's journey from weekend project to OpenAI acqui-hire in 90 days is the clearest signal yet that the AI industry's center of gravity is shifting from models to agents. OpenAI didn't pay for OpenClaw's technology. They paid for its distribution, its community, and the proof that 1.5 million people want an AI agent that does real things in the real world. The question now is whether OpenAI can solve the security problems that come with autonomous agents before a high-profile breach turns public enthusiasm into public fear.


## Sources

<a id="source-1"></a>
1. [OpenClaw GitHub Repository](https://github.com/openclaw/openclaw): Official repo with 190K+ stars, 22K+ forks, and MIT license

<a id="source-2"></a>
2. [Peter Steinberger: OpenClaw, OpenAI and the Future](https://steipete.me/posts/2026/openclaw): Steinberger's blog post announcing he's joining OpenAI, explaining the decision and OpenClaw's future as a foundation

<a id="source-3"></a>
3. [TechRadar: Sam Altman says OpenClaw founder is 'a genius'](https://www.techradar.com/pro/he-is-a-genius-with-a-lot-of-amazing-ideas-about-the-future-sam-altman-says-openclaw-founder-peter-steinberger-is-joining-openai): Altman's public endorsement and strategic framing of the hire

<a id="source-4"></a>
4. [Cisco Blog: Personal AI Agents like OpenClaw Are a Security Nightmare](https://blogs.cisco.com/ai/personal-ai-agents-like-openclaw-are-a-security-nightmare): Comprehensive security analysis finding 512 vulnerabilities, 8 critical, including nearly 1,000 exposed installations

<a id="source-5"></a>
5. [TechCrunch: Some AI experts don't think OpenClaw is all that exciting](https://techcrunch.com/2026/02/16/after-all-the-hype-some-ai-experts-dont-think-openclaw-is-all-that-exciting/): Critical analysis questioning OpenClaw's technical novelty

<a id="source-6"></a>
6. [Decrypt: OpenClaw Creator Gets Big Offers](https://decrypt.co/358129/openclaw-creator-offers-acquire-ai-sensation-stay-open-source): Reporting on Meta's mid-nine-figure offer and Steinberger's open-source condition

<a id="source-7"></a>
7. [DigitalOcean: What is OpenClaw?](https://www.digitalocean.com/resources/articles/what-is-openclaw): Technical overview of OpenClaw's architecture, Semantic Snapshots, and Lane Queue system

<a id="source-8"></a>
8. [CNBC: OpenClaw creator Peter Steinberger joining OpenAI](https://www.cnbc.com/2026/02/15/openclaw-creator-peter-steinberger-joining-openai-altman-says.html): Major business coverage of the acqui-hire, PSPDFKit background, and strategic implications

<a id="source-9"></a>
9. [ainvest: OpenClaw acquisition offers expectation gap](https://www.ainvest.com/news/openclaw-acquisition-offers-expectation-gap-20k-losses-billion-dollar-bids-2602/): Analysis of the gap between OpenClaw's $20K losses and billion-dollar acquisition offers

<a id="source-10"></a>
10. [The Hacker News: OpenClaw Bug Enables One-Click RCE](https://thehackernews.com/2026/02/openclaw-bug-enables-one-click-remote.html): CVE-2026-25253 details: CVSS 8.8 remote code execution via crafted link

<a id="source-11"></a>
11. [SiliconANGLE: OpenAI hires OpenClaw founder in push toward autonomous agents](https://siliconangle.com/2026/02/15/openai-hires-openclaw-founder-peter-steinberger-push-toward-autonomous-agents/): Industry analysis of OpenAI's agent strategy and competitive positioning

<a id="source-12"></a>
12. [Computerworld: OpenAI hires OpenClaw founder as AI agent race intensifies](https://www.computerworld.com/article/4132725/openai-hires-openclaw-founder-as-ai-agent-race-intensifies.html): Competitive landscape analysis across Google, Meta, Anthropic, and OpenAI


*Last updated: February 17, 2026*

---

*Source: [LLM Rumors](https://www.llmrumors.com/news/openclaw-openai-acquihire-agent-race)*
