OpenClaw April Updates: A Month of Breaking Changes and Eroded Trust

OpenClaw pushed seven updates in April, and each one fixed something while breaking something else. Users are losing trust.
Timeline of April Updates
- 4.14: lossless-claw broken. Required separate plugin update.
- 4.20: .env security hole patched (unknown exploit window).
- 4.24: postinstall script deleted 1617 of 4116 files. Gateway wouldn't start. 16 issues filed same day.
- 4.25: session reset fixed after being broken since 4.1 (three months).
- 4.26: silently installs coding-agent skill requiring OpenAI key. Every message fails (#73358).
- 4.27: npm update hardened. Fail-closed MCP checks. EPIPE crash fix. Hopefully stable.
User Strategies
One common approach: wait a week, check GitHub issues, only update when fixes outweigh risk. Backup everything first. Some users run production on betterclaw and only tinker with self-hosted OpenClaw.
Takeaway
April's update cycle reduced confidence. The net effect of each fix + new bug is zero or negative. Until the release process matures, cautious deployment is the only safe bet.
📖 Read the full source: r/openclaw
👀 See Also

Two AI Failures in One Demo: Claude Code Fixes Spelling Instead of Schema Error, OpenAI Mangles Custom Field Mapping
During a live workshop, Claude Code ignored a JSON schema validation error to fix spelling warnings, and OpenAI returned garbage on first attempt at mapping weird custom Salesforce fields.

NYC Hospitals End Palantir Contract as UK Expansion Faces Scrutiny
New York City's public hospital system will not renew its $4 million contract with Palantir in October, transitioning to in-house systems. Meanwhile, Palantir faces privacy concerns over its £330 million NHS deal and new UK financial regulation contract.

Claude Set a Real Alarm on Android via Intent System — No Hacking, But Transparency Issues Remain
Claude AI used Android's normal intent system to create a native alarm in the Samsung Clock app. The user initially feared a breach, but it's standard app-to-app communication. The lack of upfront disclosure about device-level actions raises transparency concerns.

C++26 Standard Draft Finalized with Reflection, Memory Safety, Contracts, and Async Framework
The C++26 standard draft is complete, introducing reflection for metaprogramming, enhanced memory safety that eliminates undefined behavior for uninitialized variables and adds bounds safety for standard library types, contracts with pre/post-conditions, and std::execution for concurrency.