Unsecured Paperclip Instances Exposing Live Dashboards via Google Search

✍️ OpenClawRadar📅 Published: April 14, 2026🔗 Source
Unsecured Paperclip Instances Exposing Live Dashboards via Google Search
Ad

A Reddit user reported accidentally accessing a live Paperclip dashboard while searching for an error related to their OpenClaw agent. After Googling the error and clicking the first result, they were immediately presented with someone's complete Paperclip interface without any authentication required.

What Was Exposed

The exposed dashboard contained:

  • Full organizational chart
  • Active issues and task assignments
  • Agent conversations and configurations
  • Business plans and marketing strategies
  • Task history and potentially API keys

The user noted they could read through "all his marketing plan, his whole business model" and described the situation as "your entire org, your agent configs, your API keys, your task history — all of it is public."

Ad

Common Security Misconfigurations

According to the source, this exposure occurs when Paperclip instances have these characteristics:

  • Exposed on a public domain or IP address
  • Running in local_trusted mode
  • Without Basic Auth or any login layer in front

The user emphasized that while Paperclip's self-hosted nature provides full control, it also means "you are responsible for securing it." They warned that improperly secured instances create "an accidental open-source intelligence feed of your entire company" that's indexable by search engines.

The core recommendation from the source is straightforward: "Don't expose it on a public domain without auth."

📖 Read the full source: r/openclaw

Ad

👀 See Also

Potential Claude Security Incident: Self-Sent Password Alerts and Suspicious .NET Process
Security

Potential Claude Security Incident: Self-Sent Password Alerts and Suspicious .NET Process

A user reports receiving suspicious password reset alerts that appeared to be sent from their own account after logging into Claude, with emails vanishing minutes later and an unusual .NET process blocking system shutdown.

OpenClawRadar
Open Source AI Tools Pose Security Risks Through 'Illusory Security Through Transparency'
Security

Open Source AI Tools Pose Security Risks Through 'Illusory Security Through Transparency'

A Reddit post warns about malware disguised as open-source AI agents and tools, where malicious code can be hidden in large codebases that users assume are safe because they're on GitHub. The post describes how 'vibe-coding' and autonomous AI agents condition users to run unknown programs without review.

OpenClawRadar
Free Claude Skill Scans Other Skills for Security Risks
Security

Free Claude Skill Scans Other Skills for Security Risks

A developer has built a free Claude skill that reviews the security of other Claude skills by checking code for potentially malicious behavior and analyzing repositories with a scorecard-style approach. The tool helps answer whether a Claude skill appears reasonably safe to use.

OpenClawRadar
Sweden's E-Government Platform Source Code Leaked via Compromised CGI Infrastructure
Security

Sweden's E-Government Platform Source Code Leaked via Compromised CGI Infrastructure

The full source code of Sweden's E-Government platform was leaked by threat actor ByteToBreach after compromising CGI Sverige AB infrastructure. The leak includes staff databases, API document signing systems, Jenkins SSH credentials, and RCE test endpoints.

OpenClawRadar