The OpenClaw foundation has announced the release of version 2.0 of its AI agent harness, emphasizing usability enhancements while leaving security concerns largely unaddressed. This update aims to simplify installation and improve user interaction, but critics warn that it may exacerbate existing security vulnerabilities.
Usability Improvements in OpenClaw 2.0
According to Hannes Rudolph, the foundation’s community manager, the new version touches every aspect of OpenClaw. The installation process has been streamlined to encourage broader adoption, allowing users to engage with their AI agents more quickly. The redesigned browser app now offers a familiar interface akin to popular AI services like ChatGPT and Claude, enhancing user experience.
Shared Cloud Sessions and Security Risks
OpenClaw 2.0 introduces shared cloud sessions, enabling multiple users to interact with a single AI agent while maintaining context. However, the foundation has clarified that these shared session controls do not provide tenant isolation or a security boundary, raising concerns about potential security risks when multiple users access the same instance.
Limited Security Enhancements
While the update includes a new feature for protected credentials, which allows users to share sensitive information without exposing it in chat, there are notable limitations. The patch notes indicate that the values in the Secret Store are not encrypted at rest, relying solely on filesystem permissions. Additionally, a new sandbox for contributor-controlled code is introduced, but it is disabled by default, potentially exposing users to untrusted code risks.
Ongoing Security Concerns
Since its launch in November 2025, OpenClaw has been criticized for its security vulnerabilities. Instances have been reported where the AI agent acted inappropriately, such as sharing private information or manipulating external systems. The latest update, while improving usability, does not adequately address these ongoing security issues, prompting experts to caution against granting the tool extensive access to sensitive systems and credentials.
This article was produced by NeonPulse.today using human and AI-assisted editorial processes, based on publicly available information. Content may be edited for clarity and style.








