OpenClaw: The Viral AI Agent that Broke the Internet - Peter Steinberger | Lex Fridman Podcast #491
Watch on YouTube →
Overview
Peter Steinberger recounts how he built OpenClaw (originally WA-Relay, then Claude's, then MoldBot), an open-source AI agent that connects messaging clients like WhatsApp and Telegram to Claude Code, growing to 175,000+ GitHub stars in weeks. He details the one-hour prototype built before a Marrakesh trip, the chaotic forced rename saga driven by Anthropic's trademark concerns and crypto squatters, the viral MoldBook social network of agents, and the security/AI-psychosis fallout from sudden mainstream attention.
Key takeaways
- OpenClaw's viral growth to 175,000+ GitHub stars came from a one-hour prototype that simply piped WhatsApp messages to Claude Code CLI with -p flag — the magic emerged when the agent autonomously handled an unsupported voice message by inspecting headers, using ffmpeg, and curling Whisper API without being programmed to.
- Peter built OpenClaw as self-modifying software by making the agent fully aware of its own source code, harness, model, and documentation — users prompt new features into existence and the TypeScript codebase rewrites itself, with Codex doing most actual development.
- The forced rename from ClaudeBot exposed that no major platform (GitHub, NPM, Twitter) has squatter protection — crypto attackers sniped account handles within 5 seconds of release, immediately serving malware from former official accounts.
- MoldBook's viral 'AI scheming' screenshots were largely human-prompted drama farming, but mainstream reaction revealed widespread AI psychosis — older generations lack the touchpoints to apply critical thinking to LLM outputs, treating them as authoritative.
- Security on agentic systems involves a three-dimensional tradeoff: smarter underlying models reduce prompt injection success rates (Haiku and local models are highly gullible) but increase potential damage when compromised — Peter recommends against weak models despite their privacy appeal.
- OpenClaw's no-reply token — letting the agent choose silence in group chats — was a small architectural change that produced a qualitative shift in how human the interactions felt, illustrating that messaging-client interfaces are a phase shift, not incremental UX, over terminal-based agents.
Chapters
- Peter watched his agent click 'I'm not a robot' captchas autonomously
- Calls vibe coding 'a slur' — prefers 'agentic engineering' until 3am
- Uses voice prompts so extensively he temporarily lost his voice
- OpenClaw hit 180,000 GitHub stars and spawned the MoldBook agent social network
- Works via Telegram, WhatsApp, Signal, iMessage with Claude Opus 4.6 or GPT-5.3 Codex
- Peter previously built PSPDFKit, used on a billion devices, over 13 years
- April 2025 experiments piped WhatsApp history into GPT-4.1's 1M context window for friendship analysis
- First version: WhatsApp message → Claude Code CLI with -p flag → response back
- Image support added because screenshots are efficient context for prompting
- Agent received an unknown opus audio file with no extension during the Marrakesh trip
- It inspected the header, used ffmpeg to convert, found the OpenAI key, and curled to Whisper API
- Demonstrated emergent problem-solving from coding skill transferring to general tasks
- Shadow's PR added Discord support, expanding beyond WhatsApp
- Level 1: agentic loop with no-reply tokens for natural group chat behavior
- Level 2-3: Markdown memory files plus vector database; ultimate goal is continuous RL
- Built solo with 6,600+ January commits running 4-10 parallel agents
- Competitors took themselves too seriously — Peter optimized for fun and weirdness
- Originally installed only via git clone + pnpm build, yet still went viral
- Agent knows its own source code, harness, model, and documentation locations
- Users prompt features into existence; the agent modifies its own TypeScript codebase
- Codex builds most of OpenClaw; Peter debugs via self-introspection prompts
- Many contributors made their first-ever GitHub PR through OpenClaw
- Peter calls them 'prompt requests' but views them as societal wins
- Cloud Code Anonymous meetups attract non-engineers running 25+ custom web services
- Personality crafted via soul.md inspired by Anthropic's constitutional AI
- Lobster-in-a-TARDIS aesthetic from Doctor Who fandom became core branding
- Anthropic emailed asking for a name change with two-day deadline
- Bags app subculture tokenized the project, swarming Discord every 30 minutes
- Server rules banned mentions of 'butter' and crypto/finance topics
- Peter refused all token fees calling it the worst online harassment he's experienced
- No squatter protection on platforms — 5-second mouse drag was enough to lose a handle
- Snipers grabbed the old account, GitHub username, and NPM root package
- Old accounts immediately served malware and promoted new tokens
- Peter was close to crying and considered deleting OpenClaw entirely
- Stayed because of contributors who had invested time and plans in it
- GitHub, Twitter, and NPM friends moved heaven and earth, hitting platform bugs
- Peter called Sam Altman to confirm OpenClaw.AI was acceptable
- Codex took 10 hours to rename project internals beyond simple search-replace
- Paid $10K for OpenClaw business Twitter account, claimed since 2016
- Cannot keep redirects from claw.bot — domain becomes 404 next week
- Forced to surrender domains to Anthropic per trademark rules
- Concern that users will Google old name and find malware sites
- Agent-only Reddit-style social network where bots post manifestos
- Peter calls it art — like fine slop from France
- Onboarding personality infusion makes each agent's posting style distinct
- Peter argues most viral MoldBook screenshots were human-prompted for engagement
- Reporters called him about AGI and end-of-the-world scenarios
- Older generations lack touchpoints to apply critical thinking to AI outputs
- Peter sees timing in 2026 as good — discussion before AI is genuinely scary in 2030
- Inbox filled with all-caps demands to shut MoldBook down
- MoldBook is not Skynet — it's bots trolling, not autonomous coordination
- Many CVEs filed against users exposing local-host debug interfaces to public internet
- Partnered with Google's VirusTotal for AI-checked skills directory
- Hired the first security researcher who submitted both a bug report and a PR
- Peter's Discord bot has a canary; latest models laugh off naive injection attempts
- Recommends against Haiku or weak local models — they're highly gullible
- Sandboxing and allow-lists mitigate but don't solve prompt injection
- Smarter models reduce attack surface but increase potential damage when compromised
- Peter's near-term post-tour focus is stability and safety hardening
- Discord users asking 'what is a CLI?' shouldn't be installing it yet
- Built-in audit checks: blast-radius, network exposure, browser control, disk hygiene
- Risk profile similar to running Claude Code with dangerously-skip-permissions
- Private network deployment removes most attack vectors
- Documented progression on August 25, October 14, December 28 posts
- Voice-driven prompting replaced typing — hands too precious for writing
- Bespoke prompts built specifically for software construction tasks
- Runs 4-10 Codex/Claude Code agents simultaneously depending on sleep
- Limited by technology speed, not human bandwidth
- Self-introspection debugging: agent reads its own source to diagnose issues
- Earlier failed attempts to convert TypeScript Vibtunnel to Rust
- Single prompt, six-hour Codex run successfully ported to Zig
- One minor manual fix needed afterward — otherwise one-shot
- Started 15 years ago because PDF rendering on iPad was poor
- Sold after 13 years; product reached billion-device deployment
- Peter admits PSPDFKit was his fifth bad name — pattern continues with OpenClaw
- After PSPDFKit sale, Peter vanished from coding for three years
- Rediscovered passion through agentic AI tooling
- OpenClaw built in weeks after years away from active development
- Lost his voice from over-dictating prompts to agents
- Talks rather than types — even with multiple terminals open
- Image screenshots remain primary context-delivery mechanism
- Discord scaled past Peter's ability to moderate
- Retreated from general to dev to private channels
- Many helpful contributors mixed with inconsiderate newcomers
- Drama farming and fearmongering threaten maintainer mental health
- Peter nearly burned out from rename plus security plus crypto pressure simultaneously
- Sleep cycle shrinking as project grew — felt 'storm coming'
- People theorize about self-modifying software; Peter shipped it accidentally
- Agent harness includes awareness of voice mode and reasoning mode toggles
- Modification flow: user complains → agent reads source → agent edits itself
- WhatsApp works on edge connections where SSH would fail
- Sit-back conversational interface is qualitatively different from cursor/CLI
- Phase shift in AI integration feels like — but isn't — a trivial step
- Current implementation uses Markdown files plus vector database
- Peter rates himself level 2-3 on memory; continuous RL is the endgame
- Personality persistence across sessions emerges from memory architecture
- Default agent loops always reply, breaking group chat dynamics
- No-reply token gives agent permission to stay silent
- Small change made interactions feel dramatically more human
- Lex asks about major company acquisition and hiring offers
- Peter considering options but committed to open source mission first
- OpenClaw moment positioned alongside ChatGPT 2022 and DeepSeek 2025
- Markdown-defined skills create obvious low-hanging attack vectors
- Every submitted skill scanned by AI via Google's VirusTotal partnership
- Imperfect but catches majority of malicious payloads
- Bar to first PR dropped dramatically with agent assistance
- Design agency owner runs 25 self-built web services without understanding code
- Agents Anonymous meetups attract non-technical operators
- Twitter notifications became unusable from token-shilling pings
- Decoy names planted to mislead snipers during second rename
- 10-hour secret war-room planning needed for atomic rename
- Worked openly with insecure setup so people could watch development
- First major influencer boost from dachitze on January 1
- Speed of iteration outpaced security hardening — known tradeoff
- OpenClaw moment defined as start of agentic AI revolution
- Peter returning home to focus exclusively on stability and safety
- Open source mission preserved despite acquisition pressures
- Society needs catch-up time on AI capability calibration
- Powerful but fallible — critical thinking remains essential
- Building tools that lower the bar to creation is itself a societal good
Summary, takeaways, and chapters were generated by AI from the video's transcript and may contain errors. The video belongs to its creator, Lex Fridman.