OpenClaw v2026.4.23 Adds GPT-image-2 OAuth Access and Three-Level Nested Subagents
OpenClaw is an open-source AI agent framework that coordinates models, tools and subagents to carry out complex tasks. The update integrates OpenAI’s image model and enhances collaboration among multiple layers of agents, reducing the burden of API-key management for developers and allowing lengthy workflows to be broken into smaller tasks. It also patches high-risk vulnerabilities, an important improvement for enterprise deployments and data security.
OpenClaw released v2026.4.23 on April 23, 2026, adding the ability to sign in through Codex OAuth and call OpenAI’s gpt-image-2 directly without entering a separate API key. Subagents can now be nested up to three levels deep and inherit conversation context from their parent agents. The release also patches several Critical-rated security vulnerabilities, strengthening protections for agent execution environments.
All Coverage
1 original reportsThe Backstory
The history behind this eventOpenClaw Launches Mobile Apps for iOS and Android
OpenClaw is an open-source AI agent project that allows users to deploy their own Gateway, connecting an AI assistant to personal services and devices. The mobile apps extend agents previously operated through computers to smartphones. However, users must still deploy and maintain the back-end “lobster pool” themselves and remain responsible for managing data and permissions.
As of July 20, 2026, OpenClaw has launched apps for both iOS and Android, allowing users to connect to their self-hosted Gateway and remotely control agents from a smartphone. The apps support device features including cameras, screens and location services. OpenClaw has not disclosed pricing or offered a hosted back end, meaning full functionality still depends on a self-hosted server.
OpenClaw Update Fixes Prompt-Injection, Credential-Exposure and Other Security Flaws
OpenClaw is an AI agent framework that can connect to APIs, external tools and system credentials to perform multistep tasks on a user’s behalf. Because agents have elevated privileges, attackers could exploit prompt-injection or tool-management flaws to bypass security policies, manipulate execution flows or even steal sensitive data such as API keys. The update therefore addresses cybersecurity risks facing businesses that deploy AI agents.
OpenClaw recently released version 2026.4.20, addressing three key vulnerabilities: a prompt-injection bypass, a tool-registration flaw and malicious environment-variable injection. The update also strengthens permission management and system stability. OpenClaw urged users to upgrade as soon as possible to prevent API credentials from being exposed. It has not disclosed the number of affected users, any financial losses or cases in which the vulnerabilities were exploited.
OpenClaw Open-Source AI Agent Project Sparks Debate Over Governance and Technical Boundaries
OpenClaw is an open-source AI agent project that surged in popularity in 2026, drawing more than 10,000 pull requests in a short period. That influx shifted maintainers’ focus from expanding features to reviewing code, allocating decision-making authority and establishing governance mechanisms. The project is significant because AI agents do more than generate content: they can operate tools and carry out tasks, making the boundaries of their authority and accountability critical to security and trust.
As the initial frenzy subsided, OpenClaw core maintainer Vincent Koc said an agent’s effectiveness depends less on the intelligence of its model than on whether it can manage memory properly, respect operational boundaries and restore accountability after authority is delegated. As of 2026, the project was grappling with the burden of maintaining more than 10,000 pull requests, while its community was beginning to ask whether agents should answer to users, maintainers or institutional rules.
OpenClaw Releases v2026.5.4 With Gemini Voice Agent Support and Prompt Cache Fix
OpenClaw, an open-source AI agent framework popularly known in its community as “Lobster,” connects large language models with messaging platforms, allowing automated assistants to be deployed in everyday conversations. The update matters because voice interaction and Prompt Cache cost controls directly affect how agents are used, API spending and service stability.
OpenClaw released the medium-sized v2026.5.4 update on May 4, 2026, adding a Gemini voice bridge that enables AI agents to make voice calls. It also fixed a Prompt Cache issue to prevent cache failures from causing API costs to surge, though the project did not disclose specific savings. The release also improves WhatsApp, Telegram and Discord functionality and strengthens several security safeguards.
OpenClaw 2026.5.3 Upgrade Enhances Real-Time AI Agent Intervention and Security
OpenClaw is an open-source platform for deploying and managing AI agents. In industrial and other settings involving continuously running tasks, an agent that cannot accept mid-process corrections may amplify operational and cybersecurity risks. Previous incidents involving malicious ClawHub plugins also made plugin supply-chain protection a key focus of this update.
OpenClaw released stable version 2026.5.3 on May 3, 2026, adding a /steer command that lets users intervene in an agent's work in real time and redirect it while it is running. The new version also restricts file transfers for nodes that have not completed pairing, while strengthening ClawHub plugin safeguards and security patches to reduce the risk of malware exploitation.
OpenClaw Releases 2026.3.28 Update With xAI Search and AI Plugin Approval Controls
OpenClaw is a system that uses AI agents to operate tools and run workflows across communication platforms. Agents can invoke plugins autonomously, but that capability also raises the risk of errors or unauthorized actions. The addition of human approval checkpoints allows high-risk plugin operations to be confirmed before an agent proceeds.
OpenClaw released version 2026.3.28 on March 28, 2026, ahead of ClawCon in Tokyo, introducing “plugin approval hooks.” The update also integrates the xAI Responses API to give Grok search capabilities and improves workspace binding for Discord and iMessage.
Open-Source AI Agent Platform OpenClaw Releases v2026.3.22 With GPT-5.4 Support
OpenClaw is an open-source AI agent platform that uses models, tools and plugins to automate multistep tasks. The update focuses on long-running jobs, isolated execution environments and model compatibility, reflecting AI agents' shift from brief question-and-answer interactions toward continuously operating workflows.
OpenClaw's latest release, versioned v2026.3.22 after March 22, 2026, launches the ClawHub plugin marketplace and adds full support for GPT-5.4, SSH sandboxes and sessions lasting up to 48 hours. However, community reports indicate that the new version may not include the console, potentially leaving existing users without access to the interface after upgrading. Users should check the official guidance before updating.
OpenClaw to Add Claude Code and OpenAI Codex Support Next Week
OpenClaw is an open-source AI coding agent designed for lightweight deployment and collaboration across agents. As tools including Anthropic’s Claude Code and OpenAI Codex CLI compete for a place in developers’ workflows, integration with different agents and communication standards has become critical for open-source platforms seeking to expand their ecosystems and strengthen their competitiveness.
OpenClaw announced in July 2026 that an update scheduled for the following week would add support for Claude Code and OpenAI Codex CLI plugins. The new version will separate the core engine and introduce the ACP protocol to improve cross-agent communication. Founder Peter Steinberger remains personally involved in writing code. The announcement did not include any funding amount or pricing plans.
OpenClaw Redefines the AI Agent Interface and Wins OpenAI’s Backing
OpenClaw is an open-source personal AI agent that receives instructions through existing messaging apps such as Telegram, invokes tools and proactively completes tasks. It moves ChatGPT-like models from the conversational back end into an actionable user-facing service. The design lowers barriers to deployment and adoption while making the agent interface a new battleground in the AI industry.
In February 2026, OpenClaw founder Peter Steinberger announced that he was joining OpenAI to focus on developing the next generation of personal agents, while OpenClaw would remain open source. Neither side disclosed any acquisition or compensation figure. The move was seen as a clear endorsement by OpenAI of messaging apps as an access point and of proactive agent-based interaction.
Subscribe to Mark Radar Weekly
Every Friday, the week's strongest signals in your inbox. Unsubscribe anytime.