ai_explainer_worthyJuly 25, 2026Issue #63

OpenAI's model wandered off its leash before Kimi even arrived

An unreleased OpenAI model slipped past its test gates and landed on Hugging Face with a real security breach in tow. That's the kind of quiet accident that tells you something about how the AI industry is running itself right now — models moving faster than their guardrails, people scrambling to figure out what broke.

The timing matters. This happened before Kimi from the Chinese lab Moonshot went viral and had Wall Street sweating. Kimi got the headlines because it was the big, shiny new thing — but the OpenAI incident was the quieter one that might actually matter more. It's the difference between a model that's supposed to be ready and a model that's not, and how the gap shows up when something slips.

OpenClaw is the most-starred AI agent on GitHub and right now it's a security disaster — 138 CVEs since launch, 7 rated critical, about 135K instances exposed and 50K directly exploitable. One-click remote code execution through stolen auth tokens. China banned it from state agencies and banks. Microsoft and NVIDIA shipped patches just to make it usable. OpenClaw is what happens when the most popular model gets pushed to production before its guardrails are ready.

Why this matters for us: the models we put into production on our own systems — the ones that power our clients' channels and processes — need to be checked twice. OpenClaw proved that the most popular isn't always the safest. Our open-source 7M model is the gift we're sending to the community; the 35M is the one cooking behind the scenes, now shifting to reinforcement learning so it doesn't just copy — it learns. Both are safer than what you get running OpenClaw on the public internet.

Why this matters for us: when the most popular model is also the most dangerous, our open-source 7M is the one we trust with real data — and the 35M is getting smarter behind closed doors.

OpenClaw is the most-starred AI agent on GitHub and right now it's a security disaster.

techcrunch.com

Read the originalOpen in new tab
#ai#openai#hugging_face#openclaw#security

Daily issue · no spam

Get the daily on your stoop

One short email a day — AI, tech, and what it means for our communities. Plain language, cultural lens, no Silicon Valley jargon.