The Sixty-Day Hype Cycle: OpenClaw and the Cooling of AI Sentiment
OpenClaw went from 'closest thing to JARVIS' to CVEs and a China ban in weeks. The same arc is showing up in the AI economy at large.
In January and February this year, OpenClaw was the thing. An open-source agent built by Peter Steinberger, the PSPDFKit founder, that ran locally, kept memory across sessions, and had actual hands on your machine: filesystem, shell, browser, email, calendar, whatever you granted it. People called it the closest thing to JARVIS anyone had shipped. It went from nothing to one of the fastest-growing repositories in GitHub's history, by some counts crossing hundreds of thousands of stars within about two months.
By March it was getting banned from Chinese government computers. By spring, people were paying strangers on secondhand marketplaces to uninstall it. That is not a slow fade. That is a full hype cycle compressed into a single quarter, and it is a useful lens for the bigger thing you are noticing, which is that the sentiment around AI doing everything for us, replacing jobs wholesale, has cooled off hard in 2026. OpenClaw did not cause that mood shift. But it is the cleanest single case study of how it happened.
Sixty days from JARVIS to uninstall scripts
The growth numbers are reported inconsistently across outlets, which is itself worth noting. Some coverage puts OpenClaw at 60,000-plus GitHub stars within 72 hours of launch. Other pieces describe it crossing roughly 250,000 stars within about 60 days, faster than any repository in GitHub's history, including React, which took over a decade to get there. I could not pin either number to a primary source I trust fully, so treat them as directionally true and specifically fuzzy: this was viral at a speed the ecosystem had not seen before, full stop.
What broke the mood was not the model underneath it. It was everything wrapped around giving an autonomous agent unsupervised system access:
- Insecure defaults. Early versions bound to
0.0.0.0:18789by default, meaning tens of thousands of self-hosted instances were reachable from the open internet without anyone deliberately choosing that. - CVE-2026-25253. A one-click remote-code-execution bug, later confirmed by multiple security vendors including runZero and SonicWall. A malicious link could trick the client into opening a WebSocket to an attacker-controlled gateway and hand over the user's auth token, which, because the agent has full shell and file access, meant handing over the whole machine.
- A poisoned plugin marketplace. Reporting on the ClawHub skill marketplace described hundreds of malicious packages, including crypto-stealing malware, with one researcher saying he found malware within two minutes of looking.
- A rename under trademark pressure. The project moved from an early name referencing Claude directly, through an intermediate name, to OpenClaw, reportedly after pushback from Anthropic.
- A state-level response. In March, Bloomberg and others reported that Chinese regulators told government agencies and state-owned banks to stop installing OpenClaw on office machines and, in some cases, personal phones on corporate networks, and to report existing installations for review. Notably, this happened at the same time some Chinese local governments were subsidizing companies building on top of it, which tells you the ambivalence was structural, not just online noise.
- A visible market for regret. "OpenClaw uninstallation service" listings reportedly appeared on Chinese resale platforms within weeks of the peak.
Steinberger's own framing, from his appearance on the Lex Fridman podcast, is worth keeping: he pushed back on some of the criticism as users exposing their own machines to the internet through their own configuration choices, while acknowledging that making the insecure configuration possible at all made it his problem. He also described the security research attention as being "DDoSed by security advisories," which is a fair complaint and also exactly what happens when a tool this capable ships this fast to this many people.
The same story, four sizes up
Zoom out from one tool to the whole AI economy and the same pattern shows up in four separate places, none of which needed OpenClaw to happen but all of which rhyme with it.
Money. In Bank of America's July 2026 Global Fund Manager Survey, fielded July 2 to 9 across 210 managers overseeing a combined $555 billion, 45% named "AI bubble" as the single biggest tail risk to markets, up from 33% the month before. The same survey found 53% of those managers still believe AI is already boosting productivity, which is the important detail: the fear is about valuation and capital allocation, not about whether the technology works. Underneath that sits the circular financing story: Bloomberg tracked more than $540 billion in 2026 deals where Nvidia funds a customer who then spends heavily on Nvidia chips, and Michael Burry has pointed to a roughly 90% year-to-date rise in the cost of insuring Nvidia's debt as evidence the market is starting to price the same worry. The IMF and the Bank for International Settlements have both flagged this circular structure as a systemic risk worth watching, not just a Twitter argument.
Labor. Challenger, Gray & Christmas's own monthly reports show AI leading all stated reasons for job cuts for two consecutive months this spring, with 21,490 AI-attributed cuts in April alone, about 26% of that month's total, and AI accounting for roughly 16% of all 2026 job-cut plans through April, up from 13% through March. That is a real, rising number. It sits next to a genuinely inconvenient complication from Gallup: in their data, the majority of laid-off workers were not AI users, and only about 1% of respondents named AI or automation as the primary reason for their own job loss. Companies are increasingly willing to cite AI in cut announcements; workers are not experiencing "an AI took my job" nearly as often as the announcements suggest. Sam Altman himself, in a Time interview in May, walked back the doomier framing, saying the "jobs apocalypse" narrative probably will not play out the way people feared. That is the CEO of the company most associated with the threat, saying the threat was overstated.
Public trust. Gallup and Bentley University's tracking survey found trust in businesses to use AI responsibly slipping from 31% to 27% between 2025 and 2026, and the share who think AI does more harm than good rising from 31% to 39%. Pew's 2026 work found 63% of Americans think AI is advancing too fast, and only 16% expect its impact over the next 20 years to be net positive. The sharpest number in there: among adults under 30, the heaviest users of the technology, 50% expect it to be net negative for society versus 14% who expect it to be positive. Meanwhile adoption keeps climbing regardless, half of US adults now use an AI chatbot, up from a third in 2024, which is its own kind of interesting: people are using it more and trusting it less, at the same time.
Product reality. MIT's NANDA initiative, in a study built from 52 executive interviews, a survey of 153 leaders, and analysis of 300 public deployments, found 95% of generative AI pilots inside companies delivered no measurable profit-and-loss impact. The stated reason was not model quality, it was integration: companies buying tools that did not fit their actual workflows, versus the minority who partnered externally and picked one sharp problem to solve, who saw real results. Gartner's first standalone Hype Cycle for Agentic AI, published in April 2026, put the category at the Peak of Inflated Expectations tipping into the Trough of Disillusionment, and noted only 17% of organizations have actually deployed an AI agent despite more than 60% saying they plan to within two years. The failure mode Gartner describes reads like a corporate version of OpenClaw's problems: agents hallucinating approvals in procurement workflows, burning five-figure API bills in runaway multi-agent loops, executing writes against production systems with nobody in the loop to catch it.
What I think is actually going on
The frame I keep seeing is "the AI bubble is popping," and I think that overstates it in the same way "AI will do everything and replace everyone" overstated it six months ago. Both are trying to compress a genuinely mixed picture into one number.
What is actually cooling is a specific, narrow claim: that you could hand an autonomous system your credentials, your inbox, your shell, and your job function, and walk away. OpenClaw is the literal version of that claim, and it broke exactly where you'd predict, at the boundary where autonomy meets unsupervised access to real systems. The corporate version of the same claim broke the same way, in the Gartner failure modes: agents making real-world writes with nobody checking. The labor version broke where Altman himself backed off it. The financial version is not breaking so much as getting priced more honestly, which is what a fund manager survey moving from 33% to 45% actually represents, a market recalibrating a probability, not a market discovering the technology is worthless.
What is not cooling: actual usage. Adoption numbers keep going up in Pew's data even as trust goes down. 53% of fund managers still say AI is boosting productivity even while they call it the top tail risk. The MIT study's own framing is that the 5% of pilots that work, work well, the failure is organizational, not technical. None of that is bubble-popping language. It is correction language: the specific, breathless version of the story, agents doing everything for us with no adult in the room, was always the hype part. The underlying capability was never the part in question.
If you want the OpenClaw version of that lesson in one line: the tool itself was genuinely useful to a lot of people, and it still is, patched and past the CVE. What collapsed was the specific pitch of "give it root and forget about it." That is a narrower claim than "AI agents don't work," and it is the claim that actually needed to die.
Where I'd flag uncertainty
In the spirit of not overclaiming: the OpenClaw star-count numbers conflict across sources and I would not repeat either figure as precise. The rename history (an early Claude-referencing name, an intermediate name, then OpenClaw) is reported consistently enough that I trust the shape of it, but I did not find a single authoritative timeline with dates I'd stand behind. And the labor numbers are the trickiest pairing in this whole piece: Challenger's cut announcements and Gallup's worker-level attribution are measuring genuinely different things, one is what companies say in press releases, the other is what laid-off people report as the reason, and they are going to keep disagreeing for a while. That gap is itself part of the story, not a flaw in it.
References
- Fridman, L. (2026). Peter Steinberger: OpenClaw, the Viral AI Agent that Broke the Internet. Lex Fridman Podcast #491. lexfridman.com
- runZero (2026). OpenClaw RCE vulnerability: CVE-2026-25253. runzero.com/blog/openclaw
- SOCRadar (2026). CVE-2026-25253: 1-Click RCE in OpenClaw Through Auth Token Exfiltration. socradar.io
- Bloomberg (2026, March 11). China Moves to Limit Use of OpenClaw AI at Banks, Government Agencies. bloomberg.com
- Fast Company (2026). China went crazy for OpenClaw. Now it's working to ban it. fastcompany.com
- Bank of America (2026, July). Global Fund Manager Survey, as reported by CNBC and Seeking Alpha. cnbc.com
- Bloomberg (2026). AI Circular Deals: How Microsoft, OpenAI and Nvidia Keep Paying Each Other. bloomberg.com/graphics/2026-ai-circular-deals
- Benzinga (2026). Michael Burry Warns Nvidia's 'Overreaching' Is Pushing Circular Spending to 'Biblical Proportions'. benzinga.com
- Challenger, Gray & Christmas (2026). Job Cut Announcement Report, April 2026. challengergray.com
- Time (2026, May 26). Sam Altman Says AI 'Jobs Apocalypse' Probably Won't Happen. What Changed?. time.com
- Gallup (2026). Americans Cool Toward AI, with Bentley University. news.gallup.com
- Pew Research Center (2026, March 12). Key findings about how Americans view artificial intelligence. pewresearch.org
- Pew Research Center (2026, June 17). Americans and AI 2026: Chatbots, Smart Devices and Views on Impact. pewresearch.org
- MIT NANDA Initiative (2025). The GenAI Divide: State of AI in Business 2025, as reported by Fortune and Forbes.
- Gartner (2026, April). Hype Cycle for Agentic AI, 2026. gartner.com