# The Unlocked Door: Ryan Eade on What OpenClaw Users Need to Secure Right Now Page: https://stenobird.com/podcast/nc-tweener-talks-7053588/the-unlocked-door-ryan-eade-on-what-openclaw-users-need-to-secure-right-now Text version: https://stenobird.com/podcast/nc-tweener-talks-7053588/the-unlocked-door-ryan-eade-on-what-openclaw-users-need-to-secure-right-now.md Podcast: [NC Tweener Talks](https://stenobird.com/podcast/nc-tweener-talks-7053588) Published: 2026-07-14T06:00:00+00:00 Episode link: https://share.transistor.fm/s/a175693c Audio file: https://media.transistor.fm/a175693c/bd2f2a61.mp3 Processing state: not_requested JSON: https://stenobird.com/v1/public/podcasts/nc-tweener-talks-7053588/episodes/the-unlocked-door-ryan-eade-on-what-openclaw-users-need-to-secure-right-now Duration seconds: 1282 ## Resource Ryan Eade, Chief Product and Technology Officer at PtEverywhere, gave this talk at the June 10th TweenerClaw meetup, and it covers something most practitioners skip: how to actually keep your OpenClaw instance secure. Ryan walks through the three main ways OpenClaw instances get compromised: an open port that older versions left fully exposed, third-party skills that can carry malicious code (36% of early store listings had prompt injection), and prompt injection delivered through external content like X posts or README files. He also covers the upgrade windows that matter most; the March 12th and April 5th releases each contained critical security patches, and what to do right now: curl port 18789 on your OpenClaw and see if you get a response back. The practical framework Ryan closes with is worth listening to by itself. He calls it "staff not software" with the idea that every access decision for your OpenClaw should mirror how you'd onboard a new employee: scoped API keys with minimum permissions, a purpose-built email account, one-time credit cards for purchasing tasks, and human approval gates before any destructive action runs. If you've been meaning to lock down your setup but kept putting it off, Ryan gives you everything you need to do it in under 20 minutes. Timestamps 00:00 Intro bumper 00:16 Sponsor recognition 01:22 Scot's intro 01:56 Introducing Ryan Eade 02:05 Ryan's topic: cybersecurity for OpenClaw 02:50 Ryan Eade 03:28 "Nobody starts with security" 04:10 Why OpenClaw isn't just a chatbot 05:26 The threat landscape 06:09 Early OpenClaw exposure stats 06:40 Threat 1: The open port 07:28 Docker's dirty secret: it bypasses your local firewall 08:07 Fix: bind to localhost and use Tailscale 09:19 What Tailscale is and why it works 09:26 Threat 2: Third-par… ## Actions - request_transcript: `POST https://stenobird.com/v1/public/podcasts/nc-tweener-talks-7053588/episodes/the-unlocked-door-ryan-eade-on-what-openclaw-users-need-to-secure-right-now/transcription-requests` — Idempotently request low-priority transcript generation for this episode. - read_markdown: `GET https://stenobird.com/podcast/nc-tweener-talks-7053588/the-unlocked-door-ryan-eade-on-what-openclaw-users-need-to-secure-right-now.md` — Read the agent-friendly Markdown representation of this episode resource. A page view does not enqueue transcription. Agents should invoke `request_transcript` explicitly when they need this episode processed. ## Transcript Full transcripts are not published on public pages unless there is a clear rights basis.