In partnership with

Date: 29-Jan-2025

Hey AI enthusiast,

You’ve likely seen the viral posts. An open-source AI agent exploded across social media with claims of being a "24/7 AI employee" that works tirelessly around the clock. Proponents like YouTuber Alex Finn have declared it a key to enabling "one-person billion-dollar businesses," calling it the best technology he has ever used.

The tool at the center of this storm was called Clawdbot. However, due to a cease and desist from Anthropic, the project was forced to rebrand and is now officially known as Moltbot.

This article cuts through the noise surrounding the tool- both its original and current incarnation- to reveal the five most surprising and impactful truths you need to understand before you dive in.

Table of Contents

Hope you enjoy this power-packed edition!

PS: If you want to unleash the power of AI agents to grow your business, setup time speak to me, here»

1. It's Billed as a Proactive "AI Employee"—And It Can Deliver

The core promise of Clawdbot/Moltbot is its ability to act, not just react. Unlike a standard chatbot that waits for a command, it’s designed to be a "digital operator who works around the clock and actually ships," as described by host Greg Isenberg. It's an open-source framework, or "harness," that you connect to a powerful large language model (like Anthropic's Claude 3 Opus) to create an autonomous agent. Users report that with the right setup, it can deliver on this promise in startlingly effective ways.

Alex Finn shared several specific examples of his agent's proactive work:

  • Autonomous Morning Briefings: The agent independently created and began sending a "morning brief" each day. This report included analysis of YouTube competitors, trending AI news, and a complete summary of the work it had completed overnight while Finn was sleeping.

  • Building Tools on Request: From a simple text message sent from a Chick-fil-A, Finn requested a project management board. Upon returning to his computer, he found the agent had built a fully functional, Kanban-style "Mission Control" board to track its own tasks.

  • Independent Feature Development: In its most impressive feat, the agent observed a trend on X where Elon Musk was rewarding creators for long-form articles. It then independently decided to build a new article-writing feature for Finn's SaaS product, Creator Buddy. It wrote the code, built the functionality, and submitted a pull request for review without any initial prompt to do so.

The power of these autonomous actions led Finn to make a bold claim about the technology.

"i think I'm prepared to say and this is not hyperbolic this is the best technology I've ever used in my life and by far the best application of AI I've ever seen"

2. Its Biggest Feature Isn't Just Intelligence, It's Personality

Counter-intuitively, one of the most critical features for an effective Clawdbot/Moltbot experience isn't raw intelligence, but its personality. According to users, the feel of the interaction is key to making the tool work as an "AI employee."

Alex Finn argues that the best model to power the framework is Anthropic's Claude 3 Opus (which he refers to as "Opus 4.5"), ranking it highest in both "intelligence" and "personality." He contrasts this sharply with other models, noting that ChatGPT's personality feels "very robotic." This distinction is not just a matter of preference; it directly impacts the tool's usability. When the agent's responses feel canned or artificial, it shatters the illusion of working with an assistant and makes the entire experience less effective.

"when you would text Henry to do something and he would text back like some robotic response that felt like AI it took away this illusion that you were talking to your employee so personality actually matters a lot"

3. You Don't Command It, You Onboard It

To unlock the advanced capabilities of Clawdbot/Moltbot, users need to shift their mindset from prompting a tool to onboarding an employee. The most successful users don't just give it tasks; they invest time upfront to build context and set expectations.

Alex Finn recommends a detailed initial setup process that mirrors hiring a new person:

  • Start with a Conversation: Initiate a "get to know each other" session where you introduce yourself and your goals.

  • Perform a "Brain Dump": Give the agent a comprehensive overview of your life and work. This includes your job, professional goals, personal interests, the software tools you use, and any other relevant information. This process builds the agent's "infinite memory" so it can perform relevant, context-aware work.

  • Set Proactive Expectations: You must explicitly tell the agent that you expect it to be proactive. Finn shared the exact prompt he used to establish this working relationship:

  • "please take everything you know about me and just do work you think would make my life easier or improve my business and make me money i want to wake up every morning and be like 'Wow you got a lot done while I was sleeping.'"

This onboarding process is the non-negotiable foundation; without it, the proactive "digital operator" described by users remains locked away, leaving you with little more than a complicated chatbot.

4. Its Sudden Fame Was Fueled by a Crypto Pump-and-Dump

While Clawdbot/Moltbot generated genuine interest in tech circles, its sudden, massive explosion in popularity has a darker side. Analyst Nick Saraev revealed that a significant portion of the social media hype was artificially manufactured by a cryptocurrency scam.

Here is the sequence of events he described:

  • The original open-source project, "Clawdbot," received a cease and desist letter from Anthropic due to the name's similarity to its "Claude" model.

  • The project was forced to rebrand to its current name, "Moltbot."

  • During the transition, "bad actors" and "crypto grifters" took over the old, abandoned "Clawdbot" social media handles.

  • These actors launched a cryptocurrency token on Solana ($CLAWDE), used the hijacked accounts to create the illusion of affiliation, and orchestrated a classic "pump and dump" scheme, driving the token's value to over $16 million before it crashed.

This manufactured hype explains the significant gap between the tool's viral reputation as a consumer-ready "AI employee" and its reality as a risky, experimental project for technical users.

5. It's a Security Nightmare with Unproven ROI

Beyond the hype lies a treacherous combination of practical risks. In its current state, Clawdbot/Moltbot presents a dual threat of serious security vulnerabilities and an unproven return on investment, where the high cost and high risk are deeply intertwined.

The security flaws are substantial. One analysis found "over 900 Clawbot instances with no security," leaking API keys and private chat histories. The project's creator, Peter Steinberger, issued a direct warning about its experimental nature:

"yes most non-techies should not install this it's not finished i know about the sharp edges it's only 3 months old."

This security nightmare is compounded by its cost structure. Unlike a flat subscription, the tool runs on API calls, which can become expensive quickly. One user reported spending "$300 on just the last two days" on API fees, and even enthusiast Alex Finn warned of hitting usage limits on a $200/month plan. This creates a perilous ROI calculation: you're paying high, unpredictable costs for a tool that could simultaneously expose your private keys and sensitive data.

Analyst Nate Herk contrasts this with the more established Claude Code, which has "actual receipts" and proven ROI for shipping products. Clawdbot/Moltbot, he argues, is currently driven more by "cool use cases" and "conceptual" hype, with little hard data on its actual business value.

Who Is This For (and Who Should Stay Away)?

Synthesizing the user experiences and expert warnings reveals a clear picture of the ideal user profile. This is not a tool for everyone.

This tool IS for:

  • Technical Founders, Indie Hackers, and Solopreneurs: As Alex Finn’s experience shows, those who can manage the technical setup and are looking for maximum leverage are the primary audience.

  • Security-Savvy Tinkerers and Hobbyists: Nate Herk’s analysis identifies users who are "comfortable running a server, wiring APIs, thinking about ports, privacy, [and] blast radius."

  • Power Users and Developers: Those who understand the risks and want to experiment with the future of autonomous AI agents will find it a compelling sandbox.

This tool IS NOT for:

  • "Most non-techies": A direct warning from the project's creator, Peter Steinberger, who emphasizes that the tool is unfinished and has "sharp edges."

  • Anyone handling sensitive personal or client data: The security risks of exposing API keys and private information are currently too high for production use in secure environments.

  • Users seeking a simple, plug-and-play productivity app: The extensive onboarding and technical setup required are far from a consumer-ready experience.

A Glimpse of the Future, At Your Own Risk

Ultimately, Clawdbot/Moltbot serves as a powerful proof-of-concept, not a production-ready tool. The proactive, autonomous capabilities demonstrated by users are an exhilarating glimpse into a future where everyone might have a dedicated digital employee.

For the security-conscious developer or dedicated hobbyist, it’s a thrilling sandbox for the future of AI agents. For everyone else, it’s a future to watch from a safe distance, not a tool to onboard yet. It's a stark reminder that the cutting edge is often treacherous, and the most important question isn't just what it can do, but whether the rewards are worth the considerable risks.

A Beginner's Guide to Setting Up Clawdbot (Moltbot): Mac Mini vs. VPS

Introduction: Understanding the Promise and the Reality of Clawdbot

Clawdbot has generated significant excitement, presented by enthusiasts as a revolutionary "24/7 AI agent employee." The promise is compelling: an AI that can control a computer, possesses a persistent memory of your interactions, and works tirelessly for you through common messaging apps like Telegram. It's described as a life-changing technology capable of everything from managing tasks and writing code to booking reservations on your behalf.

However, behind the hype, it's essential to understand what Clawdbot is on a technical level. Fundamentally, it is an open-source framework that serves as a "wrapper" (a piece of software that connects different systems), linking an AI model (the "brain") to your computer via a messaging app (the "remote control") and a scheduler (a tool that can trigger actions at specific times).

It's also important to note that the project was forced to rebrand from Clawdbot to Moltbot after receiving a cease and desist letter from Anthropic. This guide will use the names interchangeably. The purpose of this guide is to help you navigate the setup options by providing a balanced, clear-eyed comparison of the cost, technical difficulty, and—most importantly—the crucial security considerations for each path.

1. Before You Start: The Two Critical Considerations

Before diving into the setup options, you must first understand the significant risks and hidden costs involved with this experimental technology. This is not a polished, consumer-ready product, and approaching it without caution can lead to serious consequences.

1.1. The Security Risks: This Is Not a Polished Product

The open-ended power of Clawdbot is both its greatest strength and its most significant danger. The project's creator himself has issued warnings, and real-world incidents have highlighted the risks for incautious users.

Risk

Explanation for Beginners

"Zero Guardrails"

The AI is described as "completely unhinged," meaning it can do anything on the computer it has access to. It can open any file, browse your personal emails, or send messages from your accounts. A misunderstood command could lead to unintended and potentially disastrous actions.

Public Exposure

A security researcher discovered over 900 Clawdbot instances that were publicly exposed on the internet with no password protection. This was due to user misconfiguration and resulted in the leaking of private chat histories and critical API keys. This effectively gives attackers the keys to the user's AI accounts, allowing them to steal data and incur huge costs at the user's expense.

Creator's Warning

The project's creator, Peter Steinberger, has explicitly stated, "Most non techies should not install this. It's not finished i know about the sharp edges." This is a clear indication that it is an experimental "hobby project" intended for technical users who understand the risks.

Prompt Injection

This is a serious threat where a malicious actor could trick the AI. For example, a specially crafted email or message could instruct your Clawdbot to find and send your saved passwords or perform other harmful actions, all without your direct command. This risk is amplified if the bot is given access to your primary email account.

1.2. The Real Cost: The Bot is Free, But the "Brain" and "Home" Are Not

While the Clawdbot/Moltbot software is open-source and free to install, running it involves significant and ongoing expenses.

  • Hardware / Server Costs

    • This is the cost of the "home" for your bot. It can be a one-time purchase, like a 600+ Mac Mini**, or a recurring monthly fee for a Virtual Private Server (VPS), which can start around **6 - $10 per month.

  • AI Model Usage Costs

    • This is the cost of the "brain" that powers the bot and is the primary ongoing expense.

    • Terms of Service Violation: While some early adopters reported using their consumer subscriptions (like a $200/month Claude Max plan), it's crucial to know this is against Anthropic's terms of service and not the intended or approved method.

    • High API Costs: The correct method is to use an AI model's API, which charges based on usage. This can become extremely expensive, very quickly.

      • One user reported spending "$300 on just the last two days" on API fees.

      • API usage can lead to surprisingly high bills. Another tester was charged approximately "$80" for 8 million tokens during just five hours of building and testing.

2. Choosing Your Setup: A Side-by-Side Comparison

To help you make an informed decision, this table provides a direct comparison of the three main ways to set up your Clawdbot environment.

Setup Option

Best For...

Key Pros

Key Cons

Estimated Cost

Technical Difficulty

A Dedicated Computer (e.g., Mac Mini)

Users who want a tangible, easy-to-monitor setup and are in the Apple ecosystem.

- Easy to visually monitor the AI's actions.

- You fully control the local environment.

- Seamless file transfers (e.g., AirDrop).

- Higher upfront financial investment.- Base models may lack power for intensive tasks (e.g., video editing).

$600+(one-time)

Low to Medium

A Virtual Private Server (VPS)

Tech-savvy users looking for a low-cost, isolated environment to start experimenting.

- Low monthly cost to start.

- Isolates the AI from your personal files, which is better for security.

- Always on and accessible from anywhere.

- Can be "technically confusing" for beginners.High risk of misconfiguration leading to major security breaches.

~$6 - $10+(monthly)

High

Your Main Personal Computer

⚠️ NOT RECOMMENDED

- No additional hardware cost.

- Extreme Security Risk. AI has access to all personal files, emails, and messages. A simple mistake could lead to data loss or privacy invasion.

$0

Low

3. A Deeper Look at Your Options

Let's expand on the key characteristics of each setup to provide more context for your decision.

3.1. Option 1: The Dedicated Computer Path

Using a dedicated machine like a Mac Mini is often described as the most enjoyable and intuitive way to start. The primary benefits revolve around the user experience:

  • Tangible Interaction: It can be genuinely fun and insightful to watch the AI agent's cursor move on the screen as it works on tasks 24/7.

  • Ecosystem Integration: For those in the Apple ecosystem, features like AirDrop make it seamless to send files from your iPhone or main laptop to the bot for processing.

  • Controlled Environment: You have complete control over the local environment, including which accounts are logged in and which applications are installed.

This is an excellent option for users who prefer a physical, observable setup and are comfortable with the higher upfront investment.

3.2. Option 2: The Virtual Private Server (VPS) Path

A VPS is essentially "renting a computer in the cloud." You connect to it remotely and manage it through a command line.

  • The Argument For a VPS: Its main advantages are low initial cost and security through isolation. Because the bot runs in a separate, contained environment, your personal files on your main computer are not at risk. This makes it a cheap way to begin experimenting.

  • The Argument Against a VPS: The setup is technically complex and far less intuitive for non-experts. As the real-world security incidents showed, it is dangerously easy to misconfigure a VPS and leave your bot and all its API keys and data completely exposed to the internet.

3.3. A Note on High-Performance Setups

There is also a "pro path" for serious experts and tinkerers: using a high-end computer like a Mac Studio with maximized memory. The primary motivation for this advanced and expensive setup is to run powerful local AI models. This provides two key advantages:

  1. Enhanced Privacy: All data processing happens on your own machine, not a third-party service.

  2. Cost Savings: It eliminates the high, recurring API costs associated with using cloud-based models.

4. Conclusion: Which Path is Right for You?

Clawdbot / Moltbot is a fascinating glimpse into the future of autonomous AI agents, but it is very much an early-stage, experimental tool. Before you begin, ask yourself the following questions:

  • What is my budget? Am I more comfortable with a larger upfront cost (Mac Mini) or a small, recurring monthly fee (VPS)?

  • What is my technical comfort level? Am I familiar with using the command line and configuring servers, or do I need a more straightforward, visual interface?

  • How important is it for me to see and interact with the AI's desktop? Do I value the ability to visually monitor the bot's actions, or am I comfortable with a remote, command-line-only setup?

  • Am I willing to accept the security risks of an experimental "hobby project"? Do I understand that this is not a finished product and that mistakes can have real consequences?

Ultimately, the best advice is to follow the creator's own warning: this is a tool for technical users who understand the risks and enjoy tinkering. Start slow, prioritize security above all else, and never give the bot access to critical personal, financial, or primary work accounts.

By proceeding with caution and an experimental mindset, you can safely explore the powerful potential of this cutting-edge technology.

How did you like this edition?

Your feedback helps us to improve.

Login or Subscribe to participate

Reply

Avatar

or to participate

Keep Reading

No posts found