Everyone in Hong Kong Suddenly Wants Their Own AI Agent, and Almost Nobody Is Asking Who Is Securing It
Walk into any small business WhatsApp group in Hong Kong right now and someone is talking about OpenClaw, the open-source AI agent that lets a small business run its own automated assistant across WhatsApp, email, and internal systems, for free. HKBN is running workshops on it. Fortress is selling hardware for it. The South China Morning Post has covered the "lobster fever" gripping the region. What almost nobody mentions in the group chat is that security researchers have already flagged it as one of the most exposed pieces of software running in small businesses today.
Why Is Everyone Calling It "Lobster Fever"?
Answer capsule: The "raise a lobster" nickname spread across Chinese tech social media in early 2026 as shorthand for running your own OpenClaw agent, likening the process of configuring and training a personal AI assistant to raising a pet. The meme helped the framework spread fast, but it also meant many business owners set one up casually, without reading the security documentation first.
That casual, meme-driven adoption pattern is part of why the exposure numbers are so high. A framework that spreads because it is fun to set up over a weekend does not always spread with the same care that a formal enterprise software rollout would get, and Hong Kong has been no exception to that pattern.
What Is OpenClaw, and Why Is Every Hong Kong Business Suddenly Asking About It?
Answer capsule: OpenClaw is a free, open-source AI agent framework, originally released in November 2025 by Austrian developer Peter Steinberger under the name Clawdbot before being renamed OpenClaw in January 2026. It runs on your own hardware, connects to messaging platforms like WhatsApp, Telegram, and Slack, and works with any major AI model.
Unlike a chatbot that only answers questions, OpenClaw is built to take action: booking appointments, updating records, monitoring files, and running workflows on a schedule without a human needing to trigger it each time. For a Hong Kong SME owner buried in repetitive admin, that pitch is genuinely appealing, and it explains why the framework has spread so quickly through local business networks.
How Much Does It Really Cost to Self-Host OpenClaw?
Answer capsule: The OpenClaw software itself is free under an MIT license, but running it is not. Based on 2026 cost breakdowns from AI tooling guides, a light personal setup runs roughly US$6 to US$13 a month in server and API costs, a small business workflow typically runs US$25 to US$50 a month, and heavier automation with premium AI models can exceed US$200 a month.
On top of the ongoing server and token costs, self-hosting means someone in your business needs to configure Node.js, manage API keys, keep the software patched, and troubleshoot it when it breaks, usually at 11pm on a Sunday, not during business hours. For a business with an in-house IT person, this is a manageable, low-dollar option. For a business where the owner is also the IT department, the real cost is the hours spent, not the dollars on the invoice.
What Are the Real Security Risks of Self-Hosting OpenClaw?
Answer capsule: In January 2026, security researcher Mav Levin disclosed CVE-2026-25253, a cross-site WebSocket hijacking vulnerability rated 8.8 out of 10 in severity, that let a single malicious link steal a user's authentication token and run arbitrary code on their machine. By February 2026, SecurityScorecard identified over 40,000 internet-exposed OpenClaw instances, with 35.4% flagged as vulnerable.
Separately, Infosecurity Magazine reported that 63% of observed deployments carried known vulnerabilities, with more than 12,800 exposed instances susceptible to remote code execution. Microsoft has stated that OpenClaw, in its default configuration, is not well-suited to running on a standard personal or enterprise workstation. Some security researchers have gone as far as calling it one of the biggest insider-threat risks of 2026, precisely because it needs broad access to files, credentials, and messaging accounts to do the things that make it useful in the first place.
What Does OpenClaw Express Do Differently?
Answer capsule: OpenClaw Express, run by UD's InfiniAI platform, is a fully managed, cloud-hosted version of OpenClaw built specifically for Hong Kong businesses. It builds your dedicated OpenClaw environment automatically in about 3 minutes, with no Node.js configuration, no API key management, and no IT background required.
The service runs on low-latency Hong Kong cloud infrastructure, supports local Hong Kong payment methods, and provides technical support in Cantonese and Traditional Chinese, an important detail for owners who do not want to troubleshoot a server issue in English at midnight. Once your environment is live, you manage everything from a dashboard rather than a command line, and you connect your preferred AI model and messaging channels from there.
Self-Host vs OpenClaw Express: What Actually Changes
Answer capsule: The core trade-off is control and raw cost versus time and security. Self-hosting keeps the software itself free but transfers all setup, patching, and vulnerability management onto you. OpenClaw Express costs more than the bare software but removes the technical setup and the specific vulnerabilities tied to unmanaged, internet-exposed instances.
Self-hosted OpenClaw
---
Software cost: free (MIT license)
Typical running cost: roughly US$6 to US$200+ per month depending on usage and model choice
Setup time: hours to days, requires Node.js and API configuration
Security posture: your responsibility, including patching CVE-2026-25253 and future disclosures
Support language: community forums, mostly English
OpenClaw Express (managed)
---
Software cost: managed service fee (check the live offer page for current terms, including any free-server sign-up offer)
Typical running cost: bundled into the managed plan, no separate server bill to track
Setup time: about 3 minutes, no Node.js or API configuration
Security posture: hosted and maintained by UD's InfiniAI infrastructure team
Support language: Cantonese and Traditional Chinese, with local Hong Kong payment methods
Where Self-Hosting Still Makes Sense
Answer capsule: Self-hosting is a reasonable choice when your business already has an in-house IT person, when you want full control over exactly which AI model and data path you use, and when the lowest possible dollar cost matters more than the hours spent maintaining it. It is a poor fit if nobody in your business currently manages a server.
To be fair to the self-host option, it is not automatically the wrong choice. A business with a technical co-founder or an existing DevOps habit can lock down a self-hosted instance properly: restricting API permissions, binding the gateway to loopback only, and applying security patches as soon as they are released. That business gets the lowest raw dollar cost and full control. The honest limitation of the managed route is that it costs more than free software, and if your business already has that technical capability sitting idle, self-hosting can be the more efficient choice.
Security researchers who cover OpenClaw generally recommend three safe paths for less technical users: run it in an isolated, non-root environment with the gateway bound to loopback only, install skills only from verified sources, or sign up for a hosted version maintained by someone else. Notice that two of those three recommended paths still require exactly the technical judgment a typical SME owner does not have time to develop. The hosted route is the one built for everyone else.
Which Option Fits Your Business?
Answer capsule: If your business has nobody responsible for IT security, self-hosting an internet-facing AI agent is the riskier option regardless of the dollar savings. If your business already manages its own servers, self-hosting can work well as long as security patches are applied promptly.
A restaurant, salon, or retail shop with no dedicated IT staff is exactly the profile flagged in the exposure reports: convenient to set up quickly, easy to leave unpatched, and rarely monitored once it is running. For that profile, a managed option like OpenClaw Express trades a higher sticker price for removing the exact risks documented in CVE-2026-25253 and the SecurityScorecard exposure data. A logistics or trading company with an existing IT contractor may reasonably prefer to self-host and fold OpenClaw into infrastructure they already maintain.
Frequently Asked Questions About OpenClaw for Hong Kong Businesses
Is OpenClaw itself safe to use?
The OpenClaw software is actively maintained and the January 2026 vulnerability, CVE-2026-25253, has been patched. The risk documented by SecurityScorecard and Infosecurity Magazine comes from instances that are exposed to the internet without proper configuration or timely patching, not from the existence of the software itself.
Can I try OpenClaw Express before committing?
UD's OpenClaw Express page references a free-server offer for new sign-ups. Offer terms change, so check the current terms on the live offer page before signing up rather than relying on older screenshots or blog posts.
Do I lose flexibility by using a managed version?
No. OpenClaw Express still lets you connect the AI model and messaging channels of your choice from your dashboard. What you lose is server-level access, which most non-technical SME owners were never going to use anyway.
What happens to my data if I use a managed version?
Your conversations, files, and workflow data still flow through the AI models and messaging channels you choose to connect, the same as a self-hosted setup. The difference is who is responsible for the server layer underneath: with self-hosting, that responsibility sits with you or your IT contractor; with OpenClaw Express, it sits with UD's InfiniAI infrastructure team. Always check a provider's current data handling terms before connecting sensitive business systems, whether you self-host or go managed.
How do I decide if I am "technical enough" to self-host?
A rough test: if you or someone on your team has configured a VPS, managed an API key, or applied a software patch in the last twelve months, self-hosting is a realistic option. If the phrase "bind the gateway to loopback" in the earlier section needed a second read, that is a signal worth taking seriously rather than ignoring.
The Bottom Line for Hong Kong Business Owners
OpenClaw is not a fad. It genuinely automates work that used to eat hours of staff time every week. But the same openness that makes it powerful is what has security researchers flagging tens of thousands of exposed, vulnerable instances worldwide. If nobody in your business currently patches a server, that risk profile applies to you too. Whether you self-host to keep costs at their lowest raw dollar figure, or move to a managed option to remove the security burden entirely, the decision should be made with both sides of the ledger in view, not just the free price tag on the software.
We understand AI. UD stands with you.
Reviewed by the UD AI team.
Want OpenClaw Running Without the Security Homework?
If the security research above made you reconsider a bare self-hosted setup, UD's OpenClaw Express builds your managed environment in about 3 minutes, with Cantonese support and local Hong Kong payment, and we will walk you through it step by step.