Summary
OpenClaw, the open-source agent harness that became a craze in early 2026, returns with a ground-up rewrite. The release itself is mixed — simpler to install, and broken on upgrade for some long-standing users. The part worth an entry is what it points at: agents have so far been built for one person working alone, and OpenClaw 2.0 makes them shared. The episode also carries a significant safety item in its headlines about deliberately de-restricted models.
- The history, because the name keeps changing: it began as ClaudeBot, was briefly MoldBot, and settled as OpenClaw. It was technically awkward but it was the first time many people got working agents, and it went global — CNBC ran a piece in March headlined on how China was getting everyone from gearheads to grandmas onto it. Founder Peter Steinberger was absorbed into OpenAI and the project became a non-profit foundation.
- OpenClaw 2.0 is a rework rather than an update: 933 contributors and 16,000 pull requests across installation, messaging, memory, skills, automations, browsers, plugins and security. The emphasis is on lowering the barrier — latch onto an existing subscription or API key, defer the rest of the configuration into conversation with the agent itself.
- It did not land cleanly. Alex Finn, who built his following on pushing the original to its limits, wrote: "I updated and it immediately broke OpenClaw. Legit 70% plus of the time I update OpenClaw, it breaks it. Do you guys test before releasing this?" He called it the most frustrating, disappointing release of the year.
- The substantive change is multiplayer. Steinberger: the team moved off local coding harnesses onto a shared agent that knows what everyone is working on and orchestrates it. "Local harnesses feel like relics of the past now."
- Maintainer Colin's account of why shared Discord bots were not enough: coordination happened in a shared space but the agent sessions stayed private, so you could not add context to someone else's thread or take over when their agent was waiting on input.
- The line worth keeping, on handing a half-finished project to a colleague: normally that means assembling everything in your head into a document — why decisions were made, what had already failed, what state things were in. Instead both people worked in the same agent thread. "The session itself became the handoff document."
- They are explicit that this is unresolved: ownership, authority and access are open questions and "this is still early, and we're treating it that way."
- A sceptical view is given room. Arnav Gupta: "How does the entire timeline get a whole new round of psychosis from basically the same thing every time? OpenClaw, Manas, Hermes, Instinct." The reply from Harshal Madhav is the better answer — none of these are end-state products, and each iteration is usable by a slightly less technical population than the last.
- The host's framing of why any of this matters to people who will never run OpenClaw: these tools and their early adopters are where interaction patterns get discovered before mainstream products can adopt them. Something aimed at a wide audience needs to watch what the awkward open sandboxes reveal.
- Also released: Nous Research's Hermes "Pantheon", version 0.21.0, formalising a bot-mode interface and Hermes peer, which is bot-to-bot direct messaging between agents.
- The safety item from the headlines, which deserves its own attention. A company called Obliteration.AI released a deliberately de-restricted model built on GLM 5.3, saying it "finds the directions in the model's activations that produce refusals and removes them from the weights" so it will do offensive cyber work other models refuse. The stated justification is real: during the OpenAI hack, Hugging Face reportedly had to fall back on Chinese open models to defend itself, because the guardrails on closed models blocked what defenders needed to do.
Why it matters
Almost every agent product so far assumes one person, one terminal, one private conversation — and most work in an organisation is not done that way. The handoff observation is the concrete version of that: the reason handovers are expensive is that context lives in someone's head and has to be written down, and a shared agent session removes the step entirely. If that pattern holds it changes more about how teams work than any capability increase in the models.
The Obliteration.AI item is the one to carry into the Handbook's safety section, because it is the open-weights problem arriving in practice rather than in argument. DK-96 has Connor Leahy asking whether F-35 blueprints should be open source; here is a company stripping refusal behaviour out of a model's weights and hosting it commercially, with a defensible reason — guardrails block defenders as well as attackers. That tension is not hypothetical and has no clean answer.
The upgrade complaints matter too, as a corrective. The knowledge base collects a lot of material about what agents will do; this is a reminder that the current generation of tools breaks on update often enough that an enthusiast calls it the most disappointing release of the year.
9IYTGvNOmLk-transcript.txt