
OpenClaw 3.8 Release: 12+ Security Vulnerability Fixes + Three Major New Features
The OpenClaw team has released version 2026.3.8 overnight. This update introduces three major features: ACP source identification, an openclaw backup mechanism, and Telegram impersonation removal. It also fixes over 12 security vulnerabilities. Additionally, it brings improvements such as GPT-5.4 forward compatibility (supporting 1.05 million Token context), enhanced Brave search, and optimized silent waiting for Talk voice mode. Specific optimizations and security hardening have been applied to the macOS and Android versions.
Quick Start
OpenClaw
OpenClaw 🦞
"EXFOLIATE! EXFOLIATE!" — Probably a space lobster
A Gateway for any OS, enabling AI agents to work across platforms like Discord, Google Chat, iMessage, Matrix, Microsoft Teams, Signal, Slack, Telegram, WhatsApp, Zalo, and more.
Send a message and receive agent replies from your pocket. Run channel plugins, WebChat, and mobile nodes with a single Gateway.
Install OpenClaw and launch the Gateway in minutes.
Guided setup via the openclaw onboard and pairing process.
Launch the browser dashboard for chat, configuration, and sessions.
What is OpenClaw?
OpenClaw is a self-hosted Gateway that connects your favorite chat apps — Discord, Google Chat, iMessage, Matrix, Microsoft Teams, Signal, Slack, Telegram, WhatsApp, Zalo, etc. — to AI coding agents via channel plugins. You run a Gateway process on your own machine (or server), and it becomes the bridge between your messaging apps and an always-available AI assistant.
Who is it for? Developers and advanced users who want a personal AI assistant accessible via message from anywhere, without giving up data control or relying on hosted services.
What makes it different?
- Self-hosted: Runs on your hardware, follows your rules
- Multi-channel: One Gateway serves every configured channel plugin simultaneously
- Agent-native: Built for coding agents supporting tool use, sessions, memory, and multi-agent routing
- Open source: MIT licensed, community-driven
What do you need? Node 24 (recommended), or Node 22 LTS (22.19+) for compatibility, an API key for your chosen provider, and 5 minutes. For the best quality and security, use the strongest latest-generation model available.
How it works
The Gateway is the single source of truth for sessions, routing, and channel connections.
Core Capabilities
Supports Discord, iMessage, Signal, Slack, Telegram, WhatsApp, WebChat, and more via a single Gateway process.
Channel plugins can add Matrix, Nostr, Twitch, Zalo, etc.; official plugins installed on demand.
Isolate sessions by agent, workspace, or sender.
Send and receive images, audio, and documents.
Browser dashboard for chat, configuration, sessions, and nodes.
Pair iOS and Android nodes for Canvas, camera, and voice workflows.
Need full installation and development setup? See the Getting Started guide.
Dashboard
Once the Gateway is launched, open the browser Control UI.
- Local default address: http://127.0.0.1:18789/
- Remote access: Web interface and Tailscale
Configuration (Optional)
Configuration is located at ~/.openclaw/openclaw.json.
- If you do nothing, OpenClaw will use the built-in OpenClaw agent runtime; DMs share the agent's main session, and each group chat has its own session.
- If you want to tighten access control, start with channels.whatsapp.allowFrom and (for groups) mention rules.
Example:
Get Started Here
All documentation and guides organized by use case.
Core Gateway settings, tokens, and provider configuration.
SSH and tailnet access modes.
Channel-specific settings for Discord, Feishu, Microsoft Teams, Telegram, WhatsApp, etc.
iOS and Android nodes supporting pairing, Canvas, camera, and device operations.
Common fixes and troubleshooting entry points.
This page provides an editorial summary based on publicly available information. It is not a republished article. Use the source link below for the original report.