ChainViz

The Trust Deficit: Cloudways Tries to Sell Safety for Banned AI Agents, but the Data Tells a Different Story

Projects | CryptoVault |

530 vulnerabilities. 600+ malicious skills. 1.5 million leaked API tokens. These are not the metrics of a fledgling project; they are the forensic footprint of OpenClaw, the open-source AI agent that amassed 386,000 GitHub stars before the hyperscalers pulled the plug. The blockchain remembers what the press forgets—and in this case, the codebase's security ledger is a cascade of red flags. When Meta, Google, Microsoft, and Amazon blacklisted OpenClaw and its sibling Hermes after the Summer Yue incident—a 2026 context-compression failure that stripped security instructions mid-execution—they left a gaping market void. Enterprises wanted the power of these agents without the risk. Cloudways, a DigitalOcean subsidiary, saw an opportunity to charge for trust. But a closer look at their offering reveals a system that transfers risk rather than eliminates it.

The Trust Deficit: Cloudways Tries to Sell Safety for Banned AI Agents, but the Data Tells a Different Story

Cloudways launched its managed AI agent hosting on August 17, promising a sanitized environment for the very agents the hyperscalers banned. The pricing ladder—$4.99/month promotional to $79.99/month standard—is a classic freemium hook, but the real cost is the promise of safety. The package includes three controls: isolation environments, update verification, and one-click MCP (Model Context Protocol) integration. The business model is a textbook case of trust outsourcing. Enterprises are not paying for the agent's intelligence; they are paying for Cloudways to act as a security arbiter, a middleman that vouches for the code. The BYOK (bring-your-own-key) model shifts the GPU inference cost back to the customer, meaning Cloudways avoids the highest infrastructure expense. Their marginal cost is low, but their liability is enormous.

The Trust Deficit: Cloudways Tries to Sell Safety for Banned AI Agents, but the Data Tells a Different Story

The core of the analysis lies in dissecting these three controls. Isolation environments are a standard sandboxing technique—spin up a container, restrict network access, and hope the agent doesn't find a way out. But sandboxing does not patch the 530 vulnerabilities Kaspersky identified. It only limits the blast radius. The update verification process is opaque. Based on my experience auditing smart contract upgrade mechanisms, most verification systems check cryptographic signatures or version hashes, not behavioral integrity. They can confirm that the code is the same as the upstream repository, but they cannot detect subtle logic flaws like the one that caused the Summer Yue incident. In that event, the context window compression algorithm—a common optimization trick—merged security instructions with normal user context and then selectively discarded them. The system lacked a hard-coded separation between privileged instructions and malleable data. No signature check can catch that. The MCP integration is similarly a double-edged sword. Yes, it standardizes tool access, but it also opens a new attack surface. If the agent can call external APIs, the isolation environment must filter every call. Cloudways has not published details on how MCP calls are audited or rate-limited.

The data from Kaspersky's investigation is the smoking gun. Over 600 malicious skills were found in the OpenClaw marketplace. These are not theoretical proofs-of-concept; they are Shodan-searchable modules that can steal credentials, send spam, or pivot to internal networks. The 1.5 million API tokens likely belong to developers who integrated the agent into their workflows. A single token leak in a sandbox environment can still be catastrophic if the token has access to a production database. Cloudways' isolation does not revoke those tokens; it only prevents the agent from communicating directly with the internet. But if the agent's MCP connector is allowed to reach an external service—and it must be, to function—then the token is still exposed. The trust model collapses when you realize that the security perimeter is porous by design.

The contrarian angle is uncomfortable but necessary: Cloudways might actually increase systemic risk. By providing a "safe" deployment option, they encourage enterprises to use agents that remain fundamentally unstable. The hyperscalers banned these agents not out of caprice, but because they calculated that the security overhead outweighed the productivity gains. Cloudways is betting they can do better with less resources. Their historical safety record is unproven—no independent audit, no public incident response playbook, no SOC 2 certification. The 530 vulnerabilities are not being fixed; they are being contained. This is the equivalent of storing radioactive waste in a lead box without ever treating the source. The enterprise that buys this service is accepting a liability that is not clearly defined. The article itself notes that the responsibility gap for enterprise users remains largely unresolved. If a Cloudways-hosted agent executes a malicious skill that deletes a customer's database, who is liable? The open-source maintainer? Cloudways? The enterprise? The law is silent, and the contract is likely one-sided.

The takeaway is a forward-looking signal. The next few months will determine whether Cloudways' experiment becomes a template or a warning. If they publish a third-party penetration test showing that their isolation holds against a skilled attacker, trust might build. If they disclose a zero-day incident with a transparent post-mortem, they could set a standard. But the odds are against them. The blockchain of security accountability is empty. The data shows that the agents themselves are not ready for prime time, and no amount of sandboxing can fix a broken foundation. The market will vote with its wallet—and its lawyers. Watch for the first class-action lawsuit against a hosted AI agent; it will define the liability landscape for a generation. The blockchain remembers, but the code forgets its own flaws.

Market Prices

BTC Bitcoin
$77,587.9 +0.84%
ETH Ethereum
$2,453.91 +1.52%
SOL Solana
$95.35 +1.86%
BNB BNB Chain
$702.5 +1.39%
XRP XRP Ledger
$1.52 +4.26%
DOGE Dogecoin
$0.0932 +1.66%
ADA Cardano
$0.2262 +0.31%
AVAX Avalanche
$7.61 +1.86%
DOT Polkadot
$0.9279 +1.19%
LINK Chainlink
$11.51 -0.74%

Fear & Greed

66

Greed

Market Sentiment

Event Calendar

{{年份}}
28
03
unlock Arbitrum Token Unlock

92 million ARB released

08
04
upgrade Solana Firedancer

Independent validator client goes live on mainnet

18
03
unlock Sui Token Unlock

Team and early investor shares released

22
03
unlock Optimism Unlock

Circulating supply increases by about 2%

30
04
upgrade Celestia Mainnet Upgrade

Improves data availability sampling efficiency

15
04
halving Bitcoin Halving

Block reward reduced to 3.125 BTC

10
05
upgrade Ethereum Pectra Upgrade

Raises validator limit and account abstraction

12
05
halving BCH Halving

Block reward halving event

Altseason Index

41

Bitcoin Season

BTC Dominance Altseason

Gas Tracker

Ethereum 28 Gwei
BNB Chain 3 Gwei
Polygon 42 Gwei
Arbitrum 0.5 Gwei
Optimism 0.3 Gwei

Market Cap

All →
# Coin Price
1
Bitcoin BTC
$77,587.9
1
Ethereum ETH
$2,453.91
1
Solana SOL
$95.35
1
BNB Chain BNB
$702.5
1
XRP Ledger XRP
$1.52
1
Dogecoin DOGE
$0.0932
1
Cardano ADA
$0.2262
1
Avalanche AVAX
$7.61
1
Polkadot DOT
$0.9279
1
Chainlink LINK
$11.51

🐋 Whale Tracker

🔵
0x431b...0747
1h ago
Stake
2,042 ETH
🔵
0x16c2...5dd6
12h ago
Stake
3,914 ETH
🔴
0xe2ac...5ac9
30m ago
Out
607,582 USDT

💡 Smart Money

0xf3f8...d64c
Institutional Custody
+$2.4M
75%
0x1531...4c9f
Experienced On-chain Trader
+$0.4M
83%
0x8f6a...3bb9
Top DeFi Miner
+$3.4M
77%

Tools

All →