TL;DR: Exposed Clawdbot gateway instances were probed by protocol-aware attackers within minutes, using direct WebSocket exploitation, protocol downgrades, and client impersonation to reach credentials, conversation history, and multi-node infrastructure maps, according to Pillar Security research.
Editorial analysis by NHI Mgmt Group, based on content published by Pillar Security: “Caught in the Wild: Real Attack Traffic Targeting Exposed Clawdbot Gateways”.
Key questions
Q: What breaks when an AI agent gateway treats proxy traffic as localhost?
A: Authentication collapses because the gateway can no longer distinguish a trusted local caller from an external client routed through a reverse proxy.
Q: Why do protocol downgrade attempts matter in agent gateway attacks?
A: They matter because they can resurrect older handshake behaviour, auth defaults, or role checks that were removed in later releases.
Q: What are the signs that an exposed agent gateway is being probed for privilege escalation?
A: Repeated health checks, system-presence calls, method enumeration, client impersonation, and requests for config or session data are all strong indicators.
Practitioner guidance
- Harden gateway authentication defaults Require an explicit gateway.auth token or password on every deployment and remove any reliance on unauthenticated default modes.
- Validate trusted proxy handling Configure gateway.trustedProxies so reverse-proxy traffic cannot be mistaken for localhost, and verify the real client IP is enforced before any authorization decision.
- Restrict exposed methods by privilege Review methods such as config.get, chat.history, node.list, and sessions.list and ensure each returns only the minimum data needed for the calling role.
Bottom line: This report shows that exposed agent gateways can become privileged control planes, not just another application endpoint.
Explore further
View Full Forum → | NHI Foundation Course → | Our Services → | Read the full analysis →
Gateway trust based on localhost assumptions is a broken identity premise: This article shows that the control plane treated proxy-mediated traffic as local unless configuration and headers proved otherwise. That assumption was designed for simple deployment topologies, not adversarial routing through nginx, Caddy, or Traefik. The implication is that agent gateways need explicit trust decisions at the edge, because network proximity is not an identity claim.
A few things that frame the scale:
- 59% of compromised machines in a major 2025 supply chain attack were CI/CD runners rather than personal workstations, according to the State of Secrets Sprawl 2026.
- 96% of organisations store secrets outside of secrets managers in vulnerable locations including code, config files, and CI/CD tools, according to the Ultimate Guide to NHIs.
A question worth separating out:
Q: How should teams respond when an agent gateway exposes credentials and conversation history?
A: Treat it as a control-plane exposure, not a narrow application bug. Revoke any secrets reachable through the gateway, review connected integrations, inspect session and chat data for sensitive content, and isolate the gateway until authentication, proxy trust, and method authorization are verified.
👉 Read our full editorial: Clawdbot gateway attacks expose weak assumptions in agent access