The open-source agent framework OpenClaw just shipped version 2026.6.8, and it's tightening the screws on a data security hole. Previously, if an agent's configuration was missing API keys for search providers like Parallel Free or DuckDuckGo, the system would silently fall back to those keyless sources — sending context out into the wild without any warning. Now that automatic backdoor is disabled by default; you have to manually enable any keyless search source.
This change plugs a quiet data leak path where sensitive information could be whisked away to public search services without the user ever knowing.
On the messaging front, OpenClaw's Telegram channel finally gets proper structured formatting. Tables, lists, collapsible quote blocks, line breaks, and even command replies now render correctly — putting an end to the crashes that complex layouts used to trigger.