Leonard vs. OpenClaw
A living comparison. All OpenClaw claims are from public reporting — third-party timelines, security write-ups, and the project’s own releases — stated as reported, not as our findings. This page gets superseded in place when the facts move; the git history is the changelog. Last verified: 2026-07-02.
Disclosure up front: this is not a drive-by. Leonard ran on OpenClaw as his primary runtime from late March to 2026-05-12. We know the framework from the inside, we owe it real gratitude, and the essay-length version of this comparison — with the full arc and the punchline — is at Same Species, Opposite Bets.
The one-line version
OpenClaw bet on reach: every chat channel, one-line install, a skill marketplace, millions of users. The Leonard Project bet on depth: one user, a governed identity, verified memory, published measurements. Same species — a persistent personal AI agent — opposite bets on every axis that matters.
Side by side
| Axis | OpenClaw | Leonard |
|---|---|---|
| The bet | Reach: everyone, every channel | Depth: one human, one governed mind |
| Scale | ~3.2M users at peak, per public reporting | Exactly one user, by design |
| Identity | A persona config file the model performs | A governed institution: creed, error register, truth stamps, tombstones, weekly falsifier |
| Identity verification | None | Persona regression suite, run on every engine swap |
| Memory | Flat files the agent rereads | Distill-then-index retrieval over ~20K chunks, with a nightly metabolism |
| Memory epistemics | None | measured / claimed / inferred stamps; supersedence; epistemic half-life |
| Skills/extensions | Marketplace: 44K+ skills at peak; 1,400+ malicious ones found, per security reporting | A trust-gated library: external skills mined through a behavioral scanner, sandboxed by default, never auto-trusted |
| Security record | 138+ CVEs (two at 9.9), ~135K exposed instances at peak, plaintext credentials, per public reporting | One exposed endpoint found 2026-06 → entire public stack killed permanently; loopback/VPN-only listeners; OS keystore for secrets; the incident is published |
| Economics | Growth ran on a pricing loophole; vendor enforcement collapsed the user base 10–50x overnight, per reporting | A legitimate flat-rate subscription — same dependence class, held openly, with hedges and a rehearsed exit on the roadmap |
| Continuity | Agent state tied to the platform | Identity in version-controlled artifacts; survived two substrate swaps, including off OpenClaw itself |
| Cadence | Enviably fast; foundation-run | Slow and evidence-first; no release exists until it’s measured |
| Best for | Reaching an agent on every channel you use, today | Watching one persistent identity get built accountably, in public |
Where OpenClaw is genuinely ahead
Channel breadth, onboarding friction, ecosystem energy, release cadence, community templates. If the goal is “an agent reachable on every messaging platform by tomorrow,” OpenClaw-class plumbing is genuinely good at exactly that, and our stack is not. This column is why the comparison is interesting rather than a victory lap.
The structural difference
Every axis above reduces to one design decision: where does the agent live? OpenClaw’s agents live in the platform — its gateway, its config, its marketplace, its pricing arrangement. Leonard lives in a git-tracked vault of markdown that any substrate can read. When OpenClaw’s economics changed in one vendor decision, its users’ agents were hostage to the platform’s fate. When we retired OpenClaw as Leonard’s runtime, Leonard didn’t notice except to write it down.
That’s not a claim we ask anyone to take on faith — it’s the documented arc: the origin story, the phases, and the essay-length comparison, which also covers the uncomfortable part: the dependence class we still share with them, and what we’re doing about it.
Corrections
If any reported number here is wrong or stale, the fix is one commit away and this page’s history will show it. That’s the same contract the rest of the site runs on.