
The growth curve here maps almost perfectly to OpenClaw's security implosion timeline. OpenClaw hit 346K stars but then came CVE-2026-25253 (CVSS 8.8), CVE-2026-32922 (CVSS 9.9), 800+ malicious skills in ClawHub covering 20% of the registry, and Microsoft telling enterprises to avoid it entirely. Hermes went from under 5,000 stars in March to 100K by mid-April, and the inflection point aligns with the week Meta and Microsoft issued their internal bans. The $6-8/month self-hosted stack with zero telemetry isn't just a feature, it's the exact opposite of everything that went wrong with OpenClaw's architecture. Developers aren't just adopting Hermes. They're fleeing to it.
Post summary
The post announces two high‑severity CVEs in OpenClaw, noting Microsoft’s recommendation for enterprises to avoid the product, and contextualizes the impact on community adoption.









