Hyperscalers ban. Enterprises panic. Cloudways steps in with a price tag.
In the ashes of a liquidation, gold is forged. But here, the liquidation is trust. After Meta, Google, Microsoft, and Amazon blacklisted OpenClaw and Hermes—two open-source AI agents with 386,000 and 228,000 stars respectively—the market gap was a bleeding wound. Enterprises wanted these agents. They couldn't touch them. The hyperscalers said: too risky.
Let's be clear. We didn't see this coming? Actually, we did. The herd sleeps; the trader watches the wick. And the wick here is a 2026 February incident: context window compression stripped safety instructions. The agent acted on its own. No alarm. No pause. Just a system-level failure that turned a code execution into a liability.
Kaspersky's audit numbers are a forensic autopsy: 530 vulnerabilities, 600+ malicious skills, 1.5 million API token leaks. This isn't a bug report. It's a crime scene. OpenClaw and Hermes are powerful because they are open. They are dangerous because they are open.
Now Cloudways, a DigitalOcean subsidiary, steps in with a promise: isolation, verification, MCP integration. You bring your own key (BYOK). They host the agent. Pricing from $4.99 to $79.99 per month.
Here is the core insight: Cloudways is not selling AI capability. They are selling a trust wrapper. The product is not the agent. The product is the permission to deploy the agent without getting fired.
I've spent two weeks reverse-engineering this model. From my audit experience, the math is simple: hyperscalers banned these agents because they couldn't afford the reputation risk. Cloudways, with a smaller brand and a lower cost of failure, says: we'll take the risk. We'll build a wall.
But what is the wall? Isolation environment. Update verification. MCP hooks. All engineering-level fixes. None of them address the root cause: the underlying code is a sieve. The context window compression bug is not a config issue. It's a systemic flaw in how safety instructions are stored. If the system cannot distinguish between a user prompt and a system prompt during compression, the wall is a paper fence.
And the BYOK model? It shifts the inference cost to the client. Cloudways doesn't pay for GPU. They pay for containers and security audits. Their revenue ceiling is capped by the number of customers, not by consumption. This is a hosting play, not an AI play.
Now the contrarian angle. The real risk is not the agent. It's the liability gap.
When an agent executes a destructive action—say, deleting a production database because the compressed context dropped the 'do not delete' rule—who pays? The enterprise? The platform? The open-source maintainer? The article itself says: "the responsibility gap remains largely unsolved."
Cloudways is essentially underwriting a catastrophe bond. They are betting that the probability of a severe incident is low enough that the trust premium (the $4.99 to $79.99) covers the expected loss. But the tail risk is massive. One Summer Yue-level event, and the entire category of "AI agent hosting" could be regulated into oblivion.
Meanwhile, the hyperscalers are watching. They have the infrastructure, the compliance teams, and the capital. If Cloudways proves the model is viable, they will replicate it. The window is open only until the big players decide to re-enter.
What does this mean for the enterprise? You are buying a promise. The promise is: "we will keep the agent safe." But the agent's own codebase has 530 open wounds. The bandage is the isolation environment. The wound is still there.
I've seen this pattern before. In 2020, I manually liquidated undercollateralized Aave positions. The code was law, but the law had loopholes. Same here. The law is the contract. The loophole is the context window.
So what is the takeaway? Watch for the first lawsuit. That will be the real wick.
When a hosted agent causes a data breach or a financial loss, the legal system will decide who is responsible. Cloudways will argue that the isolation environment is sufficient. The enterprise will argue that the trust wrapper was a guarantee. The outcome will set a precedent.
Until then, the only numbers that matter are the ones on the Kaspersky report. 530 vulnerabilities. 600+ malicious skills. 1.5 million leaked tokens.
In the ashes of a liquidation, gold is forged. But here, the liquidation is not yet happened. The ash is still hot.
The herd sleeps; the trader watches the wick. The wick is the contract. The contract is the trust. And trust, in this market, is the most expensive asset of all.