OpenClaw , a popular autonomous AI agent, suffers from serious security vulnerabilities that could allow malicious users to perform prompt injection attacks and steal sensitive data. The Chinese CNCERT group has issued an official warning about the risks associated with the platform, which has “inherently weak default security settings.”
See also: OpenClaw: How an open source AI agent can be hijacked

OpenClaw , previously known as Clawdbot and Moltbot , is an open source platform that allows users to create autonomous AI agents to perform complex tasks. However, the privileged access it requires to the system to perform tasks autonomously creates significant vulnerabilities that can be exploited by attackers.
The risks include prompt injection, where malicious instructions embedded in web pages can lead the AI agent to leak sensitive information if it is tricked into accessing and consuming the content. This type of attack is also known as indirect prompt injection (IDPI) or cross-domain prompt injection (XPIA).
According to The Hacker News , adversaries can weaponize seemingly innocent AI functions like web summarization or content analysis to execute manipulated instructions. This can lead to bypassing AI- based ad control systems , influencing hiring decisions, poisoning SEO , and creating biased responses by suppressing negative reviews.
See also: Six security vulnerabilities identified in the OpenClaw system

Critical vulnerabilities and recent OpenClaw incidents
The risks associated with prompt injection in OpenClaw are not theoretical. Researchers at PromptArmor discovered that the link preview feature in messaging apps like Telegram or Discord can be exploited as a data extraction route when communicating with OpenClaw via indirect prompt injection.
In January 2026, the platform experienced a series of serious security incidents. From January 27 to 29, attackers uploaded 335-341malicious skills to the ClawHub marketplace, representing 12-20% of the total number of 2,857 skills. These malicious tools were disguised as legitimate programs such as “solana-wallet-tracker”, deploying keyloggers on Windows and Atomic Stealer on macOS.
On January 31, 2026, Censys reported over 21,000 publicly exposed instances of OpenClaw. On the same day, a Moltbook exposed 35,000 email addresses and 1.5 million API tokens from a platform with over 770,000 active agents.
See also: Malicious npm package impersonates OpenClaw and deploys RAT

Protection recommendations and risk mitigation
To mitigate these risks, users and organizations are advised to strengthen network controls, prevent the exposure of the default OpenClaw to the internet, and isolate the service in a container. They should also avoid storing credentials in plain text, download skills only from trusted channels, and keep the agent up to date.
CNCERT warned that for critical sectors such as finance and energy, such breaches could lead to the leakage of key business data, trade secrets and code repositories, or even the complete paralysis of entire business systems, causing significant losses .
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
