HomeSecurityOpenClaw AI Agent: Critical vulnerabilities allow prompt injection

OpenClaw AI Agent: Critical vulnerabilities allow prompt injection

OpenClaw , a popular autonomous AI agent, suffers from serious security vulnerabilities that could allow malicious users to perform prompt injection attacks and steal sensitive data. The Chinese CNCERT group has issued an official warning about the risks associated with the platform, which has “inherently weak default security settings.”

See also: OpenClaw: How an open source AI agent can be hijacked

OpenClaw prompt injection

OpenClaw , previously known as Clawdbot and Moltbot , is an open source platform that allows users to create autonomous AI agents to perform complex tasks. However, the privileged access it requires to the system to perform tasks autonomously creates significant vulnerabilities that can be exploited by attackers.

The risks include prompt injection, where malicious instructions embedded in web pages can lead the AI ​​agent to leak sensitive information if it is tricked into accessing and consuming the content. This type of attack is also known as indirect prompt injection (IDPI) or cross-domain prompt injection (XPIA).

According to The Hacker News , adversaries can weaponize seemingly innocent AI functions like web summarization or content analysis to execute manipulated instructions. This can lead to bypassing AI- based ad control systems , influencing hiring decisions, poisoning SEO , and creating biased responses by suppressing negative reviews.

See also: Six security vulnerabilities identified in the OpenClaw system

OpenClaw AI Agent: Critical vulnerabilities allow prompt injection

Critical vulnerabilities and recent OpenClaw incidents

The risks associated with prompt injection in OpenClaw are not theoretical. Researchers at PromptArmor discovered that the link preview feature in messaging apps like Telegram or Discord can be exploited as a data extraction route when communicating with OpenClaw via indirect prompt injection.

In January 2026, the platform experienced a series of serious security incidents. From January 27 to 29, attackers uploaded 335-341malicious skills to the ClawHub marketplace, representing 12-20% of the total number of 2,857 skills. These malicious tools were disguised as legitimate programs such as “solana-wallet-tracker”, deploying keyloggers on Windows and Atomic Stealer on macOS.

On January 31, 2026, Censys reported over 21,000 publicly exposed instances of OpenClaw. On the same day, a Moltbook exposed 35,000 email addresses and 1.5 million API tokens from a platform with over 770,000 active agents.

See also: Malicious npm package impersonates OpenClaw and deploys RAT

OpenClaw AI Agent: Critical vulnerabilities allow prompt injection

Protection recommendations and risk mitigation

To mitigate these risks, users and organizations are advised to strengthen network controls, prevent the exposure of the default OpenClaw to the internet, and isolate the service in a container. They should also avoid storing credentials in plain text, download skills only from trusted channels, and keep the agent up to date.

CNCERT warned that for critical sectors such as finance and energy, such breaches could lead to the leakage of key business data, trade secrets and code repositories, or even the complete paralysis of entire business systems, causing significant losses .

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr
Being your self, in a world that constantly tries to change you, is your greatest achievement

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS