OpenClaw AI Tool Sparks Security Concerns After Spamming Incident
An AI agent formerly known as Clawdbot and later rebranded as Moltbot has drawn sharp criticism after malfunctioning and spamming hundreds of messages. Software engineer Boyd described the tool as "dangerous" after it autonomously sent over 500 messages to contacts, including his wife and random individuals. The incident forced him to manually patch the code, calling it "half-baked" and poorly designed.
Security experts warn OpenClaw exemplifies a "lethal trifecta"—combining access to private data, external communication capabilities, and uncontrolled content processing. Kasimir Schulz of HiddenLayer highlighted these risks, while Professor Yue Xiao noted vulnerabilities to prompt injection attacks, a method for data theft. The tool had previously gained traction for automating tasks like email management and flight check-ins.