BTC $71,807
2026 Bull Run Is Building Start trading with 5% OFF all fees
Sign Up Now
BTC $71,807
Bull Run 2026 | 5% Off Fees Open your Binance account today
Sign Up

China Warns of OpenClaw AI Security Risks

Critical OpenClaw flaws prompt data leak warnings, state bans, and malware campaigns.

  • China’s CNCERT issued a warning about critical security risks in the open-source AI agent OpenClaw, citing weak defaults and privileged access.
  • Researchers have demonstrated practical indirect prompt injection attacks, enabling data exfiltration via manipulated URL previews.
  • Chinese authorities have moved to restrict the use of OpenClaw in state enterprises and government agencies to contain security risks.
  • Threat actors are actively exploiting the platform’s popularity, distributing malware through fake GitHub repositories.

On March 14, 2026, China’s National Computer Network Emergency Response Technical Team officially warned about severe security vulnerabilities stemming from the use of the autonomous AI agent OpenClaw. The agency highlighted the platform’s inherently weak default configurations and its privileged system access. Consequently, these flaws could allow bad actors to seize control of the endpoint through various attack vectors.
The primary risk involves indirect prompt injection, where malicious instructions embedded in a web page can trick the agent into leaking sensitive data. This attack, also referred to as cross-domain prompt injection, weaponizes benign AI features like web page summarization. It can range from SEO poisoning to generating biased responses by suppressing reviews.
Last month, researchers at PromptArmor found a practical data exfiltration pathway using this method. They demonstrated that link preview features in apps like Telegram could be exploited. The AI agent could be manipulated to generate an attacker-controlled URL that automatically transmits confidential data.
CNCERT highlighted three additional critical concerns beyond rogue prompts. These include the risk of irreversible data deletion due to misinterpreted instructions and the installation of malicious skills from repositories like ClawHub. Furthermore, attackers can exploit recently disclosed security vulnerabilities in OpenClaw to compromise systems.
The agency warned that for critical sectors like finance and energy, such breaches could leak core business data or paralyze entire systems. Meanwhile, Chinese authorities have moved to restrict state-run enterprises and government agencies from running OpenClaw AI apps on office computers, according to reports. The ban also reportedly extends to families of military personnel.
Threat actors are capitalizing on the platform’s viral popularity to distribute malware. Huntress detailed a campaign using malicious GitHub repositories posing as OpenClaw installers. These repositories deployed information stealers like Atomic and a Golang-based proxy malware known as GhostSocks.

- Advertisement -

✅ Follow BITNEWSBOT on Telegram, Facebook, LinkedIn, X.com, and Google News for instant updates.

Previous Articles:

- Advertisement -
Ad
Altseason Is Loading. Don't watch from the sidelines.
SOL $90.51
DOGE $0.0963
LINK $9.02
SUI $1.00
5% off fees when you sign up
Start Trading
Ad
Pay Less on Every Trade. For Life.
$10K/mo volume Save $60/yr
$50K/mo volume Save $300/yr
$100K/mo volume Save $600/yr
5% off all trading fees when you sign up
Claim Your Discount

Latest News

KuCoin Launches KuCard Crypto Debit Card in Australia

KuCoin has launched its virtual crypto debit card, KuCard, in Australia, allowing users to...

Figure Beats Estimates, Builds Blockchain Capital Market

Figure Technology Solutions reported Q1 earnings that significantly exceeded Wall Street expectations, indicating strong...

Saylor Signals More Bitcoin Buys, Urges Shareholder Vote

Strategy signaled another Bitcoin purchase is likely this week, continuing its multi-year accumulation strategy.The...

NGINX Under Active Attack After Patch Release

A critical heap buffer overflow vulnerability (CVE-2026-42945) in NGINX is being actively exploited in...

Micron Soars 700%; Insiders Sell $52M as AI Boom Fuels Rally

Micron stock (MU) trades near $800, a dramatic climb from a 52-week low near...

Must Read

How To Buy a Handshake Domain: A Step-by-Step Guide

Handshake Domains | Benefits | Drawbacks | How To Buy | Supported BrowsersIn this step-by-step guide, I am going to show you how to...
Ad
Altseason Is Loading. These 4 coins are trending right now.
SOL $92.12
DOGE $0.0950
LINK $9.02
SUI $1.02
5% off spot fees when you sign up
Start Trading