BTC $71,807
2026 Bull Run Is Building Start trading with 5% OFF all fees
Sign Up Now
BTC $71,807
Bull Run 2026 | 5% Off Fees Open your Binance account today
Sign Up

China Warns of OpenClaw AI Security Risks

Critical OpenClaw flaws prompt data leak warnings, state bans, and malware campaigns.

  • China’s CNCERT issued a warning about critical security risks in the open-source AI agent OpenClaw, citing weak defaults and privileged access.
  • Researchers have demonstrated practical indirect prompt injection attacks, enabling data exfiltration via manipulated URL previews.
  • Chinese authorities have moved to restrict the use of OpenClaw in state enterprises and government agencies to contain security risks.
  • Threat actors are actively exploiting the platform’s popularity, distributing malware through fake GitHub repositories.

On March 14, 2026, China’s National Computer Network Emergency Response Technical Team officially warned about severe security vulnerabilities stemming from the use of the autonomous AI agent OpenClaw. The agency highlighted the platform’s inherently weak default configurations and its privileged system access. Consequently, these flaws could allow bad actors to seize control of the endpoint through various attack vectors.
The primary risk involves indirect prompt injection, where malicious instructions embedded in a web page can trick the agent into leaking sensitive data. This attack, also referred to as cross-domain prompt injection, weaponizes benign AI features like web page summarization. It can range from SEO poisoning to generating biased responses by suppressing reviews.
Last month, researchers at PromptArmor found a practical data exfiltration pathway using this method. They demonstrated that link preview features in apps like Telegram could be exploited. The AI agent could be manipulated to generate an attacker-controlled URL that automatically transmits confidential data.
CNCERT highlighted three additional critical concerns beyond rogue prompts. These include the risk of irreversible data deletion due to misinterpreted instructions and the installation of malicious skills from repositories like ClawHub. Furthermore, attackers can exploit recently disclosed security vulnerabilities in OpenClaw to compromise systems.
The agency warned that for critical sectors like finance and energy, such breaches could leak core business data or paralyze entire systems. Meanwhile, Chinese authorities have moved to restrict state-run enterprises and government agencies from running OpenClaw AI apps on office computers, according to reports. The ban also reportedly extends to families of military personnel.
Threat actors are capitalizing on the platform’s viral popularity to distribute malware. Huntress detailed a campaign using malicious GitHub repositories posing as OpenClaw installers. These repositories deployed information stealers like Atomic and a Golang-based proxy malware known as GhostSocks.

- Advertisement -

✅ Follow BITNEWSBOT on Telegram, Facebook, LinkedIn, X.com, and Google News for instant updates.

Previous Articles:

- Advertisement -
Ad
Altseason Is Loading. Don't watch from the sidelines.
SOL $90.51
DOGE $0.0963
LINK $9.02
SUI $1.00
5% off fees when you sign up
Start Trading
Ad
Pay Less on Every Trade. For Life.
$10K/mo volume Save $60/yr
$50K/mo volume Save $300/yr
$100K/mo volume Save $600/yr
5% off all trading fees when you sign up
Claim Your Discount

Latest News

Polish crypto veto override fails by 25 votes amid scandal

Polish lawmakers failed to override President Karol Nawrocki’s veto of crypto oversight legislation, falling...

Sonic V2.2 doubles smart contract size limits for developers

Sonic V2.2 doubles the maximum deployed contract size from 24 KiB to 48 KiB...

ByteDance Secures $29.6B Loan from 30 Banks for AI Push

TikTok parent ByteDance secured a $29.6 billion loan from nearly 30 Chinese and international...

Musk: Tesla IPO value was a thousandth of current value

Tesla stock fell roughly 6% on Friday after the Cybercab launch event in Austin...

Tesla Cybercab stock crashes 6% on NHTSA audit

Tesla stock dropped 6% in an hour after the NHTSA opened a compliance audit...

Must Read

Top 8 Best Anonymous Web Hosting Companies That Accept Crypto

Nowadays, there is plenty of information about people online, and malicious people use them to carry out inappropriate activities. If you want to keep...
Ad
Altseason Is Loading. These 4 coins are trending right now.
SOL $92.12
DOGE $0.0950
LINK $9.02
SUI $1.02
5% off spot fees when you sign up
Start Trading