BTC $71,807
2026 Bull Run Is Building Start trading with 5% OFF all fees
Sign Up Now
BTC $71,807
Bull Run 2026 | 5% Off Fees Open your Binance account today
Sign Up

China Warns of OpenClaw AI Security Risks

Critical OpenClaw flaws prompt data leak warnings, state bans, and malware campaigns.

  • China’s CNCERT issued a warning about critical security risks in the open-source AI agent OpenClaw, citing weak defaults and privileged access.
  • Researchers have demonstrated practical indirect prompt injection attacks, enabling data exfiltration via manipulated URL previews.
  • Chinese authorities have moved to restrict the use of OpenClaw in state enterprises and government agencies to contain security risks.
  • Threat actors are actively exploiting the platform’s popularity, distributing malware through fake GitHub repositories.

On March 14, 2026, China’s National Computer Network Emergency Response Technical Team officially warned about severe security vulnerabilities stemming from the use of the autonomous AI agent OpenClaw. The agency highlighted the platform’s inherently weak default configurations and its privileged system access. Consequently, these flaws could allow bad actors to seize control of the endpoint through various attack vectors.
The primary risk involves indirect prompt injection, where malicious instructions embedded in a web page can trick the agent into leaking sensitive data. This attack, also referred to as cross-domain prompt injection, weaponizes benign AI features like web page summarization. It can range from SEO poisoning to generating biased responses by suppressing reviews.
Last month, researchers at PromptArmor found a practical data exfiltration pathway using this method. They demonstrated that link preview features in apps like Telegram could be exploited. The AI agent could be manipulated to generate an attacker-controlled URL that automatically transmits confidential data.
CNCERT highlighted three additional critical concerns beyond rogue prompts. These include the risk of irreversible data deletion due to misinterpreted instructions and the installation of malicious skills from repositories like ClawHub. Furthermore, attackers can exploit recently disclosed security vulnerabilities in OpenClaw to compromise systems.
The agency warned that for critical sectors like finance and energy, such breaches could leak core business data or paralyze entire systems. Meanwhile, Chinese authorities have moved to restrict state-run enterprises and government agencies from running OpenClaw AI apps on office computers, according to reports. The ban also reportedly extends to families of military personnel.
Threat actors are capitalizing on the platform’s viral popularity to distribute malware. Huntress detailed a campaign using malicious GitHub repositories posing as OpenClaw installers. These repositories deployed information stealers like Atomic and a Golang-based proxy malware known as GhostSocks.

- Advertisement -

✅ Follow BITNEWSBOT on Telegram, Facebook, LinkedIn, X.com, and Google News for instant updates.

Previous Articles:

- Advertisement -
Ad
Altseason Is Loading. Don't watch from the sidelines.
SOL $90.51
DOGE $0.0963
LINK $9.02
SUI $1.00
5% off fees when you sign up
Start Trading
Ad
Pay Less on Every Trade. For Life.
$10K/mo volume Save $60/yr
$50K/mo volume Save $300/yr
$100K/mo volume Save $600/yr
5% off all trading fees when you sign up
Claim Your Discount

Latest News

Bitcoiners Doubt US Military’s Understanding of Bitcoin

U.S. Navy Admiral Samuel Paparo told a Senate committee the U.S. government operates a...

North America Leads in Stablecoin Payments After Asia

Global stablecoin transaction volume hit $4.5 trillion in Q1 2026, signaling a move from...

CFTC Sues New York to Block State Gambling Laws on Markets

The CFTC has sued New York to prevent state gambling laws from being applied...

Bitcoin Eyes May Rally as Fed Holds Rates Steady

Bitcoin gained over 13% in April and held above $77,000, signaling strong momentum heading...

Brazil Shuts 27 Prediction Markets, Citing Debt Risk

Brazilian regulators ordered the shutdown of 27 prediction market platforms, including Kalshi and Polymarket,...

Must Read

Top 7 BEST Crypto Trading Bots for Beginners

QUICK NAVIGATIONQuick Look: Top 3 Best Crypto Trading BotsWhat Exactly is a Crypto Trading Bot?How I Chose These Trading BotsTop 7 Crypto Trading Bots...
Ad
Altseason Is Loading. These 4 coins are trending right now.
SOL $92.12
DOGE $0.0950
LINK $9.02
SUI $1.02
5% off spot fees when you sign up
Start Trading