New Attacks Trick OpenClaw AI Agent Into Running Code and Leaking Secrets
In separate studies released this week, two security teams demonstrated how OpenClaw, the well-known self-hosted AI agent, can be made to execute attacker-controlled code or provide sensitive data using inputs that appear normal.
Imperva concealed instructions that the agent carried out without the victim ever seeing them inside shared contacts, vCards, and location pins. Varonis created a test agent on the platform, provided it with a mailbox containing fictitious business data, and observed how one simple email persuaded it to transfer fictitious AWS keys and a fictitious customer export to an external address.
The bug Imperva identified is corrected in OpenClaw 2026.4.23, so update if you run it. Varonis discovered a phishing vulnerability that can only be addressed by restrictin...


