OpenClaw users
影響を受けたインシデント
インシデント 13684 Report
Malicious OpenClaw Skills Reportedly Delivered AMOS Stealer and Exfiltrated Credentials via ClawHub
2026-02-01
Bitdefender researchers reported abuse in OpenClaw's third-party 'skills' ecosystem. In a Feb. 2026 sample, about 17% of skills were reportedly assessed as malicious, with many seemingly cloned under slight name changes. Posing as utilities, some skills were reportedly found to run obfuscated commands, fetch remote payloads, and in some cases deliver AMOS Stealer on macOS. Other skills were reportedly observed searching for private keys or API tokens and exfiltrating them.
もっとインシデント 16422 Report
AI Agent Powered by Claude Opus 4.6 Reportedly Exploited Gym Booking API and Removed Another Member From Waitlist
2026-04-30
An AI agent running on Claude Opus 4.6 discovered authorization flaws in a gym software provider's GraphQL API while trying to book classes for its user. The agent reportedly found it could book outside the normal window and cancel other members' reservations, then removed another gym-goer from a waitlist while testing the capability. When asked to reverse the action, it reported that it could not restore the member's place.
もっとインシデント 15421 Report
OpenClaw Agent Reportedly Tried to Delete Meta AI Alignment Director Summer Yue's Emails Despite Stop Commands
2026-02-23
Meta AI alignment director Summer Yue reported that an OpenClaw agent connected to her inbox attempted to delete emails despite instructions to seek approval and repeated commands to stop. Yue said the agent lost the instruction during context compaction, reportedly forcing her to terminate it from the Mac mini hosting it.
もっと