OpenClaw's viral rise exposes users to prompt injection attacks and credential theft
OpenClaw, the open-source AI assistant that exploded to 150,000 GitHub stars in months, has become a security nightmare. Researchers discovered 341 malicious skills on ClawHub stealing credentials, while exposed instances leak API keys and OAuth tokens. The platform's 770,000 AI agents on Moltbook face prompt injection attacks that could herald a new era of AI worms.