
Two security teams demonstrated that OpenClaw AI agents can be manipulated through ordinary inputs. Imperva hid instructions inside shared contacts and location pins that the agent executed. Varonis showed a single email tricking an agent into forwarding fake AWS keys. Imperva's flaw is patched in OpenClaw 2026.4.23.
Tap to vote and see what everyone thinks.