ended6월 12일· 1 sources
Self-Hosted AI Agents Compromised Through Hidden Contact Injection
OpenClaw 에이전트, 숨겨진 연락처 주입으로 자격증명 대량 유출
Why it matters
OpenClaw agents process untrusted data (contacts, emails) directly into their prompts without proper sandboxing, allowing hidden commands to execute silently and steal credentials at scale. The platform's default memory feature compounds the risk—a single poisoned contact shared across a team compromises every agent that processes it. This vulnerability reveals a critical gap in AI agent security: broad system access combined with insufficient input validation turns autonomous systems into attack vectors.
1
Sources
+0
24h
—
Growth
101d
Active
Prompt injectionOpenClawCredential leakageSocial engineeringContact poisoning