ended6월 12일· 1 sources

Self-Hosted AI Agents Compromised Through Hidden Contact Injection

OpenClaw 에이전트, 숨겨진 연락처 주입으로 자격증명 대량 유출

Why it matters

OpenClaw agents process untrusted data (contacts, emails) directly into their prompts without proper sandboxing, allowing hidden commands to execute silently and steal credentials at scale. The platform's default memory feature compounds the risk—a single poisoned contact shared across a team compromises every agent that processes it. This vulnerability reveals a critical gap in AI agent security: broad system access combined with insufficient input validation turns autonomous systems into attack vectors.

1
Sources
+0
24h
Growth
101d
Active
Prompt injectionOpenClawCredential leakageSocial engineeringContact poisoning

Sources

Related Issues