OpenClaw hit by “ClawJacked” exploit: 40,000 AI agent systems allegedly compromised via silent web-based takeover bug, as users debate whether viral warning is real fix or social-engineering hoax

OpenClaw hit by “ClawJacked” exploit: 40,000 AI agent systems allegedly compromised via silent web-based takeover bug, as users debate whether viral warning is real fix or social-engineering hoax
𝕏/@zaimiri
Revision history

3 recorded changes

Want your article here?

Promote with Leviathan News

OpenClaw, a popular open‑source AI agent orchestration platform, was recently found to contain a critical vulnerability dubbed “ClawJacked” that allowed a malicious website opened in a user’s browser to silently hijack a locally running OpenClaw agent and potentially compromise the entire workstation. Security firm Oasis Security reported that any site the developer visited could open a WebSocket connection to the OpenClaw gateway on localhost, brute‑force the gateway password due to missing rate limiting, auto‑register as a trusted device without user approval, and then gain full control of the agent, including reading configuration data, logs, connected nodes, and in some attack chains executing arbitrary shell commands.

AI-generated background, compiled from web sources — not editorial content.

More coverage

Explore the topic

More on AI

Comments