ADVERTISEMENT

“Agents of chaos:” OpenClaw assistant discloses Social Security numbers

A new study has shed light on the dangers of not following OpenClaw recommendations against using the agent for multi-user interactions. When advice is ignored, OpenClaw may reveal highly sensitive information, such as Social Security numbers.

Divided screen, OpenClaw logo on one side and lines of code on another

Image by Cybernews.

Eglė Krištopaitytė
Eglė Krištopaitytė Senior Journalist
March 18, 2026 Updated: March 18, 2026 4 min read
Jurgita Lapienyte justinasv Izabele Pukenaite vilius Ernestas Naprys Egle Kristopaityte
Don't miss our latest stories on Google News
Add us as your Preferred Source on Google.
  • Unauthorized compliance with non-owners
  • Disclosure of sensitive information
  • Execution of destructive system-level actions
  • Denial-of-service conditions
  • Uncontrolled resource consumption
  • Identity spoofing vulnerabilities
  • Sross-agent propagation of unsafe practices
  • Partial system takeover

OpenClaw just cannot keep a secret

The agent revealed all the owner’s emails

ADVERTISEMENT
openclaw-mascot

OpenClaw fell for identity spoofing

In practice, agents default to satisfying whoever is speaking most urgently, recently, or coercively, which is empirically the most common attack surface our case studies exploit.
Study authors

Agents need to know their stakeholders


ADVERTISEMENT