Tired of ads? Enjoy an ad-free experience by signing up.
👩‍🍳 How we use AI at Tech in Asia, thoughtfully and responsibly.
🧔‍♂️ A friendly human may check it before it goes live. More news here

China issues second warning over OpenClaw AI security risks

The National Computer Network Emergency Response Technical Team/Coordination Center of China (CNCERT), a non-governmental and non-profit cybersecurity technical platform, issued a second warning about security and data risks tied to the OpenClaw AI agent.

The warning comes as local governments and tech firms rapidly deploy it.

OpenClaw was released by Austrian developer Peter Steinberger late last year and can perform tasks such as organising and responding to emails, drafting reports, and preparing slide decks.

CNCERT said improper installation and the agent’s need for high-level permissions increase breach risk. It is also vulnerable to prompt injection attacks via web pages that could leak system keys.

The National Vulnerability Database (NVDB) issued a similar notice, urging users to check permission settings, disable unnecessary public access, and tighten controls.

Meanwhile, Chinese tech firms including Alibaba Cloud, ByteDance, Zhipu, and Tencent are offering easy access, while several local governments have promoted or subsidised installations.

🔗 Source: South China Morning Post

🧠 Food for thought

Implications, context, and why it matters.

China’s warning targets a quantifiable security crisis

  • The advisory goes beyond precaution. SecurityScorecard (a cybersecurity ratings firm) counted more than 135,000 OpenClaw instances exposed to the public internet 1.
  • Public disclosures include a one-click remote code execution (RCE) flaw, meaning an attacker could run malicious code on a target machine, plus a supply-chain campaign tied to the ClawHub skills marketplace (a third-party plugin and add-on store for OpenClaw) 1.
  • Snyk (a developer security company) ran its February 2026 ToxicSkills research on 3,984 skills. It found 13.4% carried at least one critical-level issue 2.
  • Some problems sit in the design itself, including improper session isolation that can leak data between users on chat platforms like Telegram and Discord 3.

Easy deployment is adding to shadow IT debt

  • Chinese cloud providers offer free installation services and tutorials for OpenClaw to win customers. That speeds adoption, and many setups skip safeguards CNCERT warned about 4.
  • Grassroots excitement adds to a “shadow IT” pattern, where staff deploy tools outside official oversight. Examples include users buying dedicated Mac Minis (small desktop computers from Apple) to run the agent, which can spill into company and government networks 5.
  • Tencent is building QClaw, an OpenClaw-style one-click installer for WeChat and QQ. Tencent Cloud also launched WorkBuddy, a workplace AI agent tested by over 2,000 employees 6.
  • Across the AI industry, quick setup often means fewer guardrails. The tradeoff leaves more room for future exposure 6.

Recent OpenClaw developments

Stay ahead in Asia’s tech landscape

You've reached your 2 free content limit for the month. Sign up for free to read the full story.

🏄 For casual readers / 👶 Free

Basic

US$0

Free forever

Get instant access to this article and more every month

0 premium content

Unlimited news briefs

5

5 articles

Ad-free reading experience

Just US$0 per day

⌛Sign up in 20s. No payment details needed.

📖 For learners / 👍 Starter

Lite

US$4.92/month

Billed annually at US$59/year

Get instant access to this article and more every month

4

4 premium content

Unlimited news briefs & articles

Ad-free reading experience

Just US$0.17 per day

Cancel anytime

Our subscriber community includes professionals from these companies:

Stay updated on the go with our mobile app.

Get latest insights with smoother, more personalized experience through TIA mobile app.