🧔♂️ A friendly human may check it before it goes live. More news here
Chinese users pay to uninstall OpenClaw AI agent
China’s rush to install OpenClaw, an open-source AI assistant that can perform tasks on users’ behalf, has flipped as paid services now offer to remove the agent after an initial installation surge.
On Alibaba’s Xianyu marketplace, a Shanghai-based seller named “mojito lime water” advertised “uninstall OpenClaw” services for about 299 yuan (US$43) and showed more than 10 completed transactions.
Zhou Hongyi, co-founder and chairman of 360 Security Technology, said more than 40% of nearly 150,000 OpenClaw-related assets identified worldwide were held in China, citing company data, and warned that intelligent agents with rights to execute tasks could create new attack vectors.
The China Academy of Information and Communications Technology (CAICT), which is under the Ministry of Industry and Information Technology (MIIT), launched an initiative to develop standards for Claw agents to improve transparency, permissions, and behavioral reliability.
MIIT’s National Vulnerability Database advised users to use the latest official version, limit internet exposure, restrict permissions, and avoid third-party mirrors.
Several universities, including Jiangsu Normal and Anhui Normal, issued emergency notices warning against installation of OpenClaw on campus devices and networks, with some institutions ordering removal and others urging users to avoid it.
The warnings follow scenes of public queues for installations at locations such as Baidu’s offices earlier this week.
🔗 Source: South China Morning Post
🧠 Food for thought
Implications, context, and why it matters.
Unsafe defaults and flaws fueled the OpenClaw backlash
- People moved fast on OpenClaw after official install scripts shipped with unsafe defaults 1.
- The official Docker setup bound the gateway to 0.0.0.0:18789 on all network interfaces, raising the odds of internet exposure on cloud or virtual private server (VPS) deployments, with many exposed instances reported including in China 1.
- Attackers could pair that reach with severe bugs, including a “One-Click RCE” flaw (a remote code execution bug, meaning attackers can run code on a victim’s system; CVE-2026-25253) that could fully compromise a system after a victim clicks or visits a page containing a malicious link 1.
- Security advisories arrived in a burst, with five published in under a week starting Jan. 31, 2026, covering CVE-2026-25253 plus command injection issues (a class of bugs where untrusted input can be used to run unintended system commands) 1.
- The “skills” marketplace added supply-chain exposure, with one analysis finding 41.7% of skills in its dataset contained substantive security vulnerabilities plus malware indicators tied to ClawHavoc campaigns (malware operations that abuse Claw-related tools and add-ons) 2.
OpenClaw’s failure signals a new era of ‘Shadow AI’ agent risk
- The incident tracks “Shadow AI” shifting from unauthorized chatbots to agentic tools that run with very high system permissions, often described as root-level access 3.
- Employee installs can open unmanaged entry points that slip past standard controls, then enable wider malicious activity beyond data leakage if compromised 3.
- AI “skills” marketplaces now form another supply-chain path, since malware can arrive disguised as productivity add-ons 1.
- Threat actors can use prompt injection as the payload, delivered through external inputs like messages, to push the agent to exfiltrate data in ways security tools often miss 4.
- The project’s “vibe-coding” and “No Plan Mode” culture (informal development approaches that prioritize speed over planning) sharpened the gap between experimental open-source AI work and business tools that can act autonomously 5.
Stay updated on the go with our mobile app.
Get latest insights with smoother, more personalized experience through TIA mobile app.




