🧔♂️ A friendly human may check it before it goes live. More news here
Korean tech platforms curb OpenClaw over security concerns
Major Korean tech firms, including Kakao, Naver, and Karrot Market, are restricting the use of the open-source AI agent OpenClaw over security concerns.
Companies cited risks related to data privacy, potential leaks, and system manipulation.
Kakao and Naver told employees to avoid using OpenClaw on work devices, while Karrot Market blocked both access and use of OpenClaw and Moltbot.
Industry experts say these steps aim to prevent sensitive information from training external models and to control AI use.
Security analysts warn that OpenClaw’s open-source design and ability to bypass traditional controls pose significant risks.
🔗 Source: The Korea Times
🧠 Food for thought
Implications, context, and why it matters.
OpenClaw security flaws are real and broad
- Companies have raised “security concerns” that researchers back up. They reported hundreds of malicious add-ons called skills, including 341 tied to a coordinated campaign named “ClawHavoc” that aimed to deploy infostealers such as Atomic Stealer 1.
- Researchers also logged serious bugs in the agent software. One was a “1-click” remote code execution flaw (CVE-2026-25253) that could be triggered by a malicious link and lead to token leakage plus arbitrary shell command execution 1.
- Cyera (a data security company) counted 24,478 distinct servers running OpenClaw or former names on the public internet. It linked some cases to a U.S. government organization plus other large organizations 2.
- Snyk (a developer security company) reviewed the ClawHub marketplace and scanned 3,984 skills. It flagged 283 skills, about 7.1%, as “leaky” because their instructions could push agents to mishandle sensitive data such as API keys and credit card details by sending them through large language model (LLM) context and logs 3.
OpenClaw adds fuel to the enterprise “shadow AI” security problem
- Company blocks also connect to “shadow AI.” Employees can install agents like OpenClaw without IT and security team approval, which creates unmonitored gateways into corporate environments 4.
- These agents raise risk because they mix access to private data, exposure to untrusted content, and authority to execute commands. Security researcher Simon Willison called this a “lethal trifecta” 1. Researchers also warned that attackers may hide malicious instructions in ordinary content such as emails or documents that the agent reads, without using traditional malware 2.
- Traditional security tools that scan for bad code often struggle to assess natural-language prompts that can push an agent to leak data 5. Separately, research into the Moltbook AI-agent social network found a misconfigured Supabase database (a backend service used to store and manage app data) that exposed 1.5 million API authentication tokens and 35,000 email addresses. It also shows how “vibe-coded” development (fast, improvisational coding that prioritizes speed over hardening) can ship with insecure defaults 6.
Stay updated on the go with our mobile app.
Get latest insights with smoother, more personalized experience through TIA mobile app.




