Tired of ads? Enjoy an ad-free experience by signing up.
👩‍🍳 How we use AI at Tech in Asia, thoughtfully and responsibly.
🧔‍♂️ A friendly human may check it before it goes live. More news here

OpenClaw AI banned at financial institutions over security worries

Several brokerages, banks, and government bodies have moved to restrict staff access to OpenClaw after security concerns about the agent’s unusually high access to user devices.

OpenClaw is an open-source AI assistant that recently went viral in China.

At one major brokerage, the firm issued a risk warning banning OpenClaw from company computers and asked staff who had installed it to contact IT for removal.

Several employees at brokerages and banks said existing workplace controls already made installation technically impossible because office systems only allow company devices.

OpenClaw was released by Austrian developer Peter Steinberger late last year and can perform tasks such as organising and responding to emails, drafting reports, and preparing slide decks.

🧠 Food for thought

Implications, context, and why it matters.

The restrictions respond to a viral phenomenon with significant security risks

  • Before the restrictions, OpenClaw turned into a cultural craze in China, dubbed “raising crayfish,” while some local governments offered subsidies for OpenClaw-related projects 1.
  • That surge gave attackers more targets, with tens of thousands of OpenClaw instances exposed online and China described as the largest deployment area 2.
  • Its agent design carries an architectural weakness. It relies on “implicit trust” between its AI reasoning and its ability to execute commands on the operating system (the core software that runs a computer and controls access to its files and apps) 3.
  • Plugin distribution adds another avenue for abuse, where one analysis found 336 malicious samples among more than 3,000 ClawHub Skill samples collected (about 10.8%) 2.

AI agents can become an insider-style risk that challenges traditional security controls

  • Standard apps follow narrow rules, but agents like OpenClaw can act like a privileged “insider” on a computer. They make autonomous choices with high-level permissions, especially when over-privileged or poorly governed 4.
  • Many attacks skip software bugs. An attacker can steer the agent into misusing valid access by planting malicious text in an email or on a website (indirect prompt injection, where the agent follows hidden or misleading instructions embedded in content it reads) 5.
  • Conventional defenses can miss this behavior, since malicious skill actions and prompt-driven execution often slip past familiar controls 6.
  • The case also raises “shadow AI” concerns, where employees may install powerful, unvetted agents in workplace environments under the guise of productivity tools 6.

Recent OpenClaw developments

🔗 Source: South China Morning Post

Stay ahead in Asia’s tech landscape

You've reached your 2 free content limit for the month. Sign up for free to read the full story.

🏄 For casual readers / 👶 Free

Basic

US$0

Free forever

Get instant access to this article and more every month

0 premium content

Unlimited news briefs

5

5 articles

Ad-free reading experience

Just US$0 per day

⌛Sign up in 20s. No payment details needed.

📖 For learners / 👍 Starter

Lite

US$4.92/month

Billed annually at US$59/year

Get instant access to this article and more every month

4

4 premium content

Unlimited news briefs & articles

Ad-free reading experience

Just US$0.17 per day

Cancel anytime

Our subscriber community includes professionals from these companies:

Stay updated on the go with our mobile app.

Get latest insights with smoother, more personalized experience through TIA mobile app.