Particle.news

OpenClaw’s DIY AI Agent Keeps Growing as Security Warnings Intensify

Experts say many user‑hosted setups remain high‑risk even after recent security updates.

Overview

  • OpenClaw is a user‑hosted AI agent that connects WhatsApp, Telegram and Discord to automate files, email, calendars and web tasks directly on a local machine or VPS.
  • Adoption remains strong, with reports of hundreds of thousands of downloads and more than 140,000 GitHub stars, and hands‑on reviews highlight unusually easy setup and useful bundled integrations.
  • The latest release added new security features, but researchers demonstrated prompt‑injection by emailing a malicious command to an instance and warn misconfigured deployments can expose systems.
  • User accounts describe both benefits and harms, including a report of 75,000 emails being deleted and a separate claim of an investment portfolio wiped out after granting trading access.
  • A companion platform called Moltbook has emerged where agents post and interact autonomously, showcasing both experimentation and the governance questions raised by agent‑to‑agent activity.