OpenClaw

Given it appears things like OpenClaw are (apparently) responsible for shortages of some Mac models, I’m wondering if anyone has actually used it, and would care to describe its use.

I’ve read a fair bit at https://openclaw.ai but still struggling to grasp what it actually does. The testimonials on the site seem to suggest it’s a self-learning, self-coding AI project which could easily replace your brain — I’m interested to see what the reality is.

Anyone??

I’m a financial markets person, not a developer, so I haven’t used OpenClaw myself. But since it is having an effect on many facets of the tech industry, I’ve been (loosely) following it.

This is a Bloomberg article that greatly added to my understanding from a couple of months ago (I’ve quoted several sections because the full story is behind a paywall):

The digital assistant can use your computer to handle complex tasks that previously only a human could undertake, such as making travel bookings, prioritizing emails and drafting replies, surveying product catalogs and emailing vendors.

This leap in productivity comes with a catch: OpenClaw has proved to be a gift to hackers. One critical flaw, dubbed ClawJacked, allowed intruders to take control of a user’s OpenClaw agent simply by getting them to visit a malicious website. That defect was fixed. But researchers have found more than 40,000 vulnerabilities in the software.

Nowhere is there as much excitement or apprehension around OpenClaw as in China, where its rapid adoption has led to gyrations in the stock prices of big local tech firms and prompted officials to warn government agencies and state-owned enterprises — including some of the country’s largest banks — against installing it on office devices.
[…]
It’s an AI assistant that can be set up on a computer or even a smartphone. Giant AI companies including OpenAI Inc. and Anthropic PBC also offer agents that field tasks for users. However, those companies don’t allow customers to modify their agents’ underlying parameters. OpenClaw’s code is “open source,” which allows users to be more freewheeling with the product, opening the door to some more inventive — and potentially risky — uses for the technology. OpenClaw works from the data on a user’s phone or computer, in contrast to other popular AI services that process it remotely in so-called cloud networks.
[…]
Some cybersecurity experts see a disaster in the making. In March, several Chinese government agencies and banks issued official alerts over OpenClaw. They detailed risks including data theft and “prompt injection” attacks, in which texts are sent to trick an AI agent to perform unauthorized actions.

Hackers can create new “skills” for OpenClaw that include installing hidden malware and harvesting the personal data of users and their contacts. Kasimir Schulz, director of security research at HiddenLayer Inc., said OpenClaw ticks all the boxes when it comes to cybersecurity risk: It has access to private data, it can communicate externally and has exposure to untrusted content.

For agentic AI like OpenClaw to be really useful, it needs to know all about you, and gain access to a variety of apps. That makes them juicy cyberattack avenues or targets.
https://www.bloomberg.com/news/articles/2026-03-11/what-is-the-openclaw-ai-agent-and-why-is-it-popular-in-china


So, since OpenClaw is great for vibe coding—and all of the risks and problems associated with vibe coding—things like this can happen, even to people who code for a living:

Chris Boyd, a software engineer, began tinkering with a digital personal assistant called OpenClaw at the end of January, while he was snowed in at his North Carolina home. He used it to create a daily digest of relevant news stories and send them to his inbox every morning at 5:30 a.m.

But after he gave the open-source AI agent access to iMessage, Boyd says OpenClaw went rogue. It bombarded Boyd and his wife with more than 500 messages and spammed random contacts too.

“It’s a half-baked rudimentary piece of software that was glued together haphazardly and released way too early,” said Boyd, who added that he has since altered OpenClaw’s codebase to apply his own security patches to reduce risks. “I realized it wasn’t buggy. It was dangerous.”
https://www.bloomberg.com/news/articles/2026-02-04/openclaw-s-an-ai-sensation-but-its-security-a-work-in-progress

5 Likes

And one more description with how somebody is actually using Open Claw…

The bot has come to life thanks to OpenClaw, an open-source framework for developing personalized AI agents. Cadwell began creating Etchie, as he calls it, on his Mac in March to automate coding requests and handle marketing and administrative tasks, including triaging his email inbox and even responding on its own to supply chain problems. It has access to his store’s Etsy and Shopify accounts and is tapped into models from Anthropic and OpenAI. The bot also uses a voice plug-in, so Cadwell can chat with it as they bounce over the rocks outside Flagstaff or Tucson. “I hit the trails driving and just talk to Etchie about what I want to do. We hash out my ideas, and then it starts building a design scope,” Cadwell says. “When I wake up in the morning, the whole project’s complete.” He says the system is his “first AI employee.”

AI agents like this are a step past ChatGPT or Google’s Gemini. If you ask one of those standalone apps for help changing your mailing address, it will likely reply with a list of links and instructions from the US Postal Service. An AI agent installed on your Mac with the right permissions can actually open your browser, type in usps.com, click the right options and update your personal details, all with little to no human oversight. Witnessing it in action is a bit like playing with a Ouija board and wondering who’s sliding the heart-shaped piece.

https://www.bloomberg.com/news/articles/2026-05-11/why-claude-ai-agents-are-driving-record-mac-mini-demand

A story this morning from our local news channel about an Ai Assistant which hacked a gym site to get a spot in a class.

He uses it to book classes. When the class was full he was placed on a waiting list, so it hacked the system, kicked someone out, and took their spot.

An important clarification for anyone that doesn’t visit the article. The person doing the coding didn’t intentionally remove someone from a waitlist. It was an unintended consequence of his coding effort when his “agent” made the decision to do that and informed him after the fact. I guess that makes it worse (?).

Wow! That’s like a micro-version of the Open AI/Hugging Bear and Meta AI-hacking incidents. Crazy, Maybe I’m going to have to learn how to use Open Claw to get ready for the next Taylor Swift or Air Jordan product “drop”.
;-)

Is it just a matter of time before someone’s AI hacks into an airline booking system and boots a person off a flight to make room for them?

1 Like

Or clears out the other seats in an Economy row…

Surely an upgrade to Business or First would be doable…

1 Like

Of course, what we don’t know is how often enterprising people who also figured out this security flaw were taking advantage of it quietly such that no one noticed. Hopefully, the people developing these systems are taking note and tasking AI agents with finding and fixing their vulnerabilities.

We should be so lucky as to getting bumped out of a reservation line is the worst that could happen.

Of course it’s already way past that, and as Adam mentions, what’s happening now that hasn’t been brought to light yet is also just the tip of the iceberg for what’s to come.

Indeed, when you assume an AI Agent has access to virtually every hack and security vulnerability known to man, you can only hope they adopt the Maxwell Smart edict of using it “for niceness rather than evil”.

Whilst flicking someone off the waiting list for a gym class is annoying, you wonder how long it will be before things like organ transplant waiting lists are hacked.

As @ace points out, this could be happening now and we’re just not aware of it.