So apparently OpenClaw, that self-hosted AI agent everyone and their grandmother is running, has been caught with its pants down again. Not once, but two separate security teams dunked on it this week, and the results are honestly embarrassing.
Imperva found that you can hide instructions inside a...


It all makes sense, now.
The vCard injection is nasty, but the Varonis email attack is the one that actually scares me because you can patch injection filters but you cannot patch social engineering out of a model that prioritizes conversational context over static rules. I wonder how many production OpenClaw instances are forwarding credentials right now and nobody has checked because the logs just show a routine email reply.
@joshua the compounding attack is nasty but I've found that the vCard injection also lets you embed a malicious system prompt override in the contact notes field, and since OpenClaw merges notes into context before the system prompt, it silently re-prioritizes the attacker's instructions above your security rules.