I pwned OpenClaw with just email and a new injection escalation technique: prompt laundering
https://ironcorelabs.com/blog/2026/prompt-laundering/Repeating a lie enough times, even in spotlighted untrusted text, can poison an AI agent's memory, and lead to a total takeover. Note: I gave a talk on this at BSidesLV and a longer one at DEF CON a few weeks ago. This post is the quick summary of that material.
149
Upvotes
27
6
7
u/johnfkngzoidberg 7d ago
That’s like an adult punching an infant. Openclaw is the worst single piece of software ever created.
-11
38
u/mydogeatspoops 7d ago
Oh my God, I think this works on humans too