热门话题
#
Bonk 生态迷因币展现强韧势头
#
有消息称 Pump.fun 计划 40 亿估值发币,引发市场猜测
#
Solana 新代币发射平台 Boop.Fun 风头正劲

Rui Ma
人工智能、电动汽车、机器人、教育、中国。妈妈。我还帮助编辑@techbuzzchina。个人观点。问我任何问题
今早有很多人问我关于中国政府因安全问题对OpenClaw的警告,之前有几个市政府在推动它。
这有点像系统按预期运作,尽管时机有点滑稽。
这是因为中国设定了广泛的国家优先事项和严格的关键绩效指标(KPI),然后给地方政府留出竞争执行的空间。因此,当人工智能成为国家战略优先事项时,你会看到一系列公告、模仿行为和在那些被批准追求这些KPI的地方政府之间的快速实验。这就是激励结构在发挥作用。
当相关的中央政府机构介入以标记安全风险、关闭漏洞或保护关键现有企业时,这也是系统按预期运作。你希望通过竞争和创新推动上行,同时在任何威胁核心稳定的地方控制下行。
在美国,显然我们不对消费者的脆弱性发出警告,只对企业/关键系统的脆弱性发出警告。每个人都为自己而战。我认为在中国,如果公民没有发出警告而成为已知的、潜在危险和高度不可预测的脆弱性的受害者,他们会指责政府。

Angelica 🌐⚛️🇹🇼🇨🇳🇺🇸14 小时前
CLAWBACK! The Chinese govt is warning the public about the risk of using OpenClaw! This is after local municipal governments went on a Claw-promotion spree encouraging everyone from housewifes to seniors to “raise a lobster”
“Note this is the actual branch of central govt that is technologically literate, not the boomer led municipal govt that promoted this. I hope nothing serious happens. Otherwise some municipal govt cadres will lose their jobs”
According to the risk notice:
Risk Warning Regarding the Security Use of OpenClaw
Source: CNCERT (China’s National Computer Network Emergency Response Technical Team)
Date: March 10, 2026
Recently, the application OpenClaw (also known as “小龙虾 / Crayfish”, formerly called Clawdbot and Moltbot) has become extremely popular for download and use. Major domestic cloud platforms now provide one-click deployment services.
This intelligent agent software can directly control computers through natural language instructions. In order to achieve the capability of autonomously executing tasks, the application is granted relatively high system permissions, including:
•Accessing the local file system
•Reading environment variables
•Calling external service APIs
•Installing extensions and plugins
However, because the default security configuration is extremely weak, if attackers discover a vulnerability they may easily obtain full control of the system.
Recently, due to improper installation and use of OpenClaw agents, several serious security risks have already appeared:
⸻
1. Prompt Injection Risk
Attackers can embed hidden malicious instructions inside web pages.
If OpenClaw reads that webpage, it may be tricked into executing those instructions, potentially causing the system to leak user secrets or credentials.
⸻
2. Operational Error Risk
Because the AI may misunderstand user commands or intent, OpenClaw could accidentally delete important information such as:
•Email
•Core production data
•Other critical files
⸻
3. Malicious Plugin (Skills) Risk
Multiple plugins designed for OpenClaw have already been identified as malicious or potentially dangerous.
After installation, they may:
•Steal cryptographic keys
•Install trojans or backdoors
•Turn the device into a “botnet node” (“肉鸡” – literally “zombie computer”)
⸻
4. Security Vulnerability Risk
Several high- and medium-severity vulnerabilities in OpenClaw have already been publicly disclosed.
If exploited, attackers may gain:
•System control
•Access to private data
•Access to sensitive information
For individual users, this could expose:
•Photos
•Documents
•Chat histories
•Payment accounts
•API keys
For critical sectors such as finance or energy, this could lead to:
•Leakage of core operational data
•Exposure of business secrets
•Leakage of source code repositories
•System outages or paralysis
Potential losses could be very difficult to estimate.

94
热门
排行
收藏
