< Back to all clusters
[TECHNOLOGY] · United States · 3 sources

started · updated

OpenAI spying on users and OpenClaw flaws raise AI agent security concerns

OpenAI disclosed that it accessed the prompts of certain ChatGPT users it suspected of being part of a Chinese Communist Party‑linked influence campaign. The company identified two clusters—"Data Center Bandwagon" and "Tech and Tariffs"—and said there was no evidence the activity altered public opinion.

Security researchers from Imperva and Varonis demonstrated that the self‑hosted OpenClaw AI agent can be coaxed into executing attacker‑controlled code or leaking synthetic secrets through ordinary‑looking inputs such as shared contacts, vCards or location pins. The vulnerability, dubbed “agent phishing,” was patched in the OpenClaw 2026.4.23 release.

Separately, OpenClaw creator Peter Steinberger and Anthropic’s Claude Code lead Boris Cherny promoted “loopcraft,” a paradigm that shifts focus from individual prompts to designing automated loops that generate prompts for AI agents. They outlined six loop primitives and cited Karpathy’s autoresearch project as a practical example of loop‑driven AI engineering.