China’s Ministry of State Security Warns of Four Major OpenClaw AI Agent Cybersecurity Risks
OpenClaw is an open-source AI agent capable of autonomously executing tasks, controlling host systems, accessing files and connecting to external services. Chinese users have consequently nicknamed its use “lobster farming.” China’s Ministry of State Security said combining a high degree of automation with excessive system permissions could expose personal devices and corporate environments to national security and cybersecurity threats.
The Ministry of State Security recently issued a warning identifying four major OpenClaw security risks, including host-system takeover and sensitive data leaks. The report did not disclose the warning’s exact publication date or the amount of any losses. Cybersecurity experts recommend applying the principle of least privilege, restricting accessible data and avoiding direct exposure of the service to the public internet to reduce the risk of compromise.
All Coverage
1 original reportsThe Backstory
The history behind this eventChinese Authorities Issue First Risk Management Guide for OpenClaw-Like AI Agent Frameworks
OpenClaw-like AI agent frameworks can autonomously break down tasks, call external tools and execute actions, but uncontrolled permissions or flawed judgments can also amplify cybersecurity and operational risks. The Artificial Intelligence Industry Alliance of China developed dedicated standards with several technology companies, marking the first systematic effort to establish a risk-governance benchmark for such agent frameworks.
As of July 20, 2026, the alliance had issued what it billed as the world’s first risk management guide for OpenClaw-like AI agent frameworks. It identified six major technical risks, including tool calls and decisions based on hallucinations, as well as three major management vulnerabilities, and proposed three preventive principles. Available information did not disclose the formal publication date, the participating companies, an implementation timetable or any amounts involved.
OpenClaw AI Agent Software Goes Viral in China, Triggering Cybersecurity Warnings
OpenClaw, created by Austrian engineer Peter Steinberger and released as open source in January 2026, can handle email, manage schedules and book flights. Its popularity has sparked a “raising lobsters” craze in China. The software requires access to files and environment variables and can call APIs. Those elevated system privileges also expose personal credentials, corporate data and industrial control systems to the risk of leaks or takeover.
China’s National Computer Network Emergency Response Technical Team/Coordination Center warned on March 10, 2026, that malicious instructions embedded in webpages could cause product keys to leak. Remote uninstallation services priced at 199 yuan (about NT$920) quickly appeared. On March 22, the center and the Cyber Security Association of China issued the first secure-use guidelines, calling for OpenClaw to be isolated on dedicated devices or virtual machines and denied administrator privileges. Financial institutions, government agencies and several colleges and universities have also successively restricted its use.
Chinese Government Agency Warns of Industrial Risks From OpenClaw AI Agent
OpenClaw, formerly known as Clawdbot and Moltbot, is an open-source AI agent that can operate computers through natural-language instructions, retain persistent memory and take actions proactively. It is moving into research and design, manufacturing, and operations and maintenance. Industrial systems carry extensive privileges, handle sensitive data and face high downtime costs, making the notice a sign that Chinese authorities have brought AI agents within the scope of industrial cybersecurity oversight.
On March 12, 2026, the National Industrial Information Security Development Research Center, which is directly overseen by China’s Ministry of Industry and Information Technology, issued a special notice identifying three major risks: unauthorized host access and loss of production-line control, leaks of sensitive information, and an expanded attack surface. It said more than 80 vulnerabilities had been disclosed in OpenClaw. The center instructed companies to conduct self-assessments under two standards and a set of “six dos and six don’ts,” restrict system privileges, isolate industrial control networks and patch vulnerabilities.
Subscribe to Mark Radar Weekly
Every Friday, the week's strongest signals in your inbox. Unsubscribe anytime.
If you search news on Google, you can set Mark Radar as a preferred source—our coverage will show up more often in your results. Set as preferred source on Google →