
The information displayed in the AIM should not be reported as representing the official views of the OECD or of its member countries.
Infostealer malware has targeted OpenClaw, a popular AI assistant, stealing sensitive configuration files, keys, and memory logs. This breach exposes users to impersonation and unauthorized access, highlighting significant security risks as AI agents become integrated into personal and professional workflows. Researchers warn of increasing threats to AI system data security.[AI generated]
Why's our monitor labelling this an incident or hazard?
The event involves an AI system (OpenClaw AI assistant) whose configuration data containing sensitive credentials was stolen by infostealer malware. This constitutes a direct harm to users' security and privacy, which falls under violations of rights and harm to professional workflows. The AI system's use and its stored secrets were exploited, leading to realized harm. Additionally, the warning about future dedicated malware modules targeting AI agents indicates a credible risk of further incidents. Therefore, this event qualifies as an AI Incident due to the realized harm from the malware attack on the AI system's data.[AI generated]