{"id":3095915,"date":"2026-02-23T16:57:14","date_gmt":"2026-02-24T00:57:14","guid":{"rendered":"https:\/\/techcrunch.com\/?p=3095915"},"modified":"2026-02-23T17:18:40","modified_gmt":"2026-02-24T01:18:40","slug":"a-meta-ai-security-researcher-said-an-openclaw-agent-ran-amok-on-her-inbox","status":"publish","type":"post","link":"https:\/\/techcrunch.com\/2026\/02\/23\/a-meta-ai-security-researcher-said-an-openclaw-agent-ran-amok-on-her-inbox\/","title":{"rendered":"A Meta AI security researcher said an OpenClaw agent ran amok on her inbox\u00a0"},"content":{"rendered":"\n<p id=\"speakable-summary\" class=\"wp-block-paragraph\">The <a href=\"https:\/\/x.com\/summeryue0\/status\/2025774069124399363\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">now-viral X post<\/a> from Meta AI security researcher Summer Yue reads, at first, like satire. She told her OpenClaw AI agent to check her overstuffed email inbox and suggest what to delete or archive.\u00a0\u00a0<\/p>\n\n<p class=\"wp-block-paragraph\">The agent proceeded to run amok. It started deleting all her email in a \u201cspeed run\u201d while ignoring her commands from her phone telling it to stop.&nbsp;<\/p>\n\n<p class=\"wp-block-paragraph\">\u201cI had to RUN to my Mac mini like I was defusing a bomb,\u201d she wrote, posting images of the ignored stop prompts as receipts.&nbsp;&nbsp;<\/p>\n\n<p class=\"wp-block-paragraph\">The Mac Mini, an affordable Apple computer that sits flat on a desk and <a href=\"https:\/\/techcrunch.com\/2024\/11\/07\/apple-mac-mini-m4-review-more-power-in-a-tiny-package\/\">fits in the palm of your hand<\/a>, has become the favored device these days for running OpenClaw. (The Mini is selling \u201clike hotcakes,\u201d one \u201cconfused\u201d Apple employee apparently told <a href=\"https:\/\/x.com\/karpathy\/status\/2024987174077432126\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">famed AI researcher Andrej Karpathy<\/a> when he bought one to run an OpenClaw alternative called NanoClaw.)\u00a0<\/p>\n\n<p class=\"wp-block-paragraph\"><a href=\"https:\/\/techcrunch.com\/2026\/02\/15\/openclaw-creator-peter-steinberger-joins-openai\/\">OpenClaw<\/a> is, of course, the open source AI agent that achieved fame through Moltbook, an AI-only social network. OpenClaw agents were at the center of that <a href=\"https:\/\/techcrunch.com\/2026\/02\/16\/after-all-the-hype-some-ai-experts-dont-think-openclaw-is-all-that-exciting\/\">now largely debunked episode<\/a> on Moltbook in which it looked like the AIs were plotting against humans.\u00a0\u00a0<\/p>\n\n<p class=\"wp-block-paragraph\">But OpenClaw\u2019s mission, according to its <a href=\"https:\/\/github.com\/openclaw\/openclaw\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">GitHub page<\/a>, is not focused on social networks. It aims to be a personal AI assistant that runs on your own devices.\u00a0\u00a0<\/p>\n\n<p class=\"wp-block-paragraph\">The Silicon Valley in-crowd has fallen so in love with OpenClaw that &#8220;claw\u201d and \u201cclaws\u201d have become the <a href=\"https:\/\/x.com\/simonw\/status\/2024999368982757509\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">buzzwords of choice<\/a> for agents that run on personal hardware. Other such agents include <a href=\"https:\/\/zeroclaw.org\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">ZeroClaw<\/a>, <a href=\"https:\/\/github.com\/nearai\/ironclaw\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">IronClaw<\/a>, and <a href=\"https:\/\/picoclaw.net\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">PicoClaw<\/a>. Y Combinator\u2019s podcast team even appeared on their <a href=\"https:\/\/www.youtube.com\/watch?v=Q8wVMdwhlh4\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">most recent episode<\/a> dressed in lobster costumes.\u00a0<\/p>\n<div class=\"wp-block-techcrunch-inline-cta\">\n\t<div class=\"inline-cta__wrapper\">\n\t\t<div class=\"inline-cta__logo\">\n\t\t\t<svg aria-hidden=\"true\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\" width=\"41\" height=\"20\" fill=\"none\" viewBox=\"0 0 41 20\"><path fill=\"#fff\" d=\"M0 0v6.452h7.097V20h7.097V6.452h6.451V0zM27.742 13.548V6.452h-7.097V20h20v-6.452zM40.645 0H27.742v6.452h12.903z\"\/><\/svg>\t\t<\/div>\n\t\t<div class=\"inline-cta__flag\">Techcrunch event<\/div>\n\t\t<div class=\"inline-cta__content\">\n\t\t\t<div class=\"inline-cta__header-container\">\n\t\t\t\t<div class=\"inline-cta__header-container-desktop\">\n\t\t\t\t\t\t\t\t\t\t\t<h3 class=\"inline-cta__header has-h-5-font-size\">Save up to $300 or 30% to TechCrunch Founder Summit<\/h3>\n\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t<h4 class=\"inline-cta__subheader\">1,000+<strong> founders<\/strong> and investors come together at <strong>TechCrunch Founder Summit 2026<\/strong> for a full day focused on growth, execution, and real-world scaling. Learn from founders and investors who have shaped the industry. Connect with peers navigating similar growth stages. Walk away with tactics you can apply immediately.<br><br>Offer ends March 13.<\/h4>\n\t\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<div class=\"inline-cta__header-container-mobile\">\n\t\t\t\t\t\t\t\t\t\t\t<h3 class=\"inline-cta__header has-h-5-font-size\">Save up to $300 or 30% to TechCrunch Founder Summit<\/h3>\n\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t<h4 class=\"inline-cta__subheader\">1,000+<strong> founders<\/strong> and investors come together at <strong>TechCrunch Founder Summit 2026<\/strong> for a full day focused on growth, execution, and real-world scaling. Learn from founders and investors who have shaped the industry. Connect with peers navigating similar growth stages. Walk away with tactics you can apply immediately<br><br>Offer ends March 13.<\/h4>\n\t\t\t\t\t\t\t\t\t<\/div>\n\t\t\t<\/div>\n\t\t\t<div class=\"inline-cta__event-info\">\n\t\t\t\t\t\t\t\t\t<span class=\"inline-cta__location\">Boston, MA<\/span>\n\t\t\t\t\t\t\t\t\t\t\t\t\t<span class=\"inline-cta__separator\">|<\/span>\n\t\t\t\t\t\t\t\t\t\t\t\t\t<span class=\"inline-cta__date\">June 9, 2026<\/span>\n\t\t\t\t\t\t\t<\/div>\n\t\t\t<div class=\"inline-cta__register-button\">\n\t\t\t\t\n\n<div class=\"wp-block-buttons is-layout-flex wp-block-buttons-is-layout-flex\">\n<div class=\"wp-block-button\"><a data-ctaText=\"REGISTER NOW\" data-destinationLink=\"https:\/\/techcrunch.com\/events\/techcrunch-founder-summit-2026\/?utm_source=tc&amp;utm_medium=ad&amp;utm_campaign=tcfoundersummit2026&amp;utm_content=seb&amp;promo=tc_inline_seb&amp;display=\" data-event=\"button\" class=\"wp-block-button__link wp-element-button\" href=\"https:\/\/techcrunch.com\/events\/techcrunch-founder-summit-2026\/?utm_source=tc&amp;utm_medium=ad&amp;utm_campaign=tcfoundersummit2026&amp;utm_content=seb&amp;promo=tc_inline_seb&amp;display=\" target=\"_blank\" rel=\"noreferrer noopener\">REGISTER NOW<\/a><\/div>\n<\/div>\n\n\t\t\t<\/div>\n\t\t<\/div>\n\t<\/div>\n<\/div>\n\n<p class=\"wp-block-paragraph\">But Yue\u2019s post serves as a warning. As others on X noted, if an AI security researcher could run into this problem, what hope do mere mortals have?\u00a0<\/p>\n\n<p class=\"wp-block-paragraph\">\u201cWere you intentionally testing its guardrails or did you make a rookie mistake?\u201d a software developer asked her on X.&nbsp;&nbsp;<\/p>\n\n<p class=\"wp-block-paragraph\">\u201cRookie mistake tbh,\u201d she replied. She had been testing her agent with a smaller \u201ctoy\u201d inbox, as she called it, and it had been running well on less important email. It had earned her trust, so she thought she\u2019d let it loose on the real thing.&nbsp;<\/p>\n\n<p class=\"wp-block-paragraph\">Yue believes that the large amount of data in her real inbox \u201ctriggered compaction,\u201d she wrote. Compaction happens when the context window &#8212; the running record of everything the AI has been told and has done in a session &#8212; grows too large, causing the agent to begin summarizing, compressing, and managing the conversation.\u00a0\u00a0<\/p>\n\n<p class=\"wp-block-paragraph\">At that point, the AI may skip over instructions that the human considers quite important.&nbsp;&nbsp;<\/p>\n\n<p class=\"wp-block-paragraph\">In this case, it may have skipped her last prompt &#8212; where she told it not to act &#8212; and reverted back to its instructions from the \u201ctoy\u201d inbox.&nbsp;<\/p>\n\n<p class=\"wp-block-paragraph\">As several others <a href=\"https:\/\/x.com\/isik5\/status\/2025920413700641132\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">on X pointed out<\/a>, <a href=\"https:\/\/x.com\/mikedelta221\/status\/2025936657396985983\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">prompts can\u2019t be trusted<\/a> to act as security guardrails. Models may misconstrue or ignore them.\u00a0<\/p>\n\n<p class=\"wp-block-paragraph\">Various people offered suggestions that ranged from the exact syntax Yue should have used to stop the agent, to various methods to ensure better adherence to guardrails, like writing instructions to dedicated files or using other open source tools.\u00a0<\/p>\n\n<p class=\"wp-block-paragraph\">In the interest of full transparency, TechCrunch could not independently verify what happened to Yue\u2019s inbox. (She didn\u2019t respond to our request for comment, though she did respond to many questions and comments sent her way on X.)\u00a0<\/p>\n\n<p class=\"wp-block-paragraph\">But it doesn\u2019t really matter.&nbsp;<\/p>\n\n<p class=\"wp-block-paragraph\">The point of the tale is that agents aimed at knowledge workers, at their current stage of development, are risky. People who say they are using them successfully are cobbling together methods to protect themselves.<\/p>\n\n<p class=\"wp-block-paragraph\">One day, perhaps soon (by 2027? 2028?), they may be ready for widespread use. Goodness knows many of us would love help with email, grocery orders, and scheduling dentist appointments. But that day has not yet come.\u00a0<\/p>\n\n<p class=\"wp-block-paragraph\"><\/p>\n","protected":false},"excerpt":{"rendered":"<p>The viral X post from an AI security researcher reads like satire. But it&#8217;s really a word of warning about what can go wrong when handing tasks to an AI agent.<\/p>\n","protected":false},"author":133574633,"featured_media":3095916,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"tc-featured-article":false,"tc-header-option":"","tc-breaking-news":false,"tc-article-brief":false,"carmot_uuid":"","apple_news_api_created_at":"2026-02-24T00:57:24Z","apple_news_api_id":"b714009e-fe59-480f-b614-bbc73a6d9108","apple_news_api_modified_at":"2026-02-24T01:18:18Z","apple_news_api_revision":"AAAAAAAAAAAAAAAAAAAABg==","apple_news_api_share_url":"https:\/\/apple.news\/AtxQAnv5ZSA-2FLvHOm2RCA","apple_news_coverimage":0,"apple_news_coverimage_caption":"","apple_news_is_hidden":false,"apple_news_is_paid":false,"apple_news_is_preview":false,"apple_news_is_sponsored":false,"apple_news_maturity_rating":"","apple_news_metadata":"\"\"","apple_news_pullquote":"","apple_news_pullquote_position":"","apple_news_slug":"","apple_news_sections":[],"apple_news_suppress_video_url":false,"apple_news_use_image_component":false,"tc_subtitle":"","tc_featured_image_disabled":false,"tc_exclude_from_rss_feed":false,"tc_exclude_from_content_rivers":false,"footnotes":""},"categories":[577047203,17396],"tags":[577173265,577370397],"tc_region":[],"tc_event":[],"tc_storyline_tax":[],"coauthors":[577235617],"class_list":["post-3095915","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-artificial-intelligence","category-tc","tag-meta-ai","tag-openclaw"],"apple_news_notices":[],"yoast_head":"<!-- This site is optimized with the Yoast SEO Premium plugin v25.1 (Yoast SEO v25.1) - https:\/\/yoast.com\/wordpress\/plugins\/seo\/ -->\n<title>A Meta AI security researcher said an OpenClaw agent ran amok on her inbox\u00a0 | TechCrunch<\/title>\n<meta name=\"description\" content=\"The viral X post from an AI security researcher reads like satire. But it&#039;s really a word of warning about what can go wrong when handing tasks to an AI agent.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/techcrunch.com\/2026\/02\/23\/a-meta-ai-security-researcher-said-an-openclaw-agent-ran-amok-on-her-inbox\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"A Meta AI security researcher said an OpenClaw agent ran amok on her inbox\u00a0 | TechCrunch\" \/>\n<meta property=\"og:description\" content=\"The viral X post from an AI security researcher reads like satire. But it&#039;s really a word of warning about what can go wrong when handing tasks to an AI agent.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/techcrunch.com\/2026\/02\/23\/a-meta-ai-security-researcher-said-an-openclaw-agent-ran-amok-on-her-inbox\/\" \/>\n<meta property=\"og:site_name\" content=\"TechCrunch\" \/>\n<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/techcrunch\" \/>\n<meta property=\"article:published_time\" content=\"2026-02-24T00:57:14+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2026-02-24T01:18:40+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/techcrunch.com\/wp-content\/uploads\/2026\/02\/Y-Combinator-Crab.png?resize=1200,829\" \/>\n\t<meta property=\"og:image:width\" content=\"1200\" \/>\n\t<meta property=\"og:image:height\" content=\"829\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/png\" \/>\n<meta name=\"author\" content=\"Julie Bort\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:creator\" content=\"@TechCrunch\" \/>\n<meta name=\"twitter:site\" content=\"@TechCrunch\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"Julie Bort\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"3 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\/\/schema.org\",\"@graph\":[{\"@type\":\"NewsArticle\",\"@id\":\"https:\/\/techcrunch.com\/2026\/02\/23\/a-meta-ai-security-researcher-said-an-openclaw-agent-ran-amok-on-her-inbox\/#article\",\"isPartOf\":{\"@id\":\"https:\/\/techcrunch.com\/2026\/02\/23\/a-meta-ai-security-researcher-said-an-openclaw-agent-ran-amok-on-her-inbox\/\"},\"author\":{\"name\":\"Julie Bort\",\"@id\":\"https:\/\/techcrunch.com\/#\/schema\/person\/6069415d0273765316aa1237c2434e09\"},\"headline\":\"A Meta AI security researcher said an OpenClaw agent ran amok on her inbox\u00a0\",\"datePublished\":\"2026-02-24T00:57:14+00:00\",\"dateModified\":\"2026-02-24T01:18:40+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\/\/techcrunch.com\/2026\/02\/23\/a-meta-ai-security-researcher-said-an-openclaw-agent-ran-amok-on-her-inbox\/\"},\"wordCount\":666,\"publisher\":{\"@id\":\"https:\/\/techcrunch.com\/#organization\"},\"image\":{\"@id\":\"https:\/\/techcrunch.com\/2026\/02\/23\/a-meta-ai-security-researcher-said-an-openclaw-agent-ran-amok-on-her-inbox\/#primaryimage\"},\"thumbnailUrl\":\"https:\/\/techcrunch.com\/wp-content\/uploads\/2026\/02\/Y-Combinator-Crab.png\",\"keywords\":[\"meta ai\",\"openclaw\"],\"articleSection\":[\"AI\",\"TC\"],\"inLanguage\":\"en-US\",\"copyrightYear\":\"2026\",\"copyrightHolder\":{\"@id\":\"https:\/\/techcrunch.com\/#organization\"}},{\"@type\":\"WebPage\",\"@id\":\"https:\/\/techcrunch.com\/2026\/02\/23\/a-meta-ai-security-researcher-said-an-openclaw-agent-ran-amok-on-her-inbox\/\",\"url\":\"https:\/\/techcrunch.com\/2026\/02\/23\/a-meta-ai-security-researcher-said-an-openclaw-agent-ran-amok-on-her-inbox\/\",\"name\":\"A Meta AI security researcher said an OpenClaw agent ran amok on her inbox\u00a0 | TechCrunch\",\"isPartOf\":{\"@id\":\"https:\/\/techcrunch.com\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\/\/techcrunch.com\/2026\/02\/23\/a-meta-ai-security-researcher-said-an-openclaw-agent-ran-amok-on-her-inbox\/#primaryimage\"},\"image\":{\"@id\":\"https:\/\/techcrunch.com\/2026\/02\/23\/a-meta-ai-security-researcher-said-an-openclaw-agent-ran-amok-on-her-inbox\/#primaryimage\"},\"thumbnailUrl\":\"https:\/\/techcrunch.com\/wp-content\/uploads\/2026\/02\/Y-Combinator-Crab.png\",\"datePublished\":\"2026-02-24T00:57:14+00:00\",\"dateModified\":\"2026-02-24T01:18:40+00:00\",\"description\":\"The viral X post from an AI security researcher reads like satire. But it's really a word of warning about what can go wrong when handing tasks to an AI agent.\",\"breadcrumb\":{\"@id\":\"https:\/\/techcrunch.com\/2026\/02\/23\/a-meta-ai-security-researcher-said-an-openclaw-agent-ran-amok-on-her-inbox\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\/\/techcrunch.com\/2026\/02\/23\/a-meta-ai-security-researcher-said-an-openclaw-agent-ran-amok-on-her-inbox\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\/\/techcrunch.com\/2026\/02\/23\/a-meta-ai-security-researcher-said-an-openclaw-agent-ran-amok-on-her-inbox\/#primaryimage\",\"url\":\"https:\/\/techcrunch.com\/wp-content\/uploads\/2026\/02\/Y-Combinator-Crab.png\",\"contentUrl\":\"https:\/\/techcrunch.com\/wp-content\/uploads\/2026\/02\/Y-Combinator-Crab.png\",\"width\":2878,\"height\":1988,\"caption\":\"Y Combinator crew dressed like crabs\"},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\/\/techcrunch.com\/2026\/02\/23\/a-meta-ai-security-researcher-said-an-openclaw-agent-ran-amok-on-her-inbox\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\/\/techcrunch.com\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"A Meta AI security researcher said an OpenClaw agent ran amok on her inbox\u00a0\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\/\/techcrunch.com\/#website\",\"url\":\"https:\/\/techcrunch.com\/\",\"name\":\"TechCrunch\",\"description\":\"Startup and Technology News\",\"publisher\":{\"@id\":\"https:\/\/techcrunch.com\/#organization\"},\"alternateName\":\"TC\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\/\/techcrunch.com\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\/\/techcrunch.com\/#organization\",\"name\":\"TechCrunch\",\"alternateName\":\"TC\",\"url\":\"https:\/\/techcrunch.com\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\/\/techcrunch.com\/#\/schema\/logo\/image\/\",\"url\":\"https:\/\/techcrunch.com\/wp-content\/uploads\/2018\/04\/tc-logo-2018-square-reverse2x.png?resize=1200,1200\",\"contentUrl\":\"https:\/\/techcrunch.com\/wp-content\/uploads\/2018\/04\/tc-logo-2018-square-reverse2x.png?resize=1200,1200\",\"width\":1200,\"height\":1200,\"caption\":\"TechCrunch\"},\"image\":{\"@id\":\"https:\/\/techcrunch.com\/#\/schema\/logo\/image\/\"},\"sameAs\":[\"https:\/\/www.facebook.com\/techcrunch\",\"https:\/\/x.com\/TechCrunch\",\"https:\/\/mstdn.social\/@TechCrunch\",\"https:\/\/bsky.app\/profile\/techcrunch.com\",\"https:\/\/www.threads.net\/@techcrunch\"]},{\"@type\":\"Person\",\"@id\":\"https:\/\/techcrunch.com\/#\/schema\/person\/6069415d0273765316aa1237c2434e09\",\"name\":\"Julie Bort\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\/\/techcrunch.com\/#\/schema\/person\/image\/e5dfb34c3f5bc3003785153e61a0f140\",\"url\":\"https:\/\/secure.gravatar.com\/avatar\/1786ddc5e2df8eea59cffdb78ba99931705b85dcc01517fdb94a7f43a4a25757?s=96&d=identicon&r=g\",\"contentUrl\":\"https:\/\/secure.gravatar.com\/avatar\/1786ddc5e2df8eea59cffdb78ba99931705b85dcc01517fdb94a7f43a4a25757?s=96&d=identicon&r=g\",\"caption\":\"Julie Bort\"},\"url\":\"https:\/\/techcrunch.com\/author\/julie-bort\/\"}]}<\/script>\n<!-- \/ Yoast SEO Premium plugin. -->","yoast_head_json":{"title":"A Meta AI security researcher said an OpenClaw agent ran amok on her inbox\u00a0 | TechCrunch","description":"The viral X post from an AI security researcher reads like satire. But it's really a word of warning about what can go wrong when handing tasks to an AI agent.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/techcrunch.com\/2026\/02\/23\/a-meta-ai-security-researcher-said-an-openclaw-agent-ran-amok-on-her-inbox\/","og_locale":"en_US","og_type":"article","og_title":"A Meta AI security researcher said an OpenClaw agent ran amok on her inbox\u00a0 | TechCrunch","og_description":"The viral X post from an AI security researcher reads like satire. But it's really a word of warning about what can go wrong when handing tasks to an AI agent.","og_url":"https:\/\/techcrunch.com\/2026\/02\/23\/a-meta-ai-security-researcher-said-an-openclaw-agent-ran-amok-on-her-inbox\/","og_site_name":"TechCrunch","article_publisher":"https:\/\/www.facebook.com\/techcrunch","article_published_time":"2026-02-24T00:57:14+00:00","article_modified_time":"2026-02-24T01:18:40+00:00","og_image":[{"width":1200,"height":829,"url":"https:\/\/techcrunch.com\/wp-content\/uploads\/2026\/02\/Y-Combinator-Crab.png?resize=1200,829","type":"image\/png"}],"author":"Julie Bort","twitter_card":"summary_large_image","twitter_creator":"@TechCrunch","twitter_site":"@TechCrunch","twitter_misc":{"Written by":"Julie Bort","Est. reading time":"3 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"NewsArticle","@id":"https:\/\/techcrunch.com\/2026\/02\/23\/a-meta-ai-security-researcher-said-an-openclaw-agent-ran-amok-on-her-inbox\/#article","isPartOf":{"@id":"https:\/\/techcrunch.com\/2026\/02\/23\/a-meta-ai-security-researcher-said-an-openclaw-agent-ran-amok-on-her-inbox\/"},"author":{"name":"Julie Bort","@id":"https:\/\/techcrunch.com\/#\/schema\/person\/6069415d0273765316aa1237c2434e09"},"headline":"A Meta AI security researcher said an OpenClaw agent ran amok on her inbox\u00a0","datePublished":"2026-02-24T00:57:14+00:00","dateModified":"2026-02-24T01:18:40+00:00","mainEntityOfPage":{"@id":"https:\/\/techcrunch.com\/2026\/02\/23\/a-meta-ai-security-researcher-said-an-openclaw-agent-ran-amok-on-her-inbox\/"},"wordCount":666,"publisher":{"@id":"https:\/\/techcrunch.com\/#organization"},"image":{"@id":"https:\/\/techcrunch.com\/2026\/02\/23\/a-meta-ai-security-researcher-said-an-openclaw-agent-ran-amok-on-her-inbox\/#primaryimage"},"thumbnailUrl":"https:\/\/techcrunch.com\/wp-content\/uploads\/2026\/02\/Y-Combinator-Crab.png","keywords":["meta ai","openclaw"],"articleSection":["AI","TC"],"inLanguage":"en-US","copyrightYear":"2026","copyrightHolder":{"@id":"https:\/\/techcrunch.com\/#organization"}},{"@type":"WebPage","@id":"https:\/\/techcrunch.com\/2026\/02\/23\/a-meta-ai-security-researcher-said-an-openclaw-agent-ran-amok-on-her-inbox\/","url":"https:\/\/techcrunch.com\/2026\/02\/23\/a-meta-ai-security-researcher-said-an-openclaw-agent-ran-amok-on-her-inbox\/","name":"A Meta AI security researcher said an OpenClaw agent ran amok on her inbox\u00a0 | TechCrunch","isPartOf":{"@id":"https:\/\/techcrunch.com\/#website"},"primaryImageOfPage":{"@id":"https:\/\/techcrunch.com\/2026\/02\/23\/a-meta-ai-security-researcher-said-an-openclaw-agent-ran-amok-on-her-inbox\/#primaryimage"},"image":{"@id":"https:\/\/techcrunch.com\/2026\/02\/23\/a-meta-ai-security-researcher-said-an-openclaw-agent-ran-amok-on-her-inbox\/#primaryimage"},"thumbnailUrl":"https:\/\/techcrunch.com\/wp-content\/uploads\/2026\/02\/Y-Combinator-Crab.png","datePublished":"2026-02-24T00:57:14+00:00","dateModified":"2026-02-24T01:18:40+00:00","description":"The viral X post from an AI security researcher reads like satire. But it's really a word of warning about what can go wrong when handing tasks to an AI agent.","breadcrumb":{"@id":"https:\/\/techcrunch.com\/2026\/02\/23\/a-meta-ai-security-researcher-said-an-openclaw-agent-ran-amok-on-her-inbox\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/techcrunch.com\/2026\/02\/23\/a-meta-ai-security-researcher-said-an-openclaw-agent-ran-amok-on-her-inbox\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/techcrunch.com\/2026\/02\/23\/a-meta-ai-security-researcher-said-an-openclaw-agent-ran-amok-on-her-inbox\/#primaryimage","url":"https:\/\/techcrunch.com\/wp-content\/uploads\/2026\/02\/Y-Combinator-Crab.png","contentUrl":"https:\/\/techcrunch.com\/wp-content\/uploads\/2026\/02\/Y-Combinator-Crab.png","width":2878,"height":1988,"caption":"Y Combinator crew dressed like crabs"},{"@type":"BreadcrumbList","@id":"https:\/\/techcrunch.com\/2026\/02\/23\/a-meta-ai-security-researcher-said-an-openclaw-agent-ran-amok-on-her-inbox\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/techcrunch.com\/"},{"@type":"ListItem","position":2,"name":"A Meta AI security researcher said an OpenClaw agent ran amok on her inbox\u00a0"}]},{"@type":"WebSite","@id":"https:\/\/techcrunch.com\/#website","url":"https:\/\/techcrunch.com\/","name":"TechCrunch","description":"Startup and Technology News","publisher":{"@id":"https:\/\/techcrunch.com\/#organization"},"alternateName":"TC","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/techcrunch.com\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/techcrunch.com\/#organization","name":"TechCrunch","alternateName":"TC","url":"https:\/\/techcrunch.com\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/techcrunch.com\/#\/schema\/logo\/image\/","url":"https:\/\/techcrunch.com\/wp-content\/uploads\/2018\/04\/tc-logo-2018-square-reverse2x.png?resize=1200,1200","contentUrl":"https:\/\/techcrunch.com\/wp-content\/uploads\/2018\/04\/tc-logo-2018-square-reverse2x.png?resize=1200,1200","width":1200,"height":1200,"caption":"TechCrunch"},"image":{"@id":"https:\/\/techcrunch.com\/#\/schema\/logo\/image\/"},"sameAs":["https:\/\/www.facebook.com\/techcrunch","https:\/\/x.com\/TechCrunch","https:\/\/mstdn.social\/@TechCrunch","https:\/\/bsky.app\/profile\/techcrunch.com","https:\/\/www.threads.net\/@techcrunch"]},{"@type":"Person","@id":"https:\/\/techcrunch.com\/#\/schema\/person\/6069415d0273765316aa1237c2434e09","name":"Julie Bort","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/techcrunch.com\/#\/schema\/person\/image\/e5dfb34c3f5bc3003785153e61a0f140","url":"https:\/\/secure.gravatar.com\/avatar\/1786ddc5e2df8eea59cffdb78ba99931705b85dcc01517fdb94a7f43a4a25757?s=96&d=identicon&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/1786ddc5e2df8eea59cffdb78ba99931705b85dcc01517fdb94a7f43a4a25757?s=96&d=identicon&r=g","caption":"Julie Bort"},"url":"https:\/\/techcrunch.com\/author\/julie-bort\/"}]}},"parsely":{"version":"1.1.0","canonical_url":"https:\/\/techcrunch.com\/2026\/02\/23\/a-meta-ai-security-researcher-said-an-openclaw-agent-ran-amok-on-her-inbox\/","smart_links":{"inbound":0,"outbound":0},"traffic_boost_suggestions_count":0,"meta":{"@context":"https:\/\/schema.org","@type":"NewsArticle","headline":"A Meta AI security researcher said an OpenClaw agent ran amok on her inbox\u00a0","url":"https:\/\/techcrunch.com\/2026\/02\/23\/a-meta-ai-security-researcher-said-an-openclaw-agent-ran-amok-on-her-inbox\/","mainEntityOfPage":{"@type":"WebPage","@id":"https:\/\/techcrunch.com\/2026\/02\/23\/a-meta-ai-security-researcher-said-an-openclaw-agent-ran-amok-on-her-inbox\/"},"thumbnailUrl":"https:\/\/techcrunch.com\/wp-content\/uploads\/2026\/02\/Y-Combinator-Crab.png?w=150","image":{"@type":"ImageObject","url":"https:\/\/techcrunch.com\/wp-content\/uploads\/2026\/02\/Y-Combinator-Crab.png"},"articleSection":"AI","author":[{"@type":"Person","name":"Julie Bort"}],"creator":["Julie Bort"],"publisher":{"@type":"Organization","name":"TechCrunch","logo":"https:\/\/techcrunch.com\/wp-content\/uploads\/2015\/02\/cropped-cropped-favicon-gradient.png"},"keywords":["meta ai","openclaw"],"dateCreated":"2026-02-24T00:57:14Z","datePublished":"2026-02-24T00:57:14Z","dateModified":"2026-02-24T01:18:40Z"},"rendered":"<meta name=\"parsely-title\" content=\"A Meta AI security researcher said an OpenClaw agent ran amok on her inbox\u00a0\" \/>\n<meta name=\"parsely-link\" content=\"https:\/\/techcrunch.com\/2026\/02\/23\/a-meta-ai-security-researcher-said-an-openclaw-agent-ran-amok-on-her-inbox\/\" \/>\n<meta name=\"parsely-type\" content=\"post\" \/>\n<meta name=\"parsely-image-url\" content=\"https:\/\/techcrunch.com\/wp-content\/uploads\/2026\/02\/Y-Combinator-Crab.png?w=150\" \/>\n<meta name=\"parsely-pub-date\" content=\"2026-02-24T00:57:14Z\" \/>\n<meta name=\"parsely-section\" content=\"AI\" \/>\n<meta name=\"parsely-tags\" content=\"meta ai,openclaw\" \/>\n<meta name=\"parsely-author\" content=\"Julie Bort\" \/>","tracker_url":"https:\/\/cdn.parsely.com\/keys\/techcrunch.com\/p.js"},"jetpack_featured_media_url":"https:\/\/techcrunch.com\/wp-content\/uploads\/2026\/02\/Y-Combinator-Crab.png","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/techcrunch.com\/wp-json\/wp\/v2\/posts\/3095915","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/techcrunch.com\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/techcrunch.com\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/techcrunch.com\/wp-json\/wp\/v2\/users\/133574633"}],"replies":[{"embeddable":true,"href":"https:\/\/techcrunch.com\/wp-json\/wp\/v2\/comments?post=3095915"}],"version-history":[{"count":26,"href":"https:\/\/techcrunch.com\/wp-json\/wp\/v2\/posts\/3095915\/revisions"}],"predecessor-version":[{"id":3095975,"href":"https:\/\/techcrunch.com\/wp-json\/wp\/v2\/posts\/3095915\/revisions\/3095975"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/techcrunch.com\/wp-json\/wp\/v2\/media\/3095916"}],"wp:attachment":[{"href":"https:\/\/techcrunch.com\/wp-json\/wp\/v2\/media?parent=3095915"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/techcrunch.com\/wp-json\/wp\/v2\/categories?post=3095915"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/techcrunch.com\/wp-json\/wp\/v2\/tags?post=3095915"},{"taxonomy":"tc_region","embeddable":true,"href":"https:\/\/techcrunch.com\/wp-json\/wp\/v2\/tc_region?post=3095915"},{"taxonomy":"tc_event","embeddable":true,"href":"https:\/\/techcrunch.com\/wp-json\/wp\/v2\/tc_event?post=3095915"},{"taxonomy":"tc_storyline_tax","embeddable":true,"href":"https:\/\/techcrunch.com\/wp-json\/wp\/v2\/tc_storyline_tax?post=3095915"},{"taxonomy":"author","embeddable":true,"href":"https:\/\/techcrunch.com\/wp-json\/wp\/v2\/coauthors?post=3095915"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}