By using this site, you agree to the Privacy Policy and Terms of Use.
Accept
World of SoftwareWorld of SoftwareWorld of Software
  • News
  • Software
  • Mobile
  • Computing
  • Gaming
  • Videos
  • More
    • Gadget
    • Web Stories
    • Trending
    • Press Release
Search
  • Privacy
  • Terms
  • Advertise
  • Contact
Copyright © All Rights Reserved. World of Software.
Reading: A Meta AI security researcher said an OpenClaw agent ran amok on her inbox  | News
Share
Sign In
Notification Show More
Font ResizerAa
World of SoftwareWorld of Software
Font ResizerAa
  • Software
  • Mobile
  • Computing
  • Gadget
  • Gaming
  • Videos
Search
  • News
  • Software
  • Mobile
  • Computing
  • Gaming
  • Videos
  • More
    • Gadget
    • Web Stories
    • Trending
    • Press Release
Have an existing account? Sign In
Follow US
  • Privacy
  • Terms
  • Advertise
  • Contact
Copyright © All Rights Reserved. World of Software.
World of Software > News > A Meta AI security researcher said an OpenClaw agent ran amok on her inbox  | News
News

A Meta AI security researcher said an OpenClaw agent ran amok on her inbox  | News

News Room
Last updated: 2026/02/23 at 8:23 PM
News Room Published 23 February 2026
Share
A Meta AI security researcher said an OpenClaw agent ran amok on her inbox  |  News
SHARE

The now-viral X post from Meta AI security researcher Summer Yue reads, at first, like satire. She told her OpenClaw AI agent to check her overstuffed email inbox and suggest what to delete or archive.  

The agent proceeded to run amok. It started deleting all her email in a “speed run” while ignoring her commands from her phone telling it to stop. 

“I had to RUN to my Mac mini like I was defusing a bomb,” she wrote, posting images of the ignored stop prompts as receipts.  

The Mac Mini, an affordable Apple computer that sits flat on a desk and fits in the palm of your hand, has become the favored device these days for running OpenClaw. (The Mini is selling “like hotcakes,” one “confused” Apple employee apparently told famed AI researcher Andrej Karpathy when he bought one to run an OpenClaw alternative called NanoClaw.) 

OpenClaw is, of course, the open source AI agent that achieved fame through Moltbook, an AI-only social network. OpenClaw agents were at the center of that now largely debunked episode on Moltbook in which it looked like the AIs were plotting against humans.  

But OpenClaw’s mission, according to its GitHub page, is not focused on social networks. It aims to be a personal AI assistant that runs on your own devices.  

The Silicon Valley in-crowd has fallen so in love with OpenClaw that “claw” and “claws” have become the buzzwords of choice for agents that run on personal hardware. Other such agents include ZeroClaw, IronClaw, and PicoClaw. Y Combinator’s podcast team even appeared on their most recent episode dressed in lobster costumes. 

Techcrunch event

Boston, MA
|
June 9, 2026

But Yue’s post serves as a warning. As others on X noted, if an AI security researcher could run into this problem, what hope do mere mortals have? 

“Were you intentionally testing its guardrails or did you make a rookie mistake?” a software developer asked her on X.  

“Rookie mistake tbh,” she replied. She had been testing her agent with a smaller “toy” inbox, as she called it, and it had been running well on less important email. It had earned her trust, so she thought she’d let it loose on the real thing. 

Yue believes that the large amount of data in her real inbox “triggered compaction,” she wrote. Compaction happens when the context window — the running record of everything the AI has been told and has done in a session — grows too large, causing the agent to begin summarizing, compressing, and managing the conversation.  

At that point, the AI may skip over instructions that the human considers quite important.  

In this case, it may have skipped her last prompt — where she told it not to act — and reverted back to its instructions from the “toy” inbox. 

As several others on X pointed out, prompts can’t be trusted to act as security guardrails. Models may misconstrue or ignore them. 

Various people offered suggestions that ranged from the exact syntax Yue should have used to stop the agent, to various methods to ensure better adherence to guardrails, like writing instructions to dedicated files or using other open source tools. 

In the interest of full transparency, News could not independently verify what happened to Yue’s inbox. (She didn’t respond to our request for comment, though she did respond to many questions and comments sent her way on X.) 

But it doesn’t really matter. 

The point of the tale is that agents aimed at knowledge workers, at their current stage of development, are risky. People who say they are using them successfully are cobbling together methods to protect themselves.

One day, perhaps soon (by 2027? 2028?), they may be ready for widespread use. Goodness knows many of us would love help with email, grocery orders, and scheduling dentist appointments. But that day has not yet come. 

Sign Up For Daily Newsletter

Be keep up! Get the latest breaking news delivered straight to your inbox.
By signing up, you agree to our Terms of Use and acknowledge the data practices in our Privacy Policy. You may unsubscribe at any time.
Share This Article
Facebook Twitter Email Print
Share
What do you think?
Love0
Sad0
Happy0
Sleepy0
Angry0
Dead0
Wink0
Previous Article Anthropic Alleges DeepSeek, MiniMax Trained Models With Claude Anthropic Alleges DeepSeek, MiniMax Trained Models With Claude
Next Article 5 Ways To Protect Your Privacy On An Amazon Fire TV Stick – BGR 5 Ways To Protect Your Privacy On An Amazon Fire TV Stick – BGR
Leave a comment

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Stay Connected

248.1k Like
69.1k Follow
134k Pin
54.3k Follow

Latest News

Brazil’s competition watchdog inquires Apple over iPhone NFC restrictions – 9to5Mac
Brazil’s competition watchdog inquires Apple over iPhone NFC restrictions – 9to5Mac
News
Fresh Deals on Apple Products at Best Buy: Take 0 Off an iPad Mini
Fresh Deals on Apple Products at Best Buy: Take $100 Off an iPad Mini
News
BMW to achieve 100% green charging with China’s State Grid by 2027 · TechNode
BMW to achieve 100% green charging with China’s State Grid by 2027 · TechNode
Computing
vssusnQushhnnSHghGGSv30@20g/Gn226g/SvnnnunsusfUnnj
News

You Might also Like

Brazil’s competition watchdog inquires Apple over iPhone NFC restrictions – 9to5Mac
News

Brazil’s competition watchdog inquires Apple over iPhone NFC restrictions – 9to5Mac

3 Min Read
Fresh Deals on Apple Products at Best Buy: Take 0 Off an iPad Mini
News

Fresh Deals on Apple Products at Best Buy: Take $100 Off an iPad Mini

7 Min Read

vssusnQushhnnSHghGGSv30@20g/Gn226g/SvnnnunsusfUnnj

0 Min Read
Meta’s VR Metaverse takes one more step into the grave
News

Meta’s VR Metaverse takes one more step into the grave

3 Min Read
//

World of Software is your one-stop website for the latest tech news and updates, follow us now to get the news that matters to you.

Quick Link

  • Privacy Policy
  • Terms of use
  • Advertise
  • Contact

Topics

  • Computing
  • Software
  • Press Release
  • Trending

Sign Up for Our Newsletter

Subscribe to our newsletter to get our newest articles instantly!

World of SoftwareWorld of Software
Follow US
Copyright © All Rights Reserved. World of Software.
Welcome Back!

Sign in to your account

Lost your password?