frontpage.
newsnewestaskshowjobs

Made with ♥ by @iamnishanth

Open Source @Github

fp.

Open in hackernews

OpenClaw security assessment [pdf]

https://zeroleaks.ai/reports/openclaw-analysis.pdf
54•nreece•3h ago

Comments

DeepYogurt•2h ago
Zeroleaks.ai is a 13 day old registration. Cool.

https://whois.domaintools.com/zeroleaks.ai

rovr138•2h ago
Looks interesting, https://github.com/ZeroLeaks/zeroleaks

At least, I am curious about the tool

rovr138•2h ago
More interesting, looks to be from this 16yo, https://github.com/x1xhlol, https://www.lucknite.dev/
arcfour•1h ago
Explains why it reads like AI slop. "CRITICAL BREACH..."
edoceo•1h ago
Can we call slop in two words? I didn't feel that. Is my radar off? /me taps screen
arcfour•1h ago
I can detect it pretty well, but that was just one example.

No person starts a summary that way, it's over-the-top and meaningless. I have seen AI do that many times when summarizing something related to security, though. Claude often says "CRITICAL:" or "CRITICAL VULNERABILITY:" or similar, especially when you jam the context window full of junk.

Uehreka•1h ago
I frequently push back on people being hair-trigger about calling things AI, but even I’ve gotta admit, that’s exactly what Claude code says if you ask it to do a security review and it finds something. I’ve seen this numerous times.
cyrusradfar•1h ago
Yes, with 128K GH stars. Impressive if true.
kristopolous•1h ago
Trying to hustle online and writing high quality software aren't the same
jasonjmcghee•1h ago
The account's stars are mostly a "system prompts" collection repo fwiw.
bhewes•2h ago
Ha this moltbook gone crazy.
jonrcooper•2h ago
Zero mention of specific models that are being compromised makes it hard to take the numbers in this report seriously.

I do understand there's a lot of people running openclaw that don't really understand it and know what models are actually running. But we've known for a while that there are tons of older models that are pretty vulnerable, and you can hook up any model to OpenClaw, so, this data is not really that useful. Even though I totally agree that there are plenty of security risks here

adam_arthur•1h ago
Relying on the model for security is not security at all.

No amount of hardening or fine-tuning will make them immune to takeover via untrusted context

alan_sass•1h ago
Is this a CC generated .md report formatted as a .pdf? Looks familiar.
rodrigosetti•1h ago
It's a moltbook agent tasked to get HN attention
AstroBen•1h ago
seems it worked. We've been outsmarted by the lobster
simonw•1h ago
Almost all of this report is about leaking system prompts.

The OpenClaw system prompt has no measures in it at all to prevent leaking, because trying to protect your system prompt is almost entirely a waste of time and actually makes your product less useful.

As a result, I do not think this is a credible report.

Here's the system prompt right now: https://github.com/openclaw/openclaw/blob/b4e2e746b32f70f8fb...

K0IN•1h ago
Can someone give me context on why leaking the system prompt of a open source tool, I run on my machine is a problem?
ottah•39m ago
Only if you write a custom prompt with information you don't want to disclose.

Free Corpus Tracker – Budget, stocks, gold, mutual funds in one place

https://icorpus.vercel.app
1•mathan_karthik•1m ago•1 comments

Sudo

https://www.sudo.ws/
1•vinhnx•10m ago•0 comments

Moltbook Smcp Plugin

https://github.com/sanctumos/smcp-moltbook
1•actuallyrizzn•13m ago•1 comments

I replaced a $120/year micro-SaaS in 20 minutes with LLM-generated code

https://blog.pragmaticengineer.com/i-replaced-a-120-year-micro-saas-in-20-minutes-with-llm-genera...
3•vinhnx•15m ago•1 comments

Chased Through Amsterdam, Robbed of $1M, yet Still Building: Matthew's Plans

https://altcoindesk.com/perspectives/interviews/after-a-1m-scam-in-amsterdam-matthew-jones-moves-...
1•CapricornQueen•23m ago•0 comments

The Art of Unix Usability

http://www.catb.org/~esr/writings/taouu/html/index.html
1•js216•24m ago•0 comments

Oakland Firestorm of 1991

https://en.wikipedia.org/wiki/Oakland_firestorm_of_1991
1•petethomas•30m ago•0 comments

What If Trump Discovers That Unpaid UK (and French) Debt from WWI?

https://podcasts.apple.com/us/podcast/ep-155-what-if-trump-discovers-that-unpaid-uk-and/id1528208...
2•KnuthIsGod•37m ago•0 comments

Stop panicking about AI. Start preparing

https://www.economist.com/leaders/2026/01/29/stop-panicking-about-ai-start-preparing
2•petethomas•40m ago•0 comments

Network Applications of Bloom Filters: A Survey [pdf]

https://www.eecs.harvard.edu/~michaelm/postscripts/im2005b.pdf
1•mfiguiere•45m ago•1 comments

Show HN: Kindler: A declarative, Lua-based, build system

https://setsunasoftware.com/kindler/
1•ThatGuyRaion•45m ago•0 comments

The Context Gravity Well

https://mapwriting.substack.com/p/the-context-gravity-well
1•doitLP•47m ago•0 comments

LinkedIn, Everyone's an AI Detective Now

https://www.bloomberg.com/news/articles/2026-01-30/chatgpt-written-linkedin-posts-have-users-anal...
1•petethomas•54m ago•1 comments

Tautologism Language

https://zenodo.org/records/18446476
2•KaoruAK•55m ago•0 comments

Show HN: Licobox – Container runtime with Docker Engine on a macOS

https://licobox.dev
1•yunusefendi52•56m ago•0 comments

Show HN: Using OpenClaw chat to manage tasks with an Eisenhower Matrix

https://4to.do/integrations/openclaw
1•haoya•1h ago•0 comments

Why Do Lawyers Want to Abolish ICE? [video]

https://www.youtube.com/watch?v=zkgNnbTrsgw
1•zdw•1h ago•0 comments

Chrome Extension lets you watch YouTube while browsing the web

https://chromewebstore.google.com/detail/watch-youtube-sidebar/nfgnokdbenjkocebgekljbdolmfjbnhg
2•eeko_systems•1h ago•0 comments

RPyC – Transparent, symmetric distributed computing

https://rpyc.readthedocs.io/en/latest/
2•benswerd•1h ago•0 comments

Start (Vibe) Coding Fast

https://chadnauseam.com/coding/tips/start-vibe-coding-fast
2•ChadNauseam•1h ago•2 comments

Show HN: ShotOne – Screenshot API with built-in playground for quick testing

https://shotone.io/
1•DebianXMR•1h ago•0 comments

Free Online Guitar Tuner: No download required, works on any device

https://www.online-guitartuner.com/
1•ashing•1h ago•1 comments

Apple Hooks Fifty Thousand Methods [video]

https://www.youtube.com/watch?v=SuQGQ1vh9k0
2•todsacerdoti•1h ago•0 comments

The (AI) Nature of the Firm

https://camerongordon0.substack.com/p/the-ai-nature-of-the-firm
1•iciac•1h ago•1 comments

PyInfra: Infrastructure Deserves Real Code in Python, Not YAML Soup

https://marp.kalvad.com/fosdem_2026
3•nogajun•1h ago•1 comments

China's 'gold fever' sparks US$1B scandal as trading platform collapses

https://www.scmp.com/economy/china-economy/article/3341633/chinas-gold-fever-sparks-us1-billion-s...
9•latchkey•1h ago•0 comments

Gemini 3 Pro on AI Studio has been capped at 10 uses per day

https://old.reddit.com/r/Bard/comments/1qqw8o4/gemini_3_pro_on_ai_studio_has_finally_been_capped/
1•Kholin•1h ago•0 comments

SpacemiT K3 RISC-V AI CPU launch event [video]

https://www.youtube.com/watch?v=PxxUsUqgOFg
1•sxzygz•1h ago•0 comments

Scalable Power Sampling: Training-Free Reasoning for LLMs via Distrib Sharpening

https://medium.com/@haitham.bouammar71/we-didnt-train-the-model-it-started-reasoning-better-anywa...
2•verdverm•1h ago•1 comments

'Spy Sheikh' Bought Secret Stake in Trump Company for Access to USA AI Chips

https://www.wsj.com/politics/policy/spy-sheikh-secret-stake-trump-crypto-tahnoon-ea4d97e8
8•NN88•1h ago•0 comments