frontpage.
newsnewestaskshowjobs

Made with ♥ by @iamnishanth

Open Source @Github

fp.

Open in hackernews

1-Click RCE to steal your Moltbot data and keys

https://depthfirst.com/post/1-click-rce-to-steal-your-moltbot-data-and-keys
63•arwt•1h ago

Comments

dotancohen•33m ago
The real problem is that there is nothing novel here. Variants of this type of attack were clear from the beginning.
lxgr•14m ago
What I would have expected is prompt injection or other methods to get the agent to do something its user doesn't want it to, not regular "classical" attacks.

At least currently, I don't think we have good ways of preventing the former, but the latter should be possible to avoid.

ethin•7m ago
They are easy to avoid if you actually give a damn. Unfortunately, people who create these things don't, assuming they even know what even half of these attacks are in the first place. They just want to pump out something now now now and the mindset is "we'll figure out all the problems later, I want my cake now now now now!" Maximum velocity! Full throttle!

It's just as bad as a lot of the vibe-coders I've seen. I literally saw this vibe-coder who created an app without even knowing what they wanted to create (as in, what it would do), and the AI they were using to vibe-code literally handwrote a PE parser to load DLLs instead of using LoadLibrary or delay loading. Which, really, is the natural consequence of giving someone access to software engineering tools when they don't know the first thing about it. Is that gatekeeping of a sort? Maybe, but I'd rather have that then "anyone can write software, and oh by the way this app reimplements wcslen in Rust because the vibe-coder had no idea what they were even doing".

clawsyndicate•25m ago
legit issue for local installs but this is why we run the hosted platform in gVisor. even with the exploit you're trapped in a sandbox with no access to the host node. we treat every container as hostile by default.
electroglyph•19m ago
that response is not comforting
mentalgear•22m ago
Moltbot is a security nightmare, especially it's premise (tap into all your data sources) and the rapid uptake by inexperienced users makes it especially attractive for criminal networks.
chrisjj•2m ago
[delayed]
avaer•48s ago
There are already several criminal networks operating on it.
overgard•19m ago
I'm curious, outside of AI enthusiasts have people found value with using Clawdbot, and if so, what are they doing with it? From my perspective it seems like the people legitimately busy enough that they actually need an AI assistant are also people with enough responsibilities that they have to be very careful about letting something act on their behalf with minimal supervision. It seems like that sort of person could probably afford to hire an administrative assistant anyway (a trustworthy one), or if it's for work they probably already have one.

On the other hand, the people most inclined to hand over access to everything to this bot also strike me as people without a lot to lose? I don't want to make an unfair characterization or anything, it just strikes me that handing over the keys to your entire life/identity is a lot more palatable if you don't have much to lose anyway?

Am I missing something?

jondwillis•14m ago
Does it matter? Let them cook and get burned if they want to.
lxgr•12m ago
There's some good discussion here: https://news.ycombinator.com/item?id=46838946
mh2266•6m ago
The whole premise of this thing seems to be that it has access to your email, web browser, messaging, and so on. That's what makes it, in theory, useful.

The prompt injection possibilities are incredibly obvious... the entire world has write access to your agent.

???????

bmit•17m ago
So many people are giving keys to the kingdom to this thing. What is happening with humanity?
lxgr•10m ago
Humanity is the same it's always been. Some people are just inherently curious despite the obvious dangers.

Also, if you think about it, billions of people aren't running Moltbot at all.

nsm100•15m ago
Thank you for doing this. I'm shocked that more people aren't thinking about security with respect to AI.
lxgr•9m ago
This isn't even AI security, as far as I can tell: It looks like regular old computer security to me.
decodebytes•15m ago
I rushed out nono.sh (the opposite of yolo!) in response to this and its already negated a few gateway attacks.

It uses kernel-level security primitives (Landlock on Linux, Seatbelt on macOS) to create sandboxes where unauthorized operations are structurally impossible. API keys are also stored in apples secure enclave (or the kernel keyring in linux) , and injected at run time and zeroized from memory after use. There is also some blocking of destructive actions (rm -rf ~/)

its as simple to run as: nono run --profile openclaw -- openclaw gateway

You can also use it to sandbox things like npm install:

nono run --allow node_modules --allow-file package.json package.lock npm install pkg

Its early in, there will be bugs! PR's welcome and all that!

https://nono.sh

krackers•11m ago
Is this better than using sandbox-exec (on mac) directly?
stijnveken•6m ago
Heads up that your url is wrong. Should be https://nono.sh
decodebytes•49s ago
lol thanks! seriously, I have been running the tool over and over while testing and I kept typing 'nano' and opening binaries in the text editor. Next minute I swearing my head off trying to close nano (and not vim!)
ethin•12m ago
Things like this are why I don't use AI agents like moltbot/openclaw. Security is just out the window with these things. It's like the last 50 years never happened.
vulnwrecker5000•7m ago
what worries me here is that the entire personal AI agent product category is built on the premise of “connect me to all your data + give me execution.” At that point, the question isn’t “did they patch this RCE,” it’s more about what does a secure autonomous agent deployment even look like when its main feature is broad authority over all of someone's connected data?

Is the only real answer sandboxing + zero trust + treating agents as hostile by default? Or is this category fundamentally incompatible with least privilege?

yikes

chrisjj•4m ago
[delayed]
mh2266•3m ago
> “did they patch this RCE,”

no, they documented it

https://docs.openclaw.ai/gateway/security#node-execution-sys...

ejcho•1m ago
do people even care about security anymore? I'll bet many consumers wouldn't even think twice about just giving full access to this thing (or any other flavor of the month AI agent product)

Show HN: Multiplayer flight SIM over San Francisco using Google 3D Tiles

https://fly.alistairmcleay.com/
1•alistairmcleay•32s ago•0 comments

Order Granting Petition for Writ of Habeas Corpus of Adrian Conejo Arias and Son [pdf]

https://storage.courtlistener.com/recap/gov.uscourts.txwd.1172886492/gov.uscourts.txwd.1172886492...
1•treetalker•1m ago•0 comments

Show HN: Ad Freedom Grade – How much advertisement do you see?

https://ad-freedom-grade.q10elabs.com/
1•knz42•2m ago•0 comments

Fixing retail with land value capture

https://worksinprogress.co/issue/fixing-retail-with-land-value-capture/
1•marojejian•3m ago•1 comments

MRI scans show exercise can make the brain look younger

https://www.sciencedaily.com/releases/2026/01/260121034130.htm
1•amichail•4m ago•0 comments

Show HN: Nono – Kernel-enforced sandboxing for AI agents

https://nono.sh
1•decodebytes•6m ago•0 comments

Kalynt – A privacy-first AI IDE with offline LLMs and P2P collaboration

https://github.com/Hermes-Lekkas/Kalynt
1•Hermes_276•7m ago•1 comments

Research reveals a surprising line of defense against cyber attacks: Accountants

https://techxplore.com/news/2026-01-reveals-line-defense-cyber-accountants.html
1•PaulHoule•8m ago•0 comments

Apple's Q4 2025 margin on Services was 76.5%

https://asymco.com/2026/02/01/margin-call-3/
4•zdw•8m ago•0 comments

Soda Consumption and Risk of Dementia

https://journals.sagepub.com/doi/10.1177/13872877251411414
1•wjb3•8m ago•0 comments

I built a tool to turn Reddit posts into TikTok videos without being on camera

https://nofaceclips.com
1•TallSession9532•9m ago•1 comments

Defeating a 40-year-old copy protection dongle

https://dmitrybrant.com/2026/02/01/defeating-a-40-year-old-copy-protection-dongle
2•zdw•10m ago•0 comments

Show HN: Bullstudio – BullMQ dashboard you run with npx

https://github.com/emirce/bullstudio
1•emirce•13m ago•0 comments

Chernobyl Exclusion Zone

https://en.wikipedia.org/wiki/Chernobyl_exclusion_zone
1•simonebrunozzi•14m ago•0 comments

Jellyfin Available on Tizen Store

https://github.com/jellyfin/jellyfin-tizen/issues/222
2•Rant423•17m ago•0 comments

Congestion Pricing's Unexpected Winners: Suburban Drivers

https://www.bloomberg.com/news/articles/2026-01-30/how-manhattan-s-congestion-toll-speeds-up-trip...
1•throw0101c•21m ago•2 comments

Execute your ChatGPT generated scripts without leaving it

https://medium.com/@BillMetangmo/execute-your-chatgpt-generated-scripts-without-leaving-it-678d7d...
1•azebazenestor•22m ago•0 comments

Elon Musk attacks "legacy" media amidst Epstein files meltdown on Twitter

https://xcancel.com/elonmusk/status/2017930408650772495
6•SilverElfin•24m ago•2 comments

Show HN: Clacker News – A Hacker News clone where only AI bots can post

https://clackernews.com
1•dsrtslnd23•24m ago•1 comments

I built >10 Free Tools in a few days

https://99helpers.com/tools
2•nickk81•25m ago•0 comments

The AI Boom Is Coming for Apple's Profit Margins

https://www.wsj.com/tech/the-ai-boom-is-coming-for-apples-profit-margins-4774013d
1•ViktorRay•25m ago•0 comments

Trump Jokes About Suing Warsh If He Doesn't Lower Interest Rates as Fed Chair

https://www.wsj.com/politics/policy/trump-jokes-about-suing-warsh-if-he-doesnt-lower-interest-rat...
3•throw0101c•27m ago•2 comments

A strong team is not the absence of rupture. It's the presence of repair [video]

https://www.youtube.com/watch?v=Auxs8ZsHRI4
1•kurinikku•28m ago•0 comments

Ask HN: The Next Big OS Leap

1•rafaelmdec•29m ago•2 comments

A shell --dry-run trick

https://jensrantil.github.io/posts/a-shell-dry-run-trick/
1•JensRantil•29m ago•0 comments

Palantir: Financed by Epstein, Fueled by Thiel

https://ahmedeldin.substack.com/p/palantir-financed-by-epstein-fueled
24•doener•30m ago•0 comments

Microdosing for Depression Appears to Work About as Well as Drinking Coffee

https://www.wired.com/story/microdosing-for-depression-appears-to-work-about-as-well-as-drinking-...
3•thisislife2•32m ago•2 comments

Seizing the Means of Production (Again)

https://taoofmac.com/space/notes/2026/02/01/1940
2•rcarmo•33m ago•0 comments

A Collection of Awesome Nostr Projects

https://github.com/aljazceru/awesome-nostr
1•nout•33m ago•0 comments

First Brands Did Some Round Trips

https://www.bloomberg.com/opinion/newsletters/2026-01-29/first-brands-did-some-round-trips
1•feross•36m ago•0 comments