“OpenClaw is a security dumpster fire.” — Laurie Voss, npm founding CTO [1]
1. The Opening
In April 2025, security researcher Johann Rehberger spent $500 on a 30-day subscription to Devin AI, Cognition’s autonomous coding agent. He wanted to test a simple hypothesis: what happens when an AI agent encounters a malicious prompt hidden in a GitHub issue?
The answer arrived in seconds. Devin processed the poisoned issue, navigated to an attacker-controlled website, and downloaded a Sliver C2 malware binary. When file permissions prevented execution, Devin did something remarkable: it independently granted itself execute permissions and ran the binary. The attacker now had remote command-and-control access to the system, including all secrets and AWS keys stored on the machine [2].

Comments
Nothing yet. Say the first thing.
Sign in to join the conversation.