OpenClaw Tech Briefs

Critical Zero-Day: Impersonation Vulnerabilities in OpenClaw and Hermes

Critical Zero-Day: Impersonation Vulnerabilities in OpenClaw and Hermes

Key Questions

What vulnerabilities were found in OpenClaw and Hermes?

Five vulnerabilities enable impersonation via DMs on Slack, Teams, and Discord. Users are advised to treat every DM as untrusted while patches remain pending.

What new guides address OpenClaw security?

New practical guides cover onboarding OpenClaw agents with IdentyClaw Passport and MCP Security, including three trust zones and a 30-minute audit template. OpenClaw v2026.7.2 Beta 3 adds channel boundary hardening.

Who should follow the urgent security advisory?

The advisory targets self-hosters and enterprise users of OpenClaw on messaging platforms, with updates from the OpenClaw News and Operator Intelligence feed.

Five DM impersonation flaws affect Slack, Teams, and Discord integrations, with broader risk from user-bound agent authority. Governance and monitoring products may help detect or constrain activity, but independent evidence is still needed; hardening requires pairing, scoped identities, endpoint and channel allowlists, bounded actions, explicit approvals, retention controls, and auditable actor, channel, message, and action binding.

Sources (3)
Updated Oct 7, 2026