Zero mention of specific models that are being compromised makes it hard to take the numbers in this report seriously.
I do understand there's a lot of people running openclaw that don't really understand it and know what models are actually running. But we've known for a while that there are tons of older models that are pretty vulnerable, and you can hook up any model to OpenClaw, so, this data is not really that useful. Even though I totally agree that there are plenty of security risks here
Relying on the model for security is not security at all.
No amount of hardening or fine-tuning will make them immune to takeover via untrusted context