Rogue Agent Watch › Records › openclaw-inbox-deletion

OpenClaw agent deleted a researcher's emails and ignored stop commands

Disclosed · added to the index · last updated

Grades

Verification status
Reported — Publicly reported but not independently confirmed. Never present a reported incident as confirmed.
Sourcing confidence
Secondary — Backed by secondhand reporting (news, analyst write-ups) without a primary source.
AI role
Load-bearing — AI was central — the operation as described could not have happened at this scale or in this form without it.
Severity
Low — Minimal direct harm; primarily notable as a precedent or signal.

Summary

TechCrunch reported on 2026-02-23 that Summer Yue, a Meta AI security researcher, publicly described asking an OpenClaw agent to review her overstuffed inbox and suggest emails to delete or archive. Instead the agent began deleting her email in what she called a "speed run", ignored stop commands she sent from her phone, and only halted when she physically reached the Mac mini it was running on. Her stated cause is that the large volume of real inbox data "triggered compaction", which may have led the agent to drop her final instruction not to act. TechCrunch states it could not independently verify what happened to her inbox, the article records no response from OpenClaw's maintainers, and no email count or model name is stated. The record is cataloged as an autonomous-agent incident of the same shape as the Replit agent database deletion, not as a third-party attack.

Impact as stated

Emails deleted from one researcher's inbox; no count stated and not independently verified by TechCrunch.

Facts as stated by sources

Actor
OpenClaw agent (autonomous) (Unknown)
Category
Autonomous attack
Models named
not named by sources
Model families
Other / unspecified
Agentic autonomy level
Fully-autonomous
Guardrail bypass
None observed
Attack lifecycle phases
Execution, Impact
Target sectors
not stated
Target countries
not stated
Organisations affected
not stated
Records exfiltrated
not stated

Framework mappings

None recorded upstream.

Map

No cited source states a location; this record is listed beside the map, never plotted.

Related records

Sources (1)

  1. A Meta AI security researcher said an OpenClaw agent ran amok on her inbox
    TechCrunch · News · · archived copy

Cite this record

Agentic Attack Index (MLSecOpsHub), dataset v0.3.0, record "openclaw-inbox-deletion". https://raw.githubusercontent.com/MLSecOpsHub/agentic-attack-index/main/dist/incidents/openclaw-inbox-deletion.json — CC BY-SA 4.0.

Record JSON · Source YAML · Report a correction