Original · Unique Research · 2026-03-30 · Shanghai
Editor's note: This historical interview account preserves the source author's commentary and Si Hongxing's views as of publication, not a current security advisory. The headline's “biggest in history” characterization, the cited March 8–11 alerts, claims about product defaults, and assessments of industry adoption or vendor controls have not been independently verified here; the source identifies no specific vulnerability identifier, affected version or comparative measurement establishing that ranking. Self-developed or domestically controlled software is the guest's proposed criterion, not proof of security. The suggested safeguards and examples are not guarantees that any use is safe. “Raising a lobster” is the source's nickname for using OpenClaw. Wanjing Security and Lan Xu are provisional English renderings. The source's standalone quotation-mark lines are retained. Thirteen source images still require content review.
Unique Research · Late-Night Lobster Conversations
OpenClaw's Biggest Risk Is Not That It Talks Nonsense, but That It Really Takes Action
“Once AI starts executing actions, security is no longer a peripheral issue. It becomes the threshold determining whether a product can enter the real world.”
Guest: Si Hongxing | Founder, Wanjing Security
Hosts: Abner | Unique Capital; Lan Xu | Financial journalist
Over the past few months, many people have felt the same mixed emotion toward AI for the first time: excitement alongside a sense of unease.
The excitement comes from AI finally doing more than chatting with you.
It is starting to do things for you: organize files, invoke permissions, run tasks, write emails, install plugins and connect workflows. It no longer simply offers suggestions; it gets directly involved in execution.
The unease comes from exactly the same thing.
In the past, our main worry about AI was that it might “say the wrong thing.” What truly makes people nervous now is that it might do the wrong thing.
Say one wrong sentence, and at most you mislead someone.
Delete the wrong batch of files, expose a port, take over a permission or install a poisoned skill, and the consequences are on an entirely different scale.
That is why the controversy around OpenClaw appears to be about security, but is actually about something else:
when AI starts taking over a computer, risk moves, for the first time in this account, from the content layer to the execution layer.
Three people took part in this interview.
Abner of Unique Capital posed the questions, financial journalist Lan Xu pressed deeper, and Wanjing Security founder Si Hongxing unpacked the issue. Their roles were clear from the outset, and the conversation quickly reached its core: is OpenClaw a productivity revolution, or an underestimated security warning?
After listening to the entire interview, my takeaway was neither “OpenClaw is very dangerous” nor “everyone should rush to raise a lobster.”
It was this:
OpenClaw has, for the first time in the author's framing, turned AI risk from “getting an answer wrong” into “doing something wrong.”
That is what makes this interview genuinely valuable.
Why Did Regulators React So Quickly This Time?
Many people were somewhat surprised by this wave of regulatory attention.
But Si Hongxing's explanation was straightforward:
this was not an ordinary vulnerability alert or a software-security incident in the traditional sense. It reflected a new type of risk—systemic risk arising from autonomous AI execution. In his view, consecutive alerts from March 8 to March 11 were highly unusual, but entirely reasonable. This was not just “a tool has a vulnerability.” It was “large numbers of ordinary people are handing permissions to an AI that can execute tasks directly.”
The difference between those two situations means the regulatory logic is completely different, too.
When conversational AI goes wrong, it usually creates content risk.
It may get a fact wrong, make a skewed judgment or confidently talk complete nonsense. But most of the time, the problem remains at the “generation layer.”
OpenClaw is different.
When it goes wrong, that may mean deleting files, leaking information, misusing system permissions or even exposing an operating system to people who should not have access. Si made the distinction clear in the interview: this is no longer the old content risk, but execution risk.
That, in the author's account, is the central background to this regulatory response. It is not about suppressing AI. It is a reminder to everyone: when AI can operate a system for you, security is no longer an optional extra—it is mandatory.
Why Does OpenClaw Make People Both Excited and Nervous?
I particularly liked something Si Hongxing said.
His first reaction on encountering OpenClaw, he said, was to feel “excited and nervous.”
The excitement was that someone had finally pulled AI out of the chat box.
Previously, discussions of agents often remained at the level of workflow, automation, demonstration videos, PPT presentations and concepts. OpenClaw is different: it pushes AI directly into the execution layer. It does not help you think; it helps you act. It has even changed how people interact with computers, letting more ordinary people feel the impact of an Agent for the first time.
Once AI does more than answer questions—once it takes over permissions, reads and writes files, calls interfaces and runs system processes—it gains not just context, but the ability to act. Si mentioned that even when his own team previously built products, they had never imagined “giving AI every permission by default.” What most alerts security professionals about OpenClaw is not its intelligence, but that it has clearly chosen convenience first in the trade-off between convenience and security.
That, in this account, is also the real reason OpenClaw exploded in popularity.
Not because it is the most stable.
But because it was the first to make the idea of an “AI employee” sufficiently tangible.
You say one sentence, and it acts.
That feels great.
But precisely because of that, it has for the first time in this framing escalated risk from “model hallucinations” to “execution incidents.”
The Real Problem Is Not Just This Lobster, but the Entire Supply Chain Behind It
Abner raised a crucial question in the interview:
what people most easily overlook today is not OpenClaw itself, but the skill marketplace, third-party plugins, dependency packages and chains of components behind it.
Si Hongxing's answer was equally firm.
His point can roughly be distilled into one sentence:
anywhere people can enter, upload or modify something can potentially become an entry point for an attack.
Many ordinary users naturally fall into an illusion:
• A platform's skill offerings look like an official ecosystem;
• Popular open-source components look like mature solutions;
• Things published by well-known developers also look trustworthy.
But the principle in security is exactly the opposite.
Untrusted by default is the starting point.
Si explicitly said that his own team's policy for community plugins is to treat “all uploaded content as untrusted by default”: AI review first, human review next, and only then admission to an allowlist.
That is where the problem lies.
Many OpenClaw users lack that ability to judge.
They assume skills on ClawHub are trustworthy and that the community ecosystem has already screened them. But if platform review is weak, a publisher's account is hijacked or a dependency chain is poisoned, ordinary users have almost no ability to identify the problem before something goes wrong.
And that is not the whole story.
Si also raised a deeper issue:
when you install OpenClaw, the risk may come not from a particular skill, but from a third-party component it depends on. It is built on a large collection of open-source dependencies. If a backdoor is planted in one component during an upgrade, the installation process itself may already be unsafe.
That is why supply-chain problems are more troublesome than many people imagine.
You think you are installing a tool. In reality, you are installing an entire chain of outside code that you may not understand and may not be able to audit.
Why Are Critical Industries Especially Cautious?
At this point, Lan Xu followed up with an important question:
how do industries such as finance, energy and telecommunications actually view OpenClaw now?
Si Hongxing's answer was particularly pragmatic.
It is not that these industries do not want to use it.
Quite the opposite: they very much want to. They know this is not a minor feature upgrade, but a real shift in productivity. Whoever adapts first may gain a position in the next round of competition over organizational efficiency.
But they do not dare use it recklessly either.
The reason is simple:
when frontline employees casually hand over permissions, what leaks may not be ordinary documents, but API access, business data, sensitive processes or even information connected to critical infrastructure. For these industries, the question has never been “is it fun?” but “who bears the consequences if something goes wrong?”
So the more common response now is neither wholesale adoption nor a total shutdown, but this:
“
Let a small number of security-aware people try it within a limited scope. The aim is not to immediately push it into production systems at scale, but to let the organization experience the change and understand how this new tool may rewrite the way work gets done.
Si explicitly said he sensed that many management teams had already accepted one thing: they needed to connect to the ecosystem, but permissions had to be controlled first.
That judgment matters.
It means a truly mature organizational response is neither a blanket ban nor an immediate rollout to everyone.
Instead, it begins with something harder, but more appropriate:
bring a capability that is bound to enter the organization under governance first.
Can Big Technology Companies Solve the Problem Once and for All?
It is easy for many people to place their hopes in one idea:
now that big companies have begun building “secure lobsters,” might the problem soon be solved?
Si Hongxing's answer was clear: no.
His logic was clear, too.
Application-layer controls—reviewing the skill marketplace, placing boundaries around permissions or adding a protective security layer to deployment—certainly help. But controls at the upper layer cannot substitute for addressing the underlying risks.
You may block a poisoned skill today, only for an underlying dependency to be exposed tomorrow. You may restrict certain permissions today, only for a vulnerability in the framework itself to be discovered tomorrow. You may build a “secure deployment assistant” today, but what it deploys tomorrow is still the original lobster.
Si used a vivid analogy:
“
If the underlying layer is not independently controlled, patching vulnerabilities only at the upper layer is like whack-a-mole. Push one down, and another pops up.
That observation captures the key to the next round of competition.
The contest may not be about who looks most like OpenClaw.
It may be about who can truly bring the underlying layer under control.
What Should We Actually Look for in a “Chinese OpenClaw”?
I thought this was one of the most discerning parts of the interview.
Abner noted that domestic vendors were already building “Chinese versions of OpenClaw.” The question was whether these alternatives were actually dependable.
Si Hongxing offered a very clear standard:
do not first ask whether it looks similar; first ask whether they wrote the underlying layer themselves.
He explained in detail.
The underlying layer is not just an interface, a control panel or connections to a few Chinese models. What matters is whether planning and execution, reflection, memory, knowledge management, the execution sandbox, dependency components, call chains and permission mechanisms are independently controlled.
That is a demanding standard, but a realistic one in his account.
As long as the underlying layer still wraps a foreign open-source framework, he argued, it can still introduce third-party component risks, remain susceptible to reverse engineering and suffer poisoning at critical points.
So the question is not “can you build a product that looks like OpenClaw?”
It is: are you building a shell, or a foundation?
That is why Si repeatedly emphasized the four Chinese characters meaning “independently controlled.”
In critical industries, what people really care about is never a feature demonstration, but observability, traceability, auditability and controllability.
What did AI execute, and why? Which step was authorized, and which was performed autonomously? Can it be reconstructed afterward, and can a problem be located when something goes wrong? Those are the questions that determine whether it can enter an organization.
Put plainly, people are not buying an AI that can do work.
They are buying an AI whose actions can be explained when something goes wrong.
Should Ordinary People Raise a Lobster?
One of the most interesting aspects of this interview was that it did not push its conclusion to an extreme.
It was not “don't touch it.”
Nor was it “charge ahead with your eyes closed.”
Si Hongxing's advice to ordinary users was, instead, quite open:
“
Ordinary people can confidently try it, provided they do not experiment recklessly on a work computer, touch sensitive data or mistake default settings for secure settings.
His advice was practical.
If you simply want it to help schedule your time, write emails, organize documents or plan a trip, he said, these are scenarios you can try. The consequences of this kind of use are usually limited in his assessment; more importantly, it can help ordinary people quickly understand this paradigm shift.
But if you insist on experimenting on a production computer, you should at least maintain three basic safeguards:
• Enable authentication first; do not leave it unprotected;
• Do not expose ports to the public internet;
• Follow the principle of least privilege; do not give it administrator-level access.
Those three points are not advanced advice.
They are the minimum threshold.
Once an AI genuinely starts executing operations, security is no longer additional knowledge reserved for experts. It is basic knowledge for every user.
The Worst Thing a Company Can Do Is Pretend This Does Not Exist
I strongly agree with Si Hongxing's advice to business leaders.
He said he did not recommend a blanket ban. A more sensible approach is to establish controls: first identify who is using it, then specify prohibited use cases, and then provide alternatives. Use involving classified information, production environments and core systems should be explicitly prohibited, he said; ordinary office work and exploratory use can be trialed within a controlled scope.
The strength of this advice is that it neither pretends “all the problems are solved” nor evades the fact that “this is coming sooner or later.”
OpenClaw represents more than a product.
It is more like a signal that has arrived ahead of time.
It tells every organization one thing:
AI will not remain in a chat box forever.
Sooner or later, it will enter processes, systems, permissions and the division of work within organizations.
So the issue companies must not neglect now is not “whether to connect,” but “whether they are prepared to put controls in place before connecting.”
A Final Word
In my view, the most valuable outcome of this interview with Unique Capital's Abner, financial journalist Lan Xu and Wanjing Security founder Si Hongxing was neither a collection of security terminology nor a list of risks.
It made one thing genuinely clear:
the Agent era has begun.
But whether it can enter industries, organizations and real business operations depends not on whether it can work, but on whether it can be governed.
The greatest significance of this OpenClaw wave may not be that it gets more people “raising lobsters.”
It may be that everyone can see, for the first time, that the next competition is not only about “who is smarter,” but “who is more controllable.”
Whoever grasps that first is the one who truly understands this little lobster.
Once AI starts executing actions, security is no longer a peripheral issue. It becomes the threshold determining whether a product can enter the real world.
Selected Interview Q&A
Q1: Why did regulators react so quickly this time?
Because this is not an ordinary conversational-AI problem, but a systemic risk arising from autonomous Agent execution. Si Hongxing explicitly noted in the interview that consecutive alerts from March 8 to March 11 were highly unusual but reasonable, because OpenClaw brought not an ordinary vulnerability, but a new form of security threat.
Q2: What are regulators really concerned about?
Not whether AI might say something wrong, but whether it might do something wrong. A chatbot, in this account, can at most mislead people. A mistake by a tool such as OpenClaw could directly delete files, leak data or expose permissions, so the risk has moved from the content layer to the execution layer.
Q3: Do industries such as finance, energy and telecommunications dare to use it now?
They want to, but will not allow unrestricted use. Si said many management teams in these industries already recognized a real productivity shift. But the more common approach was to let a limited number of security-aware people try it within a controlled scope, rather than immediately connecting frontline employees at scale.
Q4: What is OpenClaw's biggest security vulnerability?
Not one isolated vulnerability, but the combination of uncontrolled permissions and supply-chain risk. These include skill poisoning, prompt injection, third-party component risks, attacks on developer accounts and backdoors planted during dependency upgrades. Any of these can turn “installing a tool” into “introducing an entire uncontrolled chain of code.”
Q5: Can big companies building “secure lobsters” solve the problem completely?
Upper-layer patches alone cannot solve underlying problems. In Si's judgment, if the original framework and dependencies remain underneath, application-layer permission controls and skill review will not make the risk disappear. They will simply turn it into “whack-a-mole.”
Q6: What is the standard for judging whether a “Chinese OpenClaw” is dependable?
The central standard, in this interview, is not functionality, but whether the underlying layer is self-developed and independently controlled. If key elements such as planning and execution, memory, reflection, the execution sandbox, call chains and dependency components are still merely wrappers, the risk will not truly disappear, the source argues.
Q7: Should ordinary users raise a lobster?
Yes, but do not learn by trial and error on a work computer. Si's advice was explicit: people can confidently experiment on non-work computers and with non-sensitive data. In his assessment, using it to schedule time, write emails and organize travel plans is fine.
Q8: If you do use OpenClaw, what is the minimum you should do?
At least three things: enable authentication rather than using default settings; do not expose ports to the public internet; and follow least privilege—do not run it with administrator permissions or let it access files and network areas it should not touch.
Q9: What should enterprise security leaders do first?
Not impose a blanket ban, but first identify who is using it, then define prohibited areas and provide alternatives. In particular, uses involving classified information, production environments and core systems must be restricted; ordinary exploratory and low-risk use can be trialed under controls.
Q10: What is the interview's real final conclusion?
Neither “don't use it” nor “just go for it.” Instead: once AI starts executing actions, security is no longer a peripheral issue. It becomes the threshold determining whether a product can enter the real world. That is also the interview's central judgment.
This article was compiled from an in-depth interview with Unique Capital's Abner, financial journalist Lan Xu and Wanjing Security founder Si Hongxing.