- Varonis’ “Pinchy” OpenClaw agent fell for identity‑based phishing despite strict settings
- Models blocked malicious links/OAuth apps but granted sensitive access when requests felt urgent
- Researchers say AI agents need enforced identity verification before acting
Security researchers tested an OpenClaw email agent to see if it’s naive enough to fall for the same phishing scams regular employees fall for and it succeeded. Or failed, depending on how you look at it.