Here’s a stress test most software companies quietly avoid: put your AI in front of the entire internet and dare people to break it. OpenClaw just did exactly that, and the results were surprisingly clean.
Fiu, an AI assistant built on the OpenClaw autonomous agent framework and developed by Fernando Irarrázaval, completed a public prompt-injection challenge hosted at hackmyclaw.com. More than 2,000 attackers sent over 6,000 emails trying to trick the AI into leaking sensitive data stored in a secrets.env file. Not one succeeded.
What actually happened
The test gained serious traction after landing on the front page of Hacker News on June 25, 2026.
Prompt injection is the AI equivalent of social engineering. Instead of exploiting a bug in code, attackers craft clever inputs designed to override an AI’s instructions and make it behave in ways its creator never intended.







