MemGhost: Stealthy Memory Poisoning Attack on Persistent AI Agents Achieves 87.5% Success Rate Against OpenClaw
Researchers from Nanyang Technological University (NTU), Singapore’s A*STAR research agency, and Johns Hopkins University have published a paper that should give every OpenClaw user pause: they built an automated attack system that poisons your agent’s persistent memory via a single crafted email — and it works with alarming reliability. The paper, titled “When Claws Remember but Do Not Tell: Stealthy Memory Injection in Persistent Personal Agents” (arXiv:2607.05189), introduces both the attack — called MemGhost — and a benchmark suite called WhisperBench to evaluate it. The results are uncomfortable reading. ...