What happened
An attacker tricks a victim into visiting a malicious link, silently exfiltrates the OpenClaw authentication token, and establishes a direct, unauthenticated WebSocket connection to the victim's local OpenClaw instance to run arbitrary commands.