{
  "version": "2",
  "id": "https://freelancenews.online/news/meta-s-muse-and-instinct-draw-openclaw-comparisons-as-agent-security-dac80f12",
  "title": "Meta's Muse and Instinct draw OpenClaw comparisons as agent security questions persist",
  "summary": "Meta says its new consumer AI agent Muse was built from scratch, but a product lead acknowledges it was heavily inspired by OpenClaw — and a reported zero-day flaw raises questions about whether the new wave of agents actually improves on the original's security problems.",
  "body": "Meta's consumer AI agent Muse climbed to the top of the App Store shortly after release and has roughly 600,000 daily active users in the US, according to an Apptopia estimate cited by The Verge. The launch has been accompanied by a public argument over how much of Muse's design comes from OpenClaw, the open-source agent that popularized the category over the past year.\n\nFor about a week, some social media users have alleged that Muse is built directly on OpenClaw. The Verge reports that the two platforms share names for core files such as SOUL.md, memory and tools, and that their personality and tone documentation contains similar lines, including the instruction to be \"genuinely helpful, not performatively helpful.\" The two products also look alike. One Redditor argued that Muse is a wrapper app layered on OpenClaw and suggested it likely inherited that platform's security risks, adding that only non-technical users were buying the hype.\n\nThose claims are rejected by Meta. Writing on X, Nat Friedman — who leads product for Meta's Superintelligence Labs — said Muse was built from scratch, though he conceded that OpenClaw served as a heavy source of inspiration. His account: after trying OpenClaw for the first time in January, he purchased hundreds of Mac Minis for his team, and through Muse he aimed to create a comparable product that would be safe, secure, simple to use and able to scale to billions. Regarding the overlapping file names and phrasing, Friedman explained that his team felt OpenClaw's creator, Peter Steinberger, had nailed those elements precisely.\n\nAccording to the report, a second AI agent platform called Instinct — whose creator is raising funds at a $2.5 billion valuation — looks less like a direct derivative. Even so, it offers messaging-based conversations with agents, mirroring the capability that set OpenClaw apart, and its users report the same sort of daily personal-assistant tasks. Paperwork for an in-network doctor visit, subscription cancellations, bachelor party planning, vacation activity bookings, a DMV appointment and an overdue toll bill were all handled by one user's agent, that person said on X. Recovery of an item left behind at a hotel in Canada was managed by another person's agent, per that user.\n\nThe Verge frames the underlying question as less about copying and more about improvement. OpenClaw began as a one-man weekend project running on users' own computers, and it conversed with people on messaging platforms including WhatsApp, Telegram, Slack, Teams and Discord. Within roughly a week it drew two million visitors and 100,000 GitHub stars, prompted people to buy Mac Minis to run agents continuously, inspired a social network for agents and led to in-person meetups.\n\nBig Tech responded in sequence. OpenAI hired Steinberger in February to work on agents, Google announced consumer agent products at its annual event in May, Apple went all-in on agents in June, Instinct grew quickly in private beta and raised hundreds of millions of dollars in August, and Meta introduced Muse in September. The report concludes that OpenClaw at least partially inspired all of them, while noting it did not invent the concept of AI agents.\n\nSecurity is the sharpest point of comparison. The Verge reports that one of the most-downloaded OpenClaw skills contained malware, and that by one researcher's analysis 15 percent of the platform's skill repository held malicious instructions designed to secretly access user data or perform other suspicious tasks. Meta's counter-argument, attributed to Mark Zuckerberg, is that Muse was built from the ground up for privacy and security, with user data and credentials stored on a Muse Secure VM described as an isolated Linux computer with a browser, CPU, memory and storage.\n\nNot yet fully demonstrated is that assertion. User data remains walled off from other users, yet Meta itself can reach it, and later this year the company intends to introduce a method for cryptographically and verifiably blocking Meta from accessing data inside a user's VM. By default, Muse also permits Meta to train and improve its models using user data, and an opt-out exists. Additionally, per the report, a zero-day vulnerability that a researcher flagged on X this week would allow anyone, using a simple attack, to hijack the agent and take complete control. Instinct, for its part, has drawn complaints that its terms of service are too broad, although the company seems to have revised them in the time since.\n\nFor freelancers, designers and developers weighing these tools, the practical distinction is access rather than architecture. Muse integrates with Meta's existing systems, which is one reason some users find it useful even when they are uneasy about handing over their data, and Instinct lets users chat with agents through Apple's default messaging product, widening the pool of people willing to try an agent at all. Both can run on dedicated local devices, which may carry security benefits, but that is not the default setup.\n\nCost and friction also matter. The report says both are, at least for now, less expensive than a competing product such as Google's Spark, and that although Instinct remains in beta, Muse's one-tap download removes much of the setup burden that OpenClaw imposed. That combination — lower price plus lower setup effort — is what expands the addressable audience more than any technical novelty.\n\nThe tradeoff is that convenience tends to arrive bundled with data access. A hosted agent that stores credentials on a vendor-controlled virtual machine is easier to adopt than a self-hosted one, but it also shifts who holds the keys. The report's account of Muse's default data-training setting and the deferred cryptographic guarantee illustrates that shift concretely: the security promise is partly a roadmap item rather than a shipped feature.\n\nThe reported zero-day is the most consequential unresolved item. If a simple attack can hand an attacker complete control of an agent, then the agent's access to messaging accounts, subscriptions, appointments and payment-adjacent tasks becomes the attack surface. The report does not say whether the flaw has been patched, how many users are affected, or whether Meta has responded to the researcher's disclosure, and those gaps should be treated as open questions rather than resolved ones.\n\nA cultural shift is also highlighted by The Verge. The OpenClaw community, it reported in March, saw the open-source agent as a grassroots crusade and a noble pursuit — a way out from an industry run by a small number of people at top AI companies. Those same top companies now compete head-on in the category, and their file structures, messaging integrations and positioning all bear the mark of the open-source project's influence.\n\nFor this audience, the useful takeaway is procedural rather than promotional. Anyone adopting Muse or Instinct for client work should treat the agent as a system with access to accounts and credentials, not as a chat toy: check whether data training is on by default, understand where credentials live, and prefer isolated or local execution where the workflow allows it. None of that is a verdict on either product — it is the minimum diligence the reported security record justifies.\n\nWhat remains genuinely unknown is whether the new entrants fixed OpenClaw's core weakness or merely repackaged it behind a friendlier interface. Meta asserts a security-first build; the report documents a default data-training setting, a vendor-accessible VM and a reported hijack vulnerability whose patch status is not stated. Until those specifics are resolved, the honest assessment is that the category has become far more accessible without yet demonstrating that it has become safer.",
  "category": "ai",
  "language": "en",
  "datePublished": "2026-09-24T21:18:36.281Z",
  "dateModified": "2026-09-24T21:18:36.281Z",
  "eventDate": null,
  "sourcePublicationDate": "2026-09-24T17:10:38.000Z",
  "source": {
    "name": "theverge.com",
    "url": "https://www.theverge.com/report/1000180/muse-openclaw-instinct-lookalike",
    "kind": "other-publisher"
  },
  "practicalImpact": "Editorial interpretation: freelancers and developers evaluating Muse or Instinct should treat the agent as a credentialed system rather than a chat interface — verify whether data training is enabled by default, establish where credentials are stored, and prefer isolated or local execution where the workflow permits, because the reported security record does not yet support assuming the hosted versions are safer than self-hosting.",
  "limitations": "The report does not state whether the reported Muse zero-day has been patched, how many users are affected, or whether Meta has responded to the disclosure. Pricing is described only as lower than Google's Spark, with no figures. Instinct remains in beta. The 600,000 daily active user figure comes from an Apptopia estimate, and the 15 percent malicious-skill figure comes from one researcher's analysis, both as relayed by The Verge. Social media allegations about Muse being built on OpenClaw are user claims that Meta denies.",
  "keyPoints": [
    "Meta says Muse was built from scratch, but product lead Nat Friedman acknowledged it was heavily inspired by OpenClaw and that shared file names and wording were kept because the team thought OpenClaw's creator got them right.",
    "The Verge reports that a zero-day vulnerability flagged by a researcher would let an attacker hijack Muse and take complete control, and that Meta can still access user data despite per-user isolation.",
    "Muse defaults to letting Meta train models on user data with an opt-out, and a cryptographic guarantee against Meta accessing VM data is described as planned for later this year rather than shipped.",
    "Instinct appears less directly derivative but mirrors OpenClaw's messaging-based agent use cases; its terms of service drew criticism for being overly broad before apparently being adjusted.",
    "Both Muse and Instinct lower cost and setup friction relative to OpenClaw, which the report identifies as their main evolution rather than a security improvement."
  ],
  "review": {
    "status": "source-reviewed",
    "checkedAt": "2026-09-24T21:18:36.281Z",
    "method": "Automated comparison against retrieved source text; not independent fact-checking.",
    "correctionNote": null
  },
  "sources": [
    {
      "id": 1,
      "url": "https://www.theverge.com/report/1000180/muse-openclaw-instinct-lookalike",
      "publisher": "theverge.com",
      "title": "Muse sure looks a lot like OpenClaw",
      "publishedAt": 1790269838000,
      "fetchedAt": 1790284688263,
      "hash": "4c1e0c187fa1d6b719d3b6764751e05a1d878d55d82247b50c9fe8fc04cbbe11",
      "kind": "other-publisher"
    }
  ],
  "claims": [
    {
      "claim": "Meta's Muse reached the top of the App Store and has about 600,000 daily active US users by an Apptopia estimate.",
      "source": 1,
      "id": "claim-1",
      "url": "https://freelancenews.online/news/meta-s-muse-and-instinct-draw-openclaw-comparisons-as-agent-security-dac80f12#claim-1"
    },
    {
      "claim": "Nat Friedman said Meta built Muse from scratch but acknowledged it was heavily inspired by OpenClaw, and that the team kept OpenClaw's file names and wording because Steinberger got them right.",
      "source": 1,
      "id": "claim-2",
      "url": "https://freelancenews.online/news/meta-s-muse-and-instinct-draw-openclaw-comparisons-as-agent-security-dac80f12#claim-2"
    },
    {
      "claim": "A researcher flagged a zero-day vulnerability that would let anyone hijack the Muse agent and take complete control.",
      "source": 1,
      "id": "claim-3",
      "url": "https://freelancenews.online/news/meta-s-muse-and-instinct-draw-openclaw-comparisons-as-agent-security-dac80f12#claim-3"
    },
    {
      "claim": "Muse defaults to letting Meta train and improve models on user data, with an opt-out, and a cryptographic guarantee against Meta accessing VM data is planned for later this year.",
      "source": 1,
      "id": "claim-4",
      "url": "https://freelancenews.online/news/meta-s-muse-and-instinct-draw-openclaw-comparisons-as-agent-security-dac80f12#claim-4"
    },
    {
      "claim": "One researcher's analysis found 15 percent of OpenClaw's skill repository contained malicious instructions.",
      "source": 1,
      "id": "claim-5",
      "url": "https://freelancenews.online/news/meta-s-muse-and-instinct-draw-openclaw-comparisons-as-agent-security-dac80f12#claim-5"
    },
    {
      "claim": "Instinct has faced criticism that its terms of service are overly broad, though the company appears to have adjusted them since.",
      "source": 1,
      "id": "claim-6",
      "url": "https://freelancenews.online/news/meta-s-muse-and-instinct-draw-openclaw-comparisons-as-agent-security-dac80f12#claim-6"
    }
  ],
  "formats": {
    "html": "https://freelancenews.online/news/meta-s-muse-and-instinct-draw-openclaw-comparisons-as-agent-security-dac80f12",
    "markdown": "https://freelancenews.online/news/meta-s-muse-and-instinct-draw-openclaw-comparisons-as-agent-security-dac80f12.md",
    "json": "https://freelancenews.online/news/meta-s-muse-and-instinct-draw-openclaw-comparisons-as-agent-security-dac80f12.json"
  }
}