SDSignal Desk

Muse sure looks a lot like OpenClaw

Sep 24, 2026, 10:10 AM · The Verge

Image: The Verge

Meta says Muse was built from scratch but admits it was heavily inspired by OpenClaw — and the security story is still unfinished.

Why it matters

Muse has already topped App Store charts and, by an Apptopia estimate, reached about 600,000 daily active users in the US. Instinct, another agent platform, is fundraising around a $2.5 billion valuation. Under the hood, both sit in OpenClaw’s shadow.

Social users pointed at shared file names like SOUL.md, overlapping personality-doc lines, and similar design. Meta’s Nat Friedman denied Muse is an OpenClaw wrapper, said it was built “from scratch,” and still called it “heavily inspired as a product.” That is the corporate confession that matters.

From the desk

We’re glad open-source agents proved the category. OpenClaw went from a weekend project on personal machines to millions of visitors and roughly 100,000 GitHub stars in about a week, talking to people where they already chat — WhatsApp, Telegram, Slack, and the rest. Big Tech noticed: OpenAI hired creator Peter Steinberger in February; Google, Apple, Instinct, and then Meta’s Muse followed through the year.

Friedman says after he used OpenClaw in January he bought hundreds of Mac Minis for his Meta team, and that Muse aims to be safe, secure, easy, and scalable to billions. He also said Steinberger got those core file names and lines “exactly right.” Inspiration that deep is fine if Meta actually improved the scary part. OpenClaw’s skill ecosystem had a malware problem; one researcher’s analysis claimed about 15 percent of the skill repository held malicious instructions.

Meta and Mark Zuckerberg pitch Muse Secure VM isolation and privacy-by-construction. The Verge notes the gaps: Meta can still access user data for now, cryptographic locks that would stop Meta are promised later this year, training on user data is on by default with opt-out, and a zero-day flagged this week reportedly lets an attacker hijack the agent. Accessibility wins — one-tap install, Meta integrations, lower friction than DIY OpenClaw — are real. Security theater with a cute mascot is not.

The grassroots OpenClaw community wanted an escape hatch from a handful of AI companies. Those companies are now shipping friendlier agents at scale. I’m for agents that book the DMV appointment and cancel the junk subscription. I’m watching whether Muse’s “safe and secure” claim survives contact with the zero-day and with Meta’s training defaults — because inspiration without hardening just industrializes the risk.

Context

Instinct looks less like a direct clone but echoes OpenClaw’s messaging-first assistant pattern, including Apple Messages access. Google’s Spark is cited as a pricier competitor for now. A correction in the piece notes Instinct was misnamed Insight in an earlier version.

Who feels it

Everyday Muse users
One-tap agents are useful only if VM isolation and upcoming crypto locks actually limit Meta — and if hijack bugs get closed fast.
Open-source agent builders
OpenClaw’s product DNA is now mainstream; the remaining edge is transparency and local control, not file-name novelty.
Security researchers
Skill-malware history plus the reported Muse zero-day make agent platforms a live exploit surface.
Investors and rivals
Instinct’s valuation and Muse’s DAU show consumer agents clearing the novelty bar; trust and ToS breadth are the next fight.

What to watch

  1. Meta’s promised cryptographic controls that would verifiably block Meta from reading Muse VM data.
  2. Patch status and disclosure details on the Muse agent hijack zero-day.
  3. Whether Muse’s default model-training opt-out rate rises as more non-technical users install it.

Read the original

Continue at the source.

The Verge

Companies: Meta

Also covering this