MemGhost: Attacker Model Plants Persistent False Memories via Email
MemGhost successfully injects persistent false memories into OpenClaw and Claude Code SDK agents using just one email.
Recent research from NTU, A*STAR, and Johns Hopkins reveals MemGhost, a model capable of injecting attacker content into the memory of OpenClaw and Claude Code SDK agents through a single email. This 'stealth memory injection' technique allows agents to act on poisoned memories in future sessions, achieving an impressive 87.5% success rate.