AI RACE— The AI Race
Business

Meta Denies Muse Is an OpenClaw Clone as Viral AI Agent Faces Scrutiny

Meta's new consumer AI agent Muse has quickly reached 600,000 daily U.S. users, but critics allege the app directly copies the architecture and prompts of open-source predecessor OpenClaw.

09/25/2026, 00:10
Meta bị nghi "sao chép" dự án mã nguồn mở OpenClaw để tạo ra AI agent Muse

Viral Launch Clouded by Clone Allegations

Meta’s new consumer-facing AI agent, Muse, rapidly surged to the top of the App Store following its September release, drawing an estimated 600,000 daily active users in the United States, according to Apptopia data. Alongside rival platform Instinct—whose creator is currently seeking funding at a $2.5 billion valuation—Muse has signaled an industry rush toward autonomous digital assistants.

However, Muse's sudden ubiquity has been met with backlash across social media, where developers and users argue that the tool borrows heavily from OpenClaw, the open-source agent platform released earlier this year. Critics pointed out that Muse mirrors OpenClaw’s core architectural structure, design, and internal documentation, prompting claims on Reddit that the service is "just a wrapper app built on top of" OpenClaw and inherits its technical risks, with one commenter writing that "only non-tech ppl are buying the hype."

Shared Codebases, VM Security, and Meta’s Defense

Users investigating Muse discovered that it shares identical core file names with OpenClaw, including SOUL.md, memory, and tools. The service also lifts exact phrasing from OpenClaw's personality and tone guidelines, such as the directive: “Be genuinely helpful, not performatively helpful.”

Meta has dismissed accusations that it repackaged OpenClaw. Nat Friedman, head of product for Meta’s Superintelligence Labs, wrote on X that the engineering team built Muse “from scratch.” He conceded, however, that Muse was “heavily inspired as a product” by the open-source software. Friedman explained that after testing OpenClaw in January, he bought hundreds of Mac Minis for his Meta team to build a competing platform that was "safe and secure and easy to use and scale to billions of people." Friedman defended retaining OpenClaw's specific file names and prompt lines by stating the team believed creator Peter Steinberger had gotten those elements "exactly right."

Security remains a major flashpoint in the debate. OpenClaw suffered from well-documented vulnerabilities: one researcher found that 15 percent of its public skill repository contained malicious instructions to siphon data, and one of its most popular skills carried malware. Meta CEO Mark Zuckerberg claimed Muse addresses these issues by being “built from the ground up for privacy and security,” isolating user data within the "Muse Secure VM"—a sandboxed Linux environment equipped with its own virtual CPU, browser, memory, and storage.

Despite these protections, Muse's architecture exhibits its own security flaws. While user environments are segregated from one another, Meta maintains internal access to the data, promising to implement cryptographic controls to verify that Meta cannot access VM contents later this year. The app also defaults to utilizing user data to train future models unless users manually opt out. Furthermore, a security researcher on X flagged a zero-day exploit this week that permits attackers to hijack and fully control a target's Muse agent via a basic attack vector.

Competitors are navigating similar hurdles. Instinct has faced backlash over overly broad terms of service, which it has since modified. Unlike OpenClaw's complex setup, both Muse and Instinct have lowered consumer adoption barriers by leaning on consumer-friendly integrations—Instinct connects to Apple's native messaging tools, while Muse offers one-tap onboarding and native hooks into Meta's ecosystem. Both platforms currently undercut competing tools like Google's Spark on price.

From Weekend Hack to Big Tech Agent War

The corporate race to commercialize agents traces back to OpenClaw’s unexpected rise. Steinberger initially assembled OpenClaw over a single weekend as a local personal computer script that interacted with users across standard chat apps like WhatsApp, Telegram, Slack, Teams, and Discord. Within a week, the repository accumulated 100,000 GitHub stars and two million visitors, spurring a hardware rush on Mac Minis to run 24/7 host nodes, agent-only social networks, and global user meetups.

The grassroots movement promptly triggered a series of countermoves from tech giants throughout 2026:

  • February: OpenAI hired OpenClaw creator Peter Steinberger to steer internal agent development.
  • May: Google outlined its consumer agent roadmap at its annual showcase.
  • June: Apple launched an all-in strategy shift targeting autonomous agents.
  • August: Instinct raised hundreds of millions during a private beta that saw users deploy agents for complex logistics—including scheduling DMV visits, disputing toll fees, booking medical appointments, and coordinating hotel lost-and-found recoveries abroad.
  • September: Meta deployed Muse to the consumer market.

While OpenClaw was initially championed by its community as an open-source alternative to proprietary AI monopolies, Big Tech companies are now aggressively absorbing the project's core concepts to secure dominance in consumer agent workflows.

◗ Sources

The Verge09/25

Related stories