Your login failed. The attack didn't. Stored XSS in OpenClaw Dashboard
Two stored XSS bugs in OpenClaw Dashboard, both the same missing encode on the way to innerHTML. One is reachable by an unauthenticated visitor through the login form, the other fires on a background timer with no admin click at all.