Muse has gone viral. What then?
At the start of 2026, OpenClaw sparked the first wave of consumer-facing Agent craze, but the "quick boom" soon turned to rapid decline. In less than two months, the first batch of "early users" paid others to uninstall the app.
After that, consumer-facing Agents were caught in the whirlpool of "security risks", and the once viral "Lobster" faded out of the public view almost overnight.
Unexpectedly, about half a year later, new consumer-facing Agents went viral again.
Recently, Muse released by Meta quickly became a smash hit. Less than 10 days after its launch, it topped the free chart on the US App Store, with a total of about 2.6 million downloads across the whole network 13 days after launch. Its daily active users on US mobile terminals reached 642,000, far higher than the 231,000 of ChatGPT in the same period.
The capital market also responded. On September 21, Meta's closing price rose by 11.43%, with its market value increasing by nearly 200 billion US dollars in a single day.
Figure: Meta's stock price performance Source: Screenshot of Tingting Tech from Tiger Brokers
Of course, controversies still exist. While Muse was going viral, Amazon closed its door to it; security researchers found a zero-day vulnerability in its macOS version; reviewers also began to question whether it is helping users get things done or frantically collecting user data.
With the myth of trillion-dollar market value on one side and restricted shopping operations by Amazon on the other, does the viral success of Muse mean that consumer-facing Agents have reached an inflection point, or is it just another bubble packaged by capital?
Muse Goes Viral
Less than half a year after the "Lobster" trend faded, consumer-facing Agents became popular again.
This time, it's Meta's turn.
At 9 September US Eastern Time, Meta officially launched Muse, its personal AI agent. Without much pre-promotion or a press conference, it was directly open to users aged 18 and above in the United States.
What happened next exceeded most people's expectations.
Public data shows that about 5 days after its launch, Muse's downloads exceeded 730,000; one week after launch, it climbed to No.1 on the free app list of Apple's US App Store, surpassing ChatGPT.
Comparing daily active data, Muse's daily active mobile users in the US have reached 642,000, while the same indicator for ChatGPT in the early stage of its launch was only 231,000, meaning Muse's figure is nearly three times that of the latter.
Figure: Muse ranks No.1 on the US App Store free chart Source: Internet
This is not a simple ranking change.
In the past two years, Meta's situation on the AI track can be described as awkward: it has invested a lot of money and computing power, but it has never had a product that ordinary people can really use.
But Muse changed this situation.
The question is, what exactly can Muse do?
If you only look at the function list, Muse does not seem to be new. It can browse web pages, call tools, process files, and help users book hotels, send emails, shop online, fill out forms and so on.
These capabilities have been demonstrated by ChatGPT, Claude, and Manus which also went viral before.
But the difference of Muse is that it packages these capabilities into a "cloud computer". When each user uses Muse, Meta will allocate an independent virtual machine for them in the cloud, which has a browser, can store files and run programs.
When a user assigns a task, such as "help me find a cheaper car insurance", Muse will execute it autonomously in this virtual computer, opening web pages, comparing plans, filling out forms, and completing transactions.
More critically, Muse will continue to work after the user closes the App.
According to Meta's official introduction, Muse is "the world's first personal AI assistant built for everyone", which can assist in information research, online form filling, online shopping order placement, restaurant reservation, pet sitting service search, and can also link with mainstream service software such as email, calendar, Spotify and Instagram.
Muse can not only remember users' usage preferences and handle daily affairs autonomously, but also obtain user authorization first when involving sensitive operations such as payment and email sending.
In other words, compared with products that are more focused on dialogue or controlled agents, Muse turns "proxy operation" into a consumer-grade product hosted in the cloud and running continuously.
The experience shared by users accelerated Muse's spread beyond the circle.
Entrepreneur Joe Devoy posted on X, saying that he uploaded his car insurance policy and asked Muse to find a cheaper plan with the same coverage. In less than 5 minutes, Muse found a policy that could save him 3500 US dollars a year, and completed all the operations of purchasing the new insurance and canceling the old policy for him.
Another X user shared a more detailed experience. He asked Muse to find a green down jacket. Muse not only completed the search, but also automatically retrieved the instant discount code, applied the discount code, and finally completed the purchase at the lowest price.
These cases quickly fermented on social media, forming a display trend of "getting things done with Muse".
Alexandr Wang, Meta's Chief AI Officer, himself posted very frequently, sometimes more than 30 posts a day, sharing product updates and user feedback in real time.
Mark Zuckerberg, CEO of Meta, positioned Muse as the first step of "personal superintelligence". By providing a free version, as well as two paid plans of 20 US dollars and 100 US dollars, plus distribution through the super entrance of WhatsApp, Meta is trying to make Muse an important touchpoint for ordinary people to access AI agents.
Why Muse?
To understand why Muse can ignite the market, we have to start from the viral success and decline of its similar product "Lobster" OpenClaw.
At the beginning of 2026, the appearance of OpenClaw caused a huge response in the geek circle, and Chinese developers gave it a friendly nickname "Lobster".
As an open-source AI agent framework, users can send instructions to OpenClaw through chat tools such as WhatsApp and Telegram, and it can perform various operations on your local computer.
But OpenClaw's problems are also obvious: it requires users to deploy, maintain, and manage security on their own. This creates an extremely high technical threshold for ordinary users.
Most importantly, OpenClaw has large controversies in terms of security.
Previously, the National Cybersecurity and Information Security Information Notification Center specially issued a risk warning, pointing out that OpenClaw has major security risks. Once exploited by attackers, it may lead to serious security problems such as server hijacking and sensitive data leakage.
After that, many reviews pointed out that OpenClaw is suitable for geeks, but not for ordinary people.
Muse tries to reverse this problem by productizing the "ability to get things done". Users do not need to understand server configuration, bother with model deployment, or worry about security strategies. Meta directly builds and runs a cloud AI assistant for users, which can be used immediately after registration.
But this is not Muse's biggest differentiation. What really makes it gap with OpenClaw in architecture are several key designs.
What is highly praised by users is that Muse has the ability to run continuously in the cloud, instead of relying on local devices.
For example, OpenClaw runs on the user's own computer, and it stops working when the computer is shut down. But Muse runs in Meta's independent cloud virtual machine, which is online 7*24 hours, and it will continue to execute tasks in the background after the user exits the App.
The technical logic behind this is that Muse is essentially not an App, but a "cloud computer" that belongs to you, and the App is just a remote controller.
Most importantly, Muse builds security into its architecture, instead of "remedying" it afterwards.
Public reports show that Meta has designed an exclusive isolated architecture called Secure VM for Muse. Each user's Muse instance runs in an independent cloud virtual machine, and the data of different users is strongly isolated by independent virtual machines.
More critically, the system sets up a Sentinel security agent independent of the Muse main program in the same virtual machine, which realizes permission separation at the system level.
Under this architecture, Muse cannot see users' plaintext passwords and payment information. The payment function in cooperation with Stripe will generate a one-time virtual card number, so that the Agent does not have to enter the user's real card number on different websites. Before performing any sensitive operations, Muse will ask for user confirmation.
Some early user experiences show that Muse is more like an "agent" rather than a "tool".
In contrast, OpenClaw is more like an advanced tool that you can customize, with powerful functions but requiring users to take care of everything.
While Muse is positioned as a "person who does things for you", Meta takes responsibility for security and operation maintenance, and users only need to tell it what to do.
Is It Sustainable?
One question is, will Muse, like OpenClaw, just be a flash in the pan?
Although the market cannot draw a conclusion for now, some signs show that there are also doubts about Muse.
For example, a reviewer spent a week trying Muse, letting it access his email, credit card, and even Apple Health data.
The conclusion is that Muse "performs quite well" on simple tasks such as organizing the inbox and summarizing important emails; but once it involves complex tasks that require coordination across multiple systems, it fails frequently.
Other reviewers found that Muse behaves "too aggressively" in connecting user data. It seems to be more obsessed with collecting user data than actually completing tasks.
Some other reviewers reported that Muse sent emails without approval.
These feedbacks point to a fundamental contradiction: to complete complex cross-site proxy tasks, Muse must deeply access users' digital lives, and this deep access itself is the biggest source of risk.
Although Meta promises that Muse's data will not be shared with the advertising system, in a company that survives on advertising revenue, the long-term credibility of this promise needs to be questioned.
The discovery of security researchers is more serious.
According to media reports, a macOS security researcher found a zero-day vulnerability in the macOS version of Muse, through which local malware can hijack Muse's dictation function, and even obtain the account identity token to control the entire AI assistant account.
It is reported that the researcher released the proof-of-concept code and advised Mac users not to install Muse. However, multiple media later reported that Meta had released a hotfix patch.
Amazon quickly responded.
Since the evening of September 20, Amazon began to block Muse from completing shopping operations on its platform, with an error prompt saying "continuous access by unauthorized AI agents violates Amazon's terms of use".
An Amazon spokesperson said that Muse did not mark its agent identity in HTTP requests, and "seems to obtain and store customer credentials".
In response to Amazon's doubts, Meta responded that Muse "cannot access users' passwords or payment method information", but this explanation did not calm the outside world's doubts.
In addition, more controversies point out that when Muse accesses various websites and services on behalf of users, it will inevitably collide with the existing platform ecosystem, after all, each platform has its own interest considerations.
In fact, from the industry's perspective, this may be the main reason why Amazon restricted Muse's shopping operations. It is widely believed in the industry that besides security and terms reasons, this also involves the defense of commercial interests.
Although the outside world has certain doubts about Muse, more analysis believes that the viral success of Muse, to some extent, verifies a judgment that the inflection point of consumer-facing Agents may come earlier than expected.
However, with the viral spread of Muse, it further exposes the tension that consumer-facing Agents must face when moving towards the public. For example, the stronger the capability, the more permissions it needs; the more permissions, the deeper users' uneasiness.
In fact, Amazon's ban, the disclosure of zero-day vulnerabilities, and the doubts about data collection will not disappear automatically just because of the App Store ranking.
From the perspective of industry insiders, how long Muse can stay popular still depends on whether Meta can find that subtle balance between "helping users get things done" and "making users feel relieved".
At least for now, this balance point is still wobbling.
(The cover image is generated by AI.)
(Statement: This article is for information exchange only, and does not constitute any investment reference advice.)
This article is from the WeChat official account "Tingting Tech", and is authorized for release by 36Kr.