The post OpenClaw’s ClawHub Flags 1,184 Malicious Skills appeared on BitcoinEthereumNews.com. Key Highlights: Security researchers flagged 1,184 malicious “skillsThe post OpenClaw’s ClawHub Flags 1,184 Malicious Skills appeared on BitcoinEthereumNews.com. Key Highlights: Security researchers flagged 1,184 malicious “skills

OpenClaw’s ClawHub Flags 1,184 Malicious Skills

2026/02/20 22:08
4 min di lettura
Per feedback o dubbi su questo contenuto, contattateci all'indirizzo [email protected].

Key Highlights:

  • Security researchers flagged 1,184 malicious “skills” on OpenClaw’s ClawHub capable of stealing SSH keys, wallet data, and browser credentials.
  • A single attacker uploaded hundreds of harmful packages, some of which were downloaded widely before being detected.
  • Experts warn that rapid adoption of OpenClaw tools is outpacing security safeguards, increasing risks of credential theft and remote code execution.

The OpenClaw ecosystem is yet again under fire for security reasons, this time due to its official marketplace, ClawHub. Researchers have identified 1184 malicious packages circulating in ClawHub.

The warning was highlighted by SlowMist founder Cosmos Yu, who shared details of the issue.

OpenClaw’s ClawHub in the Crosshairs for Security Concerns

According to the alert, a total of 1,184 malicious “skills” have been detected on ClawHub. These packages are capable of stealing SSH keys, extracting browser passwords, encrypting wallets, and even opening reverse shells on user machines. In one case, a single attacker was responsible for uploading 677 separate packages into the marketplace.

Some of these skills had already gained traction. The highest-ranked malicious package reportedly has nine separate vulnerabilities and had been downloaded thousands of times before being flagged. This raises questions about how quickly harmful code can spread across decentralized or semi-open AI agent ecosystems where discoverability is high and review processes may lag behind adoption.

ClawHub is the official skill registry for OpenClaw. It functions similarly to a package manager for AI agents, allowing developers and users to extend functionality through downloadable modules. At the time of writing, the registry listed 3,286 skills across 11 categories and had seen more than 1.5 million downloads. Its vector-based semantic search allows users to find tools using natural language queries, which improves usability but may also increase exposure to unsafe packages if moderation is insufficient.

The platform has already faced security issues in recent weeks. Earlier this month, researchers documented a “ClawHavoc” incident involving hundreds of malicious skills designed to steal user data. In response, the platform removed more than 2,400 suspicious packages, introduced automated malware scanning through a partnership with VirusTotal, and strengthened moderation rules so that flagged tools are hidden after multiple reports. A user reporting system for unsafe skills has also been introduced.

Even with these measures, the OpenClaw ecosystem continues to draw criticism. The platform, which previously operated under names including Clawdbot and Moltbot, has been described by security researchers as innovative but highly exposed to risk. Cisco Talos recently called it groundbreaking for productivity and also labeled it a major security challenge.

At the same time, the platform’s rapid growth in crypto sector has intensified the risks. OpenClaw agents can directly interact with blockchain networks like Polygon and Solana. They can also communicate with other agents and execute tasks autonomously. These features around financial capability, automation, and networked coordination has accelerated its adoption among both developers and crypto users. Some users have already reported generating trading profits through arbitrage and prediction market strategies using these agents.

However, security analysts say adoption is outpacing governance. Researchers have observed attackers scanning for default OpenClaw ports and testing ways to dodge protections. Enterprise security providers have also warned that a large number of employees are deploying these tools internally without formal approval. This pattern mirrors the wider rise of shadow IT, where new technologies spread faster than internal controls can keep up.

Yu has warned that in the age of AI agents, text inputs can function as executable commands. He advised users to run such tools in isolated environments and to treat third-party skills with caution. He also pointed out that Web3 security risks are no longer limited to smart contracts alone, as he cited recent incidents where vulnerabilities introduced via AI-assisted code contributed to losses.

Also Read: Moonwell: Recovery Plan Moves to Governance Forum Following 2.68M Loss

Source: https://www.cryptonewsz.com/openclaws-clawhub-flags-1184-malicious-skills/

Opportunità di mercato
Logo Ucan fix life in1day
Valore Ucan fix life in1day (1)
$0.0004795
$0.0004795$0.0004795
+3.92%
USD
Grafico dei prezzi in tempo reale di Ucan fix life in1day (1)
Disclaimer: gli articoli ripubblicati su questo sito provengono da piattaforme pubbliche e sono forniti esclusivamente a scopo informativo. Non riflettono necessariamente le opinioni di MEXC. Tutti i diritti rimangono agli autori originali. Se ritieni che un contenuto violi i diritti di terze parti, contatta [email protected] per la rimozione. MEXC non fornisce alcuna garanzia in merito all'accuratezza, completezza o tempestività del contenuto e non è responsabile per eventuali azioni intraprese sulla base delle informazioni fornite. Il contenuto non costituisce consulenza finanziaria, legale o professionale di altro tipo, né deve essere considerato una raccomandazione o un'approvazione da parte di MEXC.

Potrebbe anche piacerti

UK To Deepen Crypto Ties With US, May Adopt More Pro-Crypto Approach: FT

UK To Deepen Crypto Ties With US, May Adopt More Pro-Crypto Approach: FT

The UK is set to expand cooperation with the US on digital assets while exploring a more crypto-friendly approach to boost innovation and attract investment. [...]
Condividi
Insidebitcoins2025/09/17 23:42
Coinbase Issues Cryptocurrency Call to US Justice Department: “Solve Urgent Problems!”

Coinbase Issues Cryptocurrency Call to US Justice Department: “Solve Urgent Problems!”

The post Coinbase Issues Cryptocurrency Call to US Justice Department: “Solve Urgent Problems!” appeared on BitcoinEthereumNews.com. Coinbase, the largest cryptocurrency exchange in the United States, stated that there should be uniform cryptocurrency regulation in the country. At this point, Coinbase sent a letter to the US Department of Justice requesting that federal regulators prevent state regulations from conflicting with national crypto policies and ensure uniform regulatory clarity. Coinbase’s request comes after the state of Oregon filed a lawsuit against Coinbase for unregistered securities, despite the SEC withdrawing its lawsuit against the cryptocurrency exchange. Coinbase states that although the country’s top regulator, the SEC, withdrew its lawsuit, states are filing lawsuits in defiance of the SEC’s decision. In the letter, addressed by Coinbase Legal Counsel Paul Grewal, he stated: “Despite the Trump administration’s positive regulatory efforts, crypto companies are being negatively impacted by states’ flawed interpretations of securities laws and their divergent actions. If Oregon can sue us for services that are legal under federal law, we have a problem. It has long been clear that the current patchwork of state laws is not only inefficient, but also slows innovation and harms consumers. At this point, the Justice Department should take steps to address the pressing issues by calling on Congress to step in and enact comprehensive and uniform regulations.” Oregon Attorney General Dan Rayfield filed a lawsuit against Coinbase last April, alleging that Coinbase was promoting the sale of unregistered cryptocurrencies to individuals in Oregon. *This is not investment advice. Follow our Telegram and Twitter account now for exclusive news, analytics and on-chain data! Source: https://en.bitcoinsistemi.com/coinbase-issues-cryptocurrency-call-to-us-justice-department-solve-urgent-problems/
Condividi
BitcoinEthereumNews2025/09/18 05:06
CME to launch Solana and XRP futures options on October 13, 2025

CME to launch Solana and XRP futures options on October 13, 2025

The post CME to launch Solana and XRP futures options on October 13, 2025 appeared on BitcoinEthereumNews.com. Key Takeaways CME Group will launch futures options for Solana (SOL) and XRP. The launch date is set for October 13, 2025. CME Group will launch futures options for Solana and XRP on October 13, 2025. The Chicago-based derivatives exchange will add the new crypto derivatives products to its existing digital asset offerings. The launch will provide institutional and retail traders with additional tools to hedge positions and speculate on price movements for both digital assets. The futures options will be based on CME’s existing Solana and XRP futures contracts. Trading will be conducted through CME Globex, the exchange’s electronic trading platform. Source: https://cryptobriefing.com/cme-solana-xrp-futures-options-launch-2025/
Condividi
BitcoinEthereumNews2025/09/18 01:07