• bitcoinBitcoin (BTC) $ 66,493.00
  • ethereumEthereum (ETH) $ 2,046.78
  • tetherTether (USDT) $ 0.999862
  • xrpXRP (XRP) $ 1.31
  • bnbBNB (BNB) $ 589.03
  • usd-coinUSDC (USDC) $ 0.999917
  • solanaSolana (SOL) $ 79.10
  • tronTRON (TRX) $ 0.315487
  • staked-etherLido Staked Ether (STETH) $ 2,265.05
  • figure-helocFigure Heloc (FIGR_HELOC) $ 1.03
  • dogecoinDogecoin (DOGE) $ 0.090126
  • usdsUSDS (USDS) $ 0.999219
  • whitebitWhiteBIT Coin (WBT) $ 51.10
  • leo-tokenLEO Token (LEO) $ 10.03
  • bitcoin-cashBitcoin Cash (BCH) $ 443.54
  • wrapped-stethWrapped stETH (WSTETH) $ 2,779.67
  • cardanoCardano (ADA) $ 0.238726
  • hyperliquidHyperliquid (HYPE) $ 35.04
  • wrapped-bitcoinWrapped Bitcoin (WBTC) $ 76,243.00
  • moneroMonero (XMR) $ 332.56
  • binance-bridged-usdt-bnb-smart-chainBinance Bridged USDT (BNB Smart Chain) (BSC-USD) $ 0.998762
  • chainlinkChainlink (LINK) $ 8.51
  • wrapped-beacon-ethWrapped Beacon ETH (WBETH) $ 2,466.93
  • ethena-usdeEthena USDe (USDE) $ 0.999371
  • canton-networkCanton (CC) $ 0.142770
  • stellarStellar (XLM) $ 0.163597
  • wrapped-eethWrapped eETH (WEETH) $ 2,465.31
  • memecoreMemeCore (M) $ 2.63
  • daiDai (DAI) $ 1.00
  • susdssUSDS (SUSDS) $ 1.08
  • usd1-wlfiUSD1 (USD1) $ 0.999632
  • litecoinLitecoin (LTC) $ 52.13
  • paypal-usdPayPal USD (PYUSD) $ 0.999802
  • coinbase-wrapped-btcCoinbase Wrapped BTC (CBBTC) $ 76,366.00
  • zcashZcash (ZEC) $ 236.38
  • rainRain (RAIN) $ 0.007978
  • hedera-hashgraphHedera (HBAR) $ 0.086672
  • wethWETH (WETH) $ 2,268.37
  • avalanche-2Avalanche (AVAX) $ 8.68
  • shiba-inuShiba Inu (SHIB) $ 0.000006
  • suiSui (SUI) $ 0.853158
  • usdt0USDT0 (USDT0) $ 0.998824
  • the-open-networkToncoin (TON) $ 1.22
  • crypto-com-chainCronos (CRO) $ 0.069053
  • bittensorBittensor (TAO) $ 302.75
  • world-liberty-financialWorld Liberty Financial (WLFI) $ 0.097899
  • hashnote-usycCircle USYC (USYC) $ 1.12
  • tether-goldTether Gold (XAUT) $ 4,605.47
  • pax-goldPAX Gold (PAXG) $ 4,623.94
  • ethena-staked-usdeEthena Staked USDe (SUSDE) $ 1.22
  • blackrock-usd-institutional-digital-liquidity-fundBlackRock USD Institutional Digital Liquidity Fund (BUIDL) $ 1.00
  • mantleMantle (MNT) $ 0.677316
  • uniswapUniswap (UNI) $ 3.32
  • polkadotPolkadot (DOT) $ 1.22
  • global-dollarGlobal Dollar (USDG) $ 0.999839
  • pi-networkPi Network (PI) $ 0.174526
  • okbOKB (OKB) $ 83.09
  • falcon-financeFalcon USD (USDF) $ 0.997865
  • skySky (SKY) $ 0.072906
  • aster-2Aster (ASTER) $ 0.674441
  • htx-daoHTX DAO (HTX) $ 0.000002
  • syrupusdcsyrupUSDC (SYRUPUSDC) $ 1.15
  • nearNEAR Protocol (NEAR) $ 1.16
  • aaveAave (AAVE) $ 93.83
  • pepePepe (PEPE) $ 0.000003
  • bitget-tokenBitget Token (BGB) $ 1.93
  • bfusdBFUSD (BFUSD) $ 0.999287
  • ondo-us-dollar-yieldOndo US Dollar Yield (USDY) $ 1.13
  • ripple-usdRipple USD (RLUSD) $ 1.00
  • ondo-financeOndo (ONDO) $ 0.262357
  • ethereum-classicEthereum Classic (ETC) $ 7.94
  • internet-computerInternet Computer (ICP) $ 2.22
  • janus-henderson-anemoy-treasury-fundJanus Henderson Anemoy Treasury Fund (JTRSY) $ 1.10
  • gatechain-tokenGate (GT) $ 6.55
  • usddUSDD (USDD) $ 0.999696
  • kucoin-sharesKuCoin (KCS) $ 7.92
  • quant-networkQuant (QNT) $ 70.01
  • jupiter-perpetuals-liquidity-provider-tokenJupiter Perpetuals Liquidity Provider Token (JLP) $ 4.00
  • polygon-ecosystem-tokenPOL (ex-MATIC) (POL) $ 0.090957
  • pump-funPump.fun (PUMP) $ 0.001615
  • eutblSpiko EU T-Bills Money Market Fund (EUTBL) $ 1.21
  • algorandAlgorand (ALGO) $ 0.101747
  • render-tokenRender (RENDER) $ 1.74
  • jito-staked-solJito Staked SOL (JITOSOL) $ 124.46
  • worldcoin-wldWorldcoin (WLD) $ 0.268840
  • usdtbUSDtb (USDTB) $ 0.999032
  • kelp-dao-restaked-ethKelp DAO Restaked ETH (RSETH) $ 2,404.69
  • nexoNEXO (NEXO) $ 0.859636
  • kaspaKaspa (KAS) $ 0.031268
  • binance-peg-wethBinance-Peg WETH (WETH) $ 2,262.26
  • morphoMorpho (MORPHO) $ 1.49
  • rocket-pool-ethRocket Pool ETH (RETH) $ 2,631.35
  • cosmosCosmos Hub (ATOM) $ 1.63
  • midnight-3Midnight (NIGHT) $ 0.049067
  • binance-bridged-usdc-bnb-smart-chainBinance Bridged USDC (BNB Smart Chain) (USDC) $ 0.999945
  • superstate-short-duration-us-government-securities-fund-ustbSuperstate Short Duration U.S. Government Securities Fund (USTB) (USTB) $ 11.04
  • ethenaEthena (ENA) $ 0.081933
  • wbnbWrapped BNB (WBNB) $ 759.61
  • aptosAptos (APT) $ 0.862242
  • ignition-fbtcFunction FBTC (FBTC) $ 76,389.00
  • official-trumpOfficial Trump (TRUMP) $ 2.85
  • flare-networksFlare (FLR) $ 0.007460
  • stable-2​​Stable (STABLE) $ 0.028709
  • filecoinFilecoin (FIL) $ 0.811213
  • beldexBeldex (BDX) $ 0.079976
  • syrupusdtsyrupUSDT (SYRUPUSDT) $ 1.11
  • xdce-crowd-saleXDC Network (XDC) $ 0.030812
  • yldsYLDS (YLDS) $ 0.999909
  • ousgOUSG (OUSG) $ 114.78
  • binance-staked-solBinance Staked SOL (BNSOL) $ 108.24
  • hash-2Provenance Blockchain (HASH) $ 0.010386
  • ghoGHO (GHO) $ 0.999574
  • vechainVeChain (VET) $ 0.006727
  • justJUST (JST) $ 0.064068
  • usual-usdUsual USD (USD0) $ 0.998625
  • jupiter-exchange-solanaJupiter (JUP) $ 0.154812
  • new-x-ceo-is-backNEW X CEO IS BACK (XFLOKI) $ 0.506041
  • bridged-usdc-polygon-pos-bridgePolygon Bridged USDC (Polygon PoS) (USDC.E) $ 0.999720
  • arbitrumArbitrum (ARB) $ 0.090812
  • solv-btcSolv Protocol BTC (SOLVBTC) $ 76,461.00
  • fetch-aiArtificial Superintelligence Alliance (FET) $ 0.228367
  • lombard-staked-btcLombard Staked BTC (LBTC) $ 76,491.00
  • bonkBonk (BONK) $ 0.000006
  • true-usdTrueUSD (TUSD) $ 0.998039
  • a7a5A7A5 (A7A5) $ 0.012199
  • clbtcclBTC (CLBTC) $ 76,920.00
  • layerzeroLayerZero (ZRO) $ 1.89
  • pancakeswap-tokenPancakeSwap (CAKE) $ 1.33
  • virtual-protocolVirtuals Protocol (VIRTUAL) $ 0.635425
  • chilizChiliz (CHZ) $ 0.039962
  • euro-coinEURC (EURC) $ 1.15
  • blockstackStacks (STX) $ 0.219094
  • stakewise-v3-osethStakeWise Staked ETH (OSETH) $ 2,419.84
  • janus-henderson-anemoy-aaa-clo-fundJanus Henderson Anemoy AAA CLO Fund (JAAA) $ 1.03
  • first-digital-usdFirst Digital USD (FDUSD) $ 0.998704
  • kinetic-staked-hypeKinetiq Staked HYPE (KHYPE) $ 33.97
  • tbtctBTC (TBTC) $ 70,942.00
  • pudgy-penguinsPudgy Penguins (PENGU) $ 0.006258
  • dashDash (DASH) $ 30.01
  • wrappedm-by-m0WrappedM by M0 (WM) $ 1.00
  • hastra-primePRIME (PRIME) $ 1.03
  • dexeDeXe (DEXE) $ 8.06
  • tezosTezos (XTZ) $ 0.344809
  • usxUSX (USX) $ 0.999400
  • kinesis-goldKinesis Gold (KAU) $ 149.27
  • c8ntinuumc8ntinuum (CTM) $ 0.087592
  • ether-fiEther.fi (ETHFI) $ 0.452356
  • sei-networkSei (SEI) $ 0.052087
  • mantle-staked-etherMantle Staked Ether (METH) $ 2,455.82
  • decredDecred (DCR) $ 20.08
  • adi-tokenADI (ADI) $ 4.31
  • polygon-pos-bridged-dai-polygon-posPolygon PoS Bridged DAI (Polygon POS) (DAI) $ 0.999983
  • sun-tokenSun Token (SUN) $ 0.017834
  • resolv-wstusrResolv wstUSR (WSTUSR) $ 1.13
  • apenftAINFT (NFT) $ 0.00000033
  • cocaCOCA (COCA) $ 1.30
  • gnosisGnosis (GNO) $ 120.27
  • curve-dao-tokenCurve DAO (CRV) $ 0.209278
  • doge-strategyDoge Strategy (DOGESTR) $ 0.288297
  • bittorrentBitTorrent (BTT) $ 0.00000031
  • liquid-staked-ethereumLiquid Staked ETH (LSETH) $ 2,406.26
  • usdaiUSDai (USDAI) $ 0.999914
  • arbitrum-bridged-wbtc-arbitrum-oneArbitrum Bridged WBTC (Arbitrum One) (WBTC) $ 76,200.00
  • venice-tokenVenice Token (VVV) $ 6.60
  • aerodrome-financeAerodrome Finance (AERO) $ 0.316503
  • kaiaKaia (KAIA) $ 0.049190
  • bitcoin-svBitcoin SV (BSV) $ 14.30
  • wrapped-flareWrapped Flare (WFLR) $ 0.009961
  • injective-protocolInjective (INJ) $ 2.79
  • fraxLegacy Frax Dollar (FRAX) $ 0.990347
  • l2-standard-bridged-weth-baseL2 Standard Bridged WETH (Base) (WETH) $ 2,266.86
  • lido-daoLido DAO (LDO) $ 0.318463
  • steakhouse-usdc-morpho-vaultSteakhouse USDC Morpho Vault (STEAKUSDC) $ 1.12
  • kinesis-silverKinesis Silver (KAG) $ 71.32
  • official-foOfficial FO (FO) $ 0.269323
  • conflux-tokenConflux (CFX) $ 0.051551
  • doublezeroDoubleZero (2Z) $ 0.076486
  • crvusdcrvUSD (CRVUSD) $ 0.999946
  • binance-peg-xrpBinance-Peg XRP (XRP) $ 1.59
  • jasmycoinJasmyCoin (JASMY) $ 0.005330
  • ether-fi-liquid-ethEther.Fi Liquid ETH (LIQUIDETH) $ 2,443.47
  • plasmaPlasma (XPL) $ 0.109158
  • renzo-restaked-ethRenzo Restaked ETH (EZETH) $ 2,421.84
  • riverRiver (RIVER) $ 13.26
  • noonNoon (NOON) $ 0.751949
  • stakestoneStakeStone (STO) $ 1.14
  • sbtc-2sBTC (SBTC) $ 77,039.00
  • celestiaCelestia (TIA) $ 0.286616
  • flokiFLOKI (FLOKI) $ 0.000027
  • the-graphThe Graph (GRT) $ 0.023693
  • jupiter-staked-solJupiter Staked SOL (JUPSOL) $ 115.56
  • iotaIOTA (IOTA) $ 0.058353
  • savings-usddSavings USDD (SUSDD) $ 1.03
  • monadMonad (MON) $ 0.023312
  • kite-2Kite (KITE) $ 0.140089
  • ape-and-pepeApe and Pepe (APEPE) $ 0.000001
  • msolMarinade Staked SOL (MSOL) $ 133.18
  • olympusOlympus (OHM) $ 15.62
  • arbitrum-bridged-weth-arbitrum-oneArbitrum Bridged WETH (Arbitrum One) (WETH) $ 2,265.06
  • spx6900SPX6900 (SPX) $ 0.262356

AI agents like OpenClaw could drain crypto wallets via ‘malicious skills’: CertiK

0 0


The widespread integration of AI assistants such as OpenClaw introduces critical security risks that open up users to unauthorized actions, data exposure, system compromises and drained crypto wallets, according to cybersecurity firm CertiK.

OpenClaw is a self-hosted AI agent that integrates with messaging platforms such as WhatsApp, Slack, and Telegram and can autonomously take actions on users’ computers, such as managing email, calendars, and files.

It’s estimated there are around 2 million active monthly users of the platform, according to Openclaw.vps. A McKinsey study in November revealed that 62% of survey respondents said their organizations were already experimenting with AI agents.

However, CertiK warns that it has become a “primary supply chain attack vector at scale.”

OpenClaw grew from a side project called Clawdbot, launched in November 2025, to over 300,000 GitHub stars, a bookmarking or “like” feature on the developer platform, signaling a surge in popularity but accumulating serious “security debt” in the process, noted CertiK.

However, within weeks of launch, Bitsight identified 30,000 internet-exposed instances of OpenClaw, and SecurityScorecard researchers found 135,000 instances across 82 countries, with 15,200 specifically vulnerable to remote code execution.

OpenClaw has also become the most “aggressively scrutinized AI agent platform from a security standpoint,” accumulating more than 280 GitHub Security Advisories, 100 Common Vulnerabilities and Exposures (CVEs), and a “string of ecosystem-level attacks” since its November launch, CertiK researchers wrote in a report shared with Cointelegraph.

Rapid growth of the OpenClaw ecosystem. Source: CertiK

Crypto wallet credentials at risk

Because OpenClaw acts as a bridge between external inputs and local system execution, “it introduces classic attack vectors,” the researchers said.

These include local gateway hijacking, where malicious websites or payloads could exploit the agent’s local machine presence to extract sensitive user data or execute unauthorized commands.

Related: SlowMist introduces Web3 security stack for autonomous AI agents

CertiK warned of the dangers of plugins, which could add channels, tools, HTTP routes, services, and providers, while malicious skills could be installed from local or marketplace sources.

Unlike traditional malware, “malicious skills” can manipulate behavior through natural language, resisting conventional scanning.

“Once launched, the malware can exfiltrate sensitive information such as passwords and cryptocurrency wallet credentials.”

Malicious backdoors may also be hidden within legitimate functional codebases, “where they fetch seemingly benign URLs that ultimately deliver shell commands or malware payloads,” they added.

CertiK researchers told Cointelegraph that attackers strategically seeded malicious skills across various high-value categories, “including utilities for Phantom, wallet trackers, insider-wallet finders, Polymarket tools, and Google Workspace integrations.”

“They cast a remarkably wide net across the crypto ecosystem, with the primary payload designed to target a large number of browser extension wallets simultaneously, such as MetaMask, Phantom, Trust Wallet, Coinbase Wallet, OKX Wallet, and many others,” they said.

The researchers added that there was a “clear overlap in tradecraft with the broader crypto-theft ecosystem, like social engineering, fake utility lures, credential theft, wallet-focused phishing.”

“These are all well-known plays from the crypto drainer playbook, and we did see them used here.

OpenClaw founder Peter Steinberg, who recently joined OpenAI, said they are working on improving OpenClaw’s security.

“Something that we worked on for the last two months is security. So things are a lot better on that front,” said Steinberg at the “ClawCon” event on Monday in Tokyo.

Don’t install OpenClaw unless you’re a geek

Earlier this month, cybersecurity firm OX Security reported a phishing campaign that used fake GitHub posts and a bogus “CLAW” token to lure OpenClaw developers into connecting crypto wallets.

CertiK advised ordinary users “who are not security professionals, developers, or experienced geeks,” not to install and use OpenClaw from scratch but wait for “more mature, hardened, and manageable versions.”

Cybersecurity company SlowMist introduced a security framework for AI agents earlier in March, pitching it as a “digital fortress” to defend against risks that come with autonomous systems handling onchain actions and digital assets.

Magazine: Banks want to run Vietnam’s crypto exchanges, Boyaa’s $70M BTC plan: Asia Express



Source link

Leave A Reply

Your email address will not be published.