• bitcoinBitcoin (BTC) $ 60,608.00
  • ethereumEthereum (ETH) $ 1,553.35
  • tetherTether (USDT) $ 0.999518
  • bnbBNB (BNB) $ 573.65
  • usd-coinUSDC (USDC) $ 0.999723
  • xrpXRP (XRP) $ 1.08
  • solanaSolana (SOL) $ 62.01
  • tronTRON (TRX) $ 0.318643
  • staked-etherLido Staked Ether (STETH) $ 2,265.05
  • figure-helocFigure Heloc (FIGR_HELOC) $ 1.03
  • hyperliquidHyperliquid (HYPE) $ 58.76
  • dogecoinDogecoin (DOGE) $ 0.080719
  • usdsUSDS (USDS) $ 0.999576
  • leo-tokenLEO Token (LEO) $ 9.58
  • rainRain (RAIN) $ 0.012863
  • wrapped-stethWrapped stETH (WSTETH) $ 2,779.67
  • stellarStellar (XLM) $ 0.196159
  • zcashZcash (ZEC) $ 367.22
  • wrapped-bitcoinWrapped Bitcoin (WBTC) $ 76,243.00
  • canton-networkCanton (CC) $ 0.153668
  • binance-bridged-usdt-bnb-smart-chainBinance Bridged USDT (BNB Smart Chain) (BSC-USD) $ 0.998762
  • cardanoCardano (ADA) $ 0.154754
  • wrapped-beacon-ethWrapped Beacon ETH (WBETH) $ 2,466.93
  • moneroMonero (XMR) $ 301.51
  • chainlinkChainlink (LINK) $ 7.27
  • whitebitWhiteBIT Coin (WBT) $ 43.22
  • wrapped-eethWrapped eETH (WEETH) $ 2,465.31
  • usd1-wlfiUSD1 (USD1) $ 0.999493
  • ethena-usdeEthena USDe (USDE) $ 0.999423
  • susdssUSDS (SUSDS) $ 1.08
  • bitcoin-cashBitcoin Cash (BCH) $ 217.26
  • daiDai (DAI) $ 0.999625
  • the-open-networkToncoin (TON) $ 1.55
  • coinbase-wrapped-btcCoinbase Wrapped BTC (CBBTC) $ 76,366.00
  • memecoreMemeCore (M) $ 2.82
  • hedera-hashgraphHedera (HBAR) $ 0.078303
  • litecoinLitecoin (LTC) $ 42.60
  • wethWETH (WETH) $ 2,268.37
  • labLAB (LAB) $ 9.35
  • paypal-usdPayPal USD (PYUSD) $ 0.999522
  • avalanche-2Avalanche (AVAX) $ 6.62
  • usdt0USDT0 (USDT0) $ 0.998824
  • hashnote-usycCircle USYC (USYC) $ 1.13
  • suiSui (SUI) $ 0.696934
  • shiba-inuShiba Inu (SHIB) $ 0.000004
  • tether-goldTether Gold (XAUT) $ 4,284.87
  • crypto-com-chainCronos (CRO) $ 0.057573
  • global-dollarGlobal Dollar (USDG) $ 0.999973
  • nearNEAR Protocol (NEAR) $ 1.88
  • ethena-staked-usdeEthena Staked USDe (SUSDE) $ 1.22
  • blackrock-usd-institutional-digital-liquidity-fundBlackRock USD Institutional Digital Liquidity Fund (BUIDL) $ 1.00
  • ondo-us-dollar-yieldOndo US Dollar Yield (USDY) $ 1.13
  • pax-goldPAX Gold (PAXG) $ 4,293.65
  • bittensorBittensor (TAO) $ 192.08
  • world-liberty-financialWorld Liberty Financial (WLFI) $ 0.055411
  • mantleMantle (MNT) $ 0.515273
  • ripple-usdRipple USD (RLUSD) $ 0.999670
  • polkadotPolkadot (DOT) $ 0.937371
  • aster-2Aster (ASTER) $ 0.613903
  • ondo-financeOndo (ONDO) $ 0.322794
  • little-pepe-5Little Pepe (LILPEPE) $ 2.16
  • htx-daoHTX DAO (HTX) $ 0.000002
  • syrupusdcsyrupUSDC (SYRUPUSDC) $ 1.15
  • uniswapUniswap (UNI) $ 2.41
  • falcon-financeFalcon USD (USDF) $ 0.995095
  • okbOKB (OKB) $ 68.69
  • worldcoin-wldWorldcoin (WLD) $ 0.418841
  • usddUSDD (USDD) $ 0.999696
  • skySky (SKY) $ 0.057745
  • bfusdBFUSD (BFUSD) $ 0.999200
  • pi-networkPi Network (PI) $ 0.121912
  • bitget-tokenBitget Token (BGB) $ 1.82
  • internet-computerInternet Computer (ICP) $ 2.28
  • pepePepe (PEPE) $ 0.000003
  • humanityHumanity (H) $ 0.595089
  • morphoMorpho (MORPHO) $ 1.64
  • ethereum-classicEthereum Classic (ETC) $ 6.74
  • usdtbUSDtb (USDTB) $ 1.00
  • jupiter-perpetuals-liquidity-provider-tokenJupiter Perpetuals Liquidity Provider Token (JLP) $ 4.00
  • united-stablesUnited Stables (U) $ 0.999899
  • eutblSpiko EU T-Bills Money Market Fund (EUTBL) $ 1.21
  • blockchain-capitalBlockchain Capital (BCAP) $ 107.06
  • superstate-short-duration-us-government-securities-fund-ustbSuperstate Short Duration U.S. Government Securities Fund (USTB) (USTB) $ 11.10
  • quant-networkQuant (QNT) $ 63.64
  • jito-staked-solJito Staked SOL (JITOSOL) $ 124.46
  • dexeDeXe (DEXE) $ 19.86
  • aaveAave (AAVE) $ 60.75
  • kelp-dao-restaked-ethKelp DAO Restaked ETH (RSETH) $ 2,404.69
  • janus-henderson-anemoy-treasury-fundJanus Henderson Anemoy Treasury Fund (JTRSY) $ 1.11
  • ethenaEthena (ENA) $ 0.090919
  • binance-peg-wethBinance-Peg WETH (WETH) $ 2,262.26
  • render-tokenRender (RENDER) $ 1.62
  • rocket-pool-ethRocket Pool ETH (RETH) $ 2,631.35
  • kaspaKaspa (KAS) $ 0.030391
  • kucoin-sharesKuCoin (KCS) $ 6.18
  • binance-bridged-usdc-bnb-smart-chainBinance Bridged USDC (BNB Smart Chain) (USDC) $ 0.999945
  • cosmosCosmos Hub (ATOM) $ 1.61
  • algorandAlgorand (ALGO) $ 0.091605
  • wbnbWrapped BNB (WBNB) $ 759.61
  • polygon-ecosystem-tokenPOL (ex-MATIC) (POL) $ 0.075389
  • ignition-fbtcFunction FBTC (FBTC) $ 76,389.00
  • stable-2​​Stable (STABLE) $ 0.032166
  • venice-tokenVenice Token (VVV) $ 16.03
  • nexoNEXO (NEXO) $ 0.733753
  • justJUST (JST) $ 0.082803
  • bianrensheng币安人生 (BinanceLife) (币安人生) $ 0.697812
  • syrupusdtsyrupUSDT (SYRUPUSDT) $ 1.11
  • gatechain-tokenGate (GT) $ 6.14
  • beldexBeldex (BDX) $ 0.078811
  • siren-2Siren (SIREN) $ 0.810122
  • binance-staked-solBinance Staked SOL (BNSOL) $ 108.24
  • xdce-crowd-saleXDC Network (XDC) $ 0.029283
  • ghoGHO (GHO) $ 0.999006
  • filecoinFilecoin (FIL) $ 0.719310
  • flare-networksFlare (FLR) $ 0.006620
  • audieraAudiera (BEAT) $ 1.90
  • usual-usdUsual USD (USD0) $ 0.998541
  • new-x-ceo-is-backNEW X CEO IS BACK (XFLOKI) $ 0.506041
  • bridged-usdc-polygon-pos-bridgePolygon Bridged USDC (Polygon PoS) (USDC.E) $ 0.999720
  • aptosAptos (APT) $ 0.646947
  • solv-btcSolv Protocol BTC (SOLVBTC) $ 76,461.00
  • yldsYLDS (YLDS) $ 0.999712
  • lombard-staked-btcLombard Staked BTC (LBTC) $ 76,491.00
  • injective-protocolInjective (INJ) $ 5.21
  • a7a5A7A5 (A7A5) $ 0.013100
  • jupiter-exchange-solanaJupiter (JUP) $ 0.154164
  • clbtcclBTC (CLBTC) $ 76,920.00
  • midnight-3Midnight (NIGHT) $ 0.030747
  • hash-2Provenance Blockchain (HASH) $ 0.009448
  • ousgOUSG (OUSG) $ 115.47
  • pump-funPump.fun (PUMP) $ 0.001417
  • arbitrumArbitrum (ARB) $ 0.078941
  • true-usdTrueUSD (TUSD) $ 1.00
  • stakewise-v3-osethStakeWise Staked ETH (OSETH) $ 2,419.84
  • usxUSX (USX) $ 0.999361
  • spiko-amundi-overnight-swap-fund-eurSpiko Amundi Overnight Swap Fund (EUR) (EURSAFO) $ 1.16
  • kinetic-staked-hypeKinetiq Staked HYPE (KHYPE) $ 33.97
  • euro-coinEURC (EURC) $ 1.15
  • tbtctBTC (TBTC) $ 70,942.00
  • fetch-aiArtificial Superintelligence Alliance (FET) $ 0.191725
  • wrappedm-by-m0WrappedM by M0 (WM) $ 1.00
  • janus-henderson-anemoy-aaa-clo-fundJanus Henderson Anemoy AAA CLO Fund (JAAA) $ 1.04
  • kite-2Kite (KITE) $ 0.175368
  • vechainVeChain (VET) $ 0.004688
  • dashDash (DASH) $ 31.14
  • pudgy-penguinsPudgy Penguins (PENGU) $ 0.006214
  • apxusdapxUSD (APXUSD) $ 0.915566
  • c8ntinuumc8ntinuum (CTM) $ 0.087592
  • pancakeswap-tokenPancakeSwap (CAKE) $ 1.18
  • mantle-staked-etherMantle Staked Ether (METH) $ 2,455.82
  • adi-tokenADI (ADI) $ 3.70
  • hastra-primePRIME (PRIME) $ 1.04
  • polygon-pos-bridged-dai-polygon-posPolygon PoS Bridged DAI (Polygon POS) (DAI) $ 0.999983
  • the9bitThe9bit (9BIT) $ 0.045599
  • resolv-wstusrResolv wstUSR (WSTUSR) $ 1.13
  • official-trumpOfficial Trump (TRUMP) $ 1.56
  • cocaCOCA (COCA) $ 1.30
  • bonkBonk (BONK) $ 0.000004
  • lighterLighter (LIT) $ 1.46
  • virtual-protocolVirtuals Protocol (VIRTUAL) $ 0.540683
  • doge-strategyDoge Strategy (DOGESTR) $ 0.288297
  • liquid-staked-ethereumLiquid Staked ETH (LSETH) $ 2,406.26
  • first-digital-usdFirst Digital USD (FDUSD) $ 0.997397
  • arbitrum-bridged-wbtc-arbitrum-oneArbitrum Bridged WBTC (Arbitrum One) (WBTC) $ 76,200.00
  • sun-tokenSun Token (SUN) $ 0.017241
  • terra-lunaTerra Luna Classic (LUNC) $ 0.000059
  • blockstackStacks (STX) $ 0.177725
  • kinesis-goldKinesis Gold (KAU) $ 137.19
  • wrapped-flareWrapped Flare (WFLR) $ 0.009961
  • sei-networkSei (SEI) $ 0.046492
  • aerodrome-financeAerodrome Finance (AERO) $ 0.317888
  • l2-standard-bridged-weth-baseL2 Standard Bridged WETH (Base) (WETH) $ 2,266.86
  • celestiaCelestia (TIA) $ 0.294494
  • steakhouse-usdc-morpho-vaultSteakhouse USDC Morpho Vault (STEAKUSDC) $ 1.12
  • curve-dao-tokenCurve DAO (CRV) $ 0.179258
  • fraxLegacy Frax Dollar (FRAX) $ 0.990767
  • spx6900SPX6900 (SPX) $ 0.292027
  • unibaseUnibase (UB) $ 0.107680
  • apenftAINFT (NFT) $ 0.00000027
  • binance-peg-xrpBinance-Peg XRP (XRP) $ 1.59
  • olympusOlympus (OHM) $ 17.47
  • ether-fi-liquid-ethEther.Fi Liquid ETH (LIQUIDETH) $ 2,443.47
  • usdgoUSDGO (USDGO) $ 0.999782
  • tezosTezos (XTZ) $ 0.238747
  • renzo-restaked-ethRenzo Restaked ETH (EZETH) $ 2,421.84
  • bittorrentBitTorrent (BTT) $ 0.00000026
  • noonNoon (NOON) $ 0.751949
  • chilizChiliz (CHZ) $ 0.024499
  • sbtc-2sBTC (SBTC) $ 77,039.00
  • kinesis-silverKinesis Silver (KAG) $ 67.41
  • ether-fiEther.fi (ETHFI) $ 0.283202
  • royal-dollarRoyal Dollar (RUSD) $ 0.999173
  • jupiter-staked-solJupiter Staked SOL (JUPSOL) $ 115.56
  • pyth-networkPyth Network (PYTH) $ 0.031455
  • savings-usddSavings USDD (SUSDD) $ 1.03
  • monadMonad (MON) $ 0.020656
  • jito-governance-tokenJito (JTO) $ 0.501614
  • zebec-networkZebec Network (ZBCN) $ 0.002447
  • msolMarinade Staked SOL (MSOL) $ 133.18
  • doublezeroDoubleZero (2Z) $ 0.068622

AI just bypassed the Cloudflare protection that DeFi needs

0 2


Despite launching countless branding exercises that feature the word “decentralization,” much of the crypto industry actually uses Cloudflare to defend large chunks of its user-facing infrastructure.

Indeed, Cloudflare protects crypto websites collectively processing billions of dollars worth of trades and receiving millions of visitors daily. However, this week, crypto learned that autonomous AI agents can apparently use an open-source library to walk right through several of Cloudflare’s lines of defense.

Most heard of the vulnerability from a headline about OpenClaw, an AI agent that runs on a Mac Mini or cloud server.

OpenClaws, formerly known as ClawdBots or MoltBots, can now use a free library called Scrapling to “bypass Cloudflare natively.”

“Scrape any website without getting blocked, with zero bot detection,” the developer wrote in a brief blurb on Github before releasing the code into the wild.

It soon rocketed to a #1 trending spot among Github repositories.

The age of homespun AI agents has arrived

Boasting concurrent, multi-session crawlers with realistic start/stop actions and proxy IP addresses, the Python library allows AI agents like OpenClaw and others to bypass “all types of Cloudflare’s Turnstiles and Interstitials.”

Not only that, its own benchmarks claim over 600 times the parsing speed of BeautifulSoup, a formerly impressive web crawler.

The age of homespun AI agents is here, and the traditional armor that crypto has employed to protect its websites against crawlers, spiders, Denial of Service (DoS) attacks, and hackers of all types is starting to crack.

Through the use of human-mimicking behavior and AI adaptation, an OpenClaw agent can trick sophisticated forms of bot detection. Even more devastatingly, it can operate on commodity hardware and volley attacks for a few cents.

DeFi keeps relying on Cloudflare while losing millions

Decentralized Finance (DeFi) has already learned — repeatedly and expensively — what happens when its Cloudflare-dependent front-ends fail.

Although it doesn’t have 1:1 similarity with the capabilities of Scrapling, the most obvious example of crypto’s reliance on Cloudflare remains BadgerDAO.

In December 2021, an attacker compromised a Cloudflare Workers API key.

The attacker used that key to inject a malicious script into BadgerDAO’s front-end, tricking users into signing token approvals. It drained $130 million.

Consider another example. Curve Finance suffered Domain Name System (DNS) hijacks in August 2022 and again in May 2025.

Each time, attackers accessed its registrar and redirected traffic away from Cloudflare’s nameservers to malicious clones.

The 2022 attack cost users over $500,000. The 2025 attack forced Curve to abandon its “.fi” TLD entirely and migrate to Curve.finance.

Read more: Saga becomes latest victim in DeFi hacking spree

The pattern only accelerated. In July 2024, a single DNS attack on Squarespace put 228 DeFi protocol websites at risk, including Compound and Celer Network.

Aerodrome Finance,a decentralized exchange (DEX) on Coinbase’s Base network, lost over $1 million in a November 2025 DNS hijack. OpenEden disclosed a DNS compromise on February 16, 2026. Curvance detected and blocked a front-end attack on the same day.

Every one of these attacks exploited the gap between decentralized smart contracts and the centralized web infrastructure that users actually touch: DNS records, content delivery network (CDN) scripts, and Cloudflare configurations.

Although Scrapling is too new to boast of any crypto hacks to date, there might be victims in coming days, unfortunately. Its primary intention is to scrape and download content, not hack Defi, of course. Hopefully, developers and OpenClaw users use it for its legal and intended purposes.

Scrapling lowers the Cloudflare shield

The traditional defense model assumed that bot detection, fingerprinting, and Cloudflare’s Turnstile challenges could keep automated traffic out. Scrapling breaks some of those assumptions through AI.

Its developer describes, in language probably only developers understand, about packaging TLS fingerprint spoofing, headless detection avoidance, Canvas noise generation, and WebRTC leak mitigation into a composable library.

A third party analysis noted that the core breakthrough “wasn’t a single new trick.” Instead, it was the combination of multiple AI skills to trick cybersecurity services.

Cloudflare’s own documentation warns developers to “never trust client-side validation alone.” Unfortunately, many DeFi frontends treat Cloudflare challenge widgets as sufficient, leaving backdoors open to tools that can fake a passed challenge on the client side.

The crypto industry spent five years and hundreds of millions in user losses learning that Cloudflare is a speed bump, not a wall. Scrapling just used AI to hop over again.



Source link

Leave A Reply

Your email address will not be published.