Cointime

Download App
iOS & Android

AI agents like OpenClaw could drain crypto wallets via ‘malicious skills’: CertiK

Validated Individual Expert

The widespread integration of AI assistants such as OpenClaw introduces critical security risks that open up users to unauthorized actions, data exposure, system compromises and drained crypto wallets, according to cybersecurity firm CertiK.

OpenClaw is a self-hosted AI agent that integrates with messaging platforms such as WhatsApp, Slack, and Telegram and can autonomously take actions on users' computers, such as managing email, calendars, and files. 

It’s estimated there are around 2 million active monthly users of the platform, according to Openclaw.vps. A McKinsey study in November revealed that 62% of survey respondents said their organizations were already experimenting with AI agents.

However, CertiK warns that it has become a “primary supply chain attack vector at scale.”

OpenClaw grew from a side project called Clawdbot, launched in November 2025, to over 300,000 GitHub stars, a bookmarking or “like” feature on the developer platform, signaling a surge in popularity but accumulating serious “security debt” in the process, noted CertiK. 

However, within weeks of launch, Bitsight identified 30,000 internet-exposed instances of OpenClaw, and SecurityScorecard researchers found 135,000 instances across 82 countries, with 15,200 specifically vulnerable to remote code execution.

OpenClaw has also become the most “aggressively scrutinized AI agent platform from a security standpoint,” accumulating more than 280 GitHub Security Advisories, 100 Common Vulnerabilities and Exposures (CVEs), and a “string of ecosystem-level attacks” since its November launch, CertiK researchers wrote in a report shared with Cointelegraph.

Rapid growth of the OpenClaw ecosystem. Source: CertiK 

Crypto wallet credentials at risk

Because OpenClaw acts as a bridge between external inputs and local system execution, “it introduces classic attack vectors,” the researchers said.

These include local gateway hijacking, where malicious websites or payloads could exploit the agent’s local machine presence to extract sensitive user data or execute unauthorized commands.

CertiK warned of the dangers of plugins, which could add channels, tools, HTTP routes, services, and providers, while malicious skills could be installed from local or marketplace sources. 

Unlike traditional malware, “malicious skills” can manipulate behavior through natural language, resisting conventional scanning. 

“Once launched, the malware can exfiltrate sensitive information such as passwords and cryptocurrency wallet credentials.”

Malicious backdoors may also be hidden within legitimate functional codebases, “where they fetch seemingly benign URLs that ultimately deliver shell commands or malware payloads,” they added.

CertiK researchers told Cointelegraph that attackers strategically seeded malicious skills across various high-value categories, “including utilities for Phantom, wallet trackers, insider-wallet finders, Polymarket tools, and Google Workspace integrations.” 

“They cast a remarkably wide net across the crypto ecosystem, with the primary payload designed to target a large number of browser extension wallets simultaneously, such as MetaMask, Phantom, Trust Wallet, Coinbase Wallet, OKX Wallet, and many others,” they said.

The researchers added that there was a “clear overlap in tradecraft with the broader crypto-theft ecosystem, like social engineering, fake utility lures, credential theft, wallet-focused phishing.”

“These are all well-known plays from the crypto drainer playbook, and we did see them used here.

OpenClaw founder Peter Steinberg, who recently joined OpenAI, said they are working on improving OpenClaw’s security.

"Something that we worked on for the last two months is security. So things are a lot better on that front," said Steinberg at the "ClawCon" event on Monday in Tokyo.

Don’t install OpenClaw unless you’re a geek

Earlier this month, cybersecurity firm OX Security reported a phishing campaign that used fake GitHub posts and a bogus “CLAW” token to lure OpenClaw developers into connecting crypto wallets.

CertiK advised ordinary users “who are not security professionals, developers, or experienced geeks,” not to install and use OpenClaw from scratch but wait for “more mature, hardened, and manageable versions.” 

Cybersecurity company SlowMist introduced a security framework for AI agents earlier in March, pitching it as a “digital fortress” to defend against risks that come with autonomous systems handling onchain actions and digital assets.

Comments

All Comments

Recommended for you

  • BTC Briefly Drops Below $60,000

    Market data shows that BTC briefly dropped below $60,000, currently recovering to $61,290.9, with a 24-hour decline of 3.5%. The market is experiencing significant volatility, so please ensure proper risk management.

  • Yili Hua: US Stocks Correct as Expected, Decline Faster Than Anticipated

    On June 5, Liquid Capital (formerly LD Capital) founder Yili Hua stated, "As we anticipated, US stocks have begun to correct, and expectations for interest rate cuts have changed. Trading is always the most challenging task; getting it right ten times and wrong once can lead to problems. It is essential to remain cautious and manage risks. The speed of this decline following the rebound has far exceeded expectations. However, it also comes with greater opportunities; historically, bear markets have been the time to make money, while bull markets often lead to losses."

  • Fed's Harker: Maintaining Stable Rates is Reasonable for Now

    On June 5, Fed's Harker stated that it may soon be time to adjust interest rates. Given the uncertainty, maintaining stable rates is reasonable at this time.

  • President Trump: Recent Employment Report is Strong, Stock Market Should Rise, Not Fall

    On June 5, U.S. President Trump stated that the recently released employment report is very strong, and the stock market should rise, not fall. This has been the case for the past 200 years. Economic growth does not mean inflation!

  • SpaceX's Initial IPO Oversubscribed

    On June 5, according to media reports, the number of subscriptions attracted by SpaceX's initial public offering (IPO) exceeded the number of shares available.

  • Strong U.S. Labor Market, but Consumers May Worry About Negative Real Wage Growth

    On June 5, Brent Schutte, Chief Investment Officer of Northwestern Mutual Wealth Management, stated that the U.S. labor market has moved away from the weak and limited growth experienced in 2025, showing signs of recovery and broader expansion. In 2025, the non-cyclical healthcare and social assistance sectors contributed to all job growth. The diffusion index, which had been below 50 for nine months in 2025, has rebounded to above 50 in the last five months, reaching 54.4 in May. The good news for consumers is that the labor market is strong and employment is stable. However, concerns about future spending arise as real wages are experiencing negative growth, with average hourly earnings up 3.4% year-on-year and inflation at 3.8%. The Federal Reserve may lean towards a wait-and-see approach, but its focus is likely to shift towards the inflation aspects of monetary policy.

  • Nasdaq China Golden Dragon Index Falls by 2%

    The Nasdaq China Golden Dragon Index has declined by 2%, with Baidu (BIDU.O) dropping nearly 7%, NIO (NIO.N) and Xpeng Motors (XPEV.N) falling over 3%, and Alibaba (BABA.N) decreasing by 1.3%.

  • Spot Silver Falls Below $70/Ounce; Spot Gold Drops Over $100 in a Day

    On June 5, spot silver fell below $70 per ounce for the first time since April 7, with a daily decline of 5.4%. Spot gold also dropped over $100 in a day, currently priced at $4,375.35 per ounce, reflecting a decrease of 2.24%.

  • US Optical Communication Stocks Plummet, Mavenir Technologies Drops Over 8%

    On June 5, US optical communication concept stocks collectively declined, with Mavenir Technologies and Nokia falling over 8%, Ciena and Coherent dropping over 7%, Corning decreasing over 6%, and Lumentum falling over 4%.

  • Cryptocurrency Total Market Cap Falls Below $2.2 Trillion

    On June 5, data from CoinGecko shows that the current total market cap of cryptocurrencies is $2.181 trillion, with a 24-hour decline of 5.0%. Bitcoin accounts for 55.8% of the market cap, while Ethereum accounts for 8.95%.