Cointime

Download App
iOS & Android

AI agents like OpenClaw could drain crypto wallets via ‘malicious skills’: CertiK

Validated Individual Expert

The widespread integration of AI assistants such as OpenClaw introduces critical security risks that open up users to unauthorized actions, data exposure, system compromises and drained crypto wallets, according to cybersecurity firm CertiK.

OpenClaw is a self-hosted AI agent that integrates with messaging platforms such as WhatsApp, Slack, and Telegram and can autonomously take actions on users' computers, such as managing email, calendars, and files. 

It’s estimated there are around 2 million active monthly users of the platform, according to Openclaw.vps. A McKinsey study in November revealed that 62% of survey respondents said their organizations were already experimenting with AI agents.

However, CertiK warns that it has become a “primary supply chain attack vector at scale.”

OpenClaw grew from a side project called Clawdbot, launched in November 2025, to over 300,000 GitHub stars, a bookmarking or “like” feature on the developer platform, signaling a surge in popularity but accumulating serious “security debt” in the process, noted CertiK. 

However, within weeks of launch, Bitsight identified 30,000 internet-exposed instances of OpenClaw, and SecurityScorecard researchers found 135,000 instances across 82 countries, with 15,200 specifically vulnerable to remote code execution.

OpenClaw has also become the most “aggressively scrutinized AI agent platform from a security standpoint,” accumulating more than 280 GitHub Security Advisories, 100 Common Vulnerabilities and Exposures (CVEs), and a “string of ecosystem-level attacks” since its November launch, CertiK researchers wrote in a report shared with Cointelegraph.

Rapid growth of the OpenClaw ecosystem. Source: CertiK 

Crypto wallet credentials at risk

Because OpenClaw acts as a bridge between external inputs and local system execution, “it introduces classic attack vectors,” the researchers said.

These include local gateway hijacking, where malicious websites or payloads could exploit the agent’s local machine presence to extract sensitive user data or execute unauthorized commands.

CertiK warned of the dangers of plugins, which could add channels, tools, HTTP routes, services, and providers, while malicious skills could be installed from local or marketplace sources. 

Unlike traditional malware, “malicious skills” can manipulate behavior through natural language, resisting conventional scanning. 

“Once launched, the malware can exfiltrate sensitive information such as passwords and cryptocurrency wallet credentials.”

Malicious backdoors may also be hidden within legitimate functional codebases, “where they fetch seemingly benign URLs that ultimately deliver shell commands or malware payloads,” they added.

CertiK researchers told Cointelegraph that attackers strategically seeded malicious skills across various high-value categories, “including utilities for Phantom, wallet trackers, insider-wallet finders, Polymarket tools, and Google Workspace integrations.” 

“They cast a remarkably wide net across the crypto ecosystem, with the primary payload designed to target a large number of browser extension wallets simultaneously, such as MetaMask, Phantom, Trust Wallet, Coinbase Wallet, OKX Wallet, and many others,” they said.

The researchers added that there was a “clear overlap in tradecraft with the broader crypto-theft ecosystem, like social engineering, fake utility lures, credential theft, wallet-focused phishing.”

“These are all well-known plays from the crypto drainer playbook, and we did see them used here.

OpenClaw founder Peter Steinberg, who recently joined OpenAI, said they are working on improving OpenClaw’s security.

"Something that we worked on for the last two months is security. So things are a lot better on that front," said Steinberg at the "ClawCon" event on Monday in Tokyo.

Don’t install OpenClaw unless you’re a geek

Earlier this month, cybersecurity firm OX Security reported a phishing campaign that used fake GitHub posts and a bogus “CLAW” token to lure OpenClaw developers into connecting crypto wallets.

CertiK advised ordinary users “who are not security professionals, developers, or experienced geeks,” not to install and use OpenClaw from scratch but wait for “more mature, hardened, and manageable versions.” 

Cybersecurity company SlowMist introduced a security framework for AI agents earlier in March, pitching it as a “digital fortress” to defend against risks that come with autonomous systems handling onchain actions and digital assets.

Comments

All Comments

Recommended for you

  • BTC Surpasses $75,000

    Market data shows that BTC has surpassed $75,000, currently priced at $75,003.04, with a 24-hour increase of 0.85%. The market is experiencing significant volatility, so please ensure proper risk management.

  • Drift Secures $147.5 Million in Funding from Tether for User Recovery

    On April 16, Drift announced that the Drift Protocol has received support from Tether and other partners, with Tether contributing $127.5 million and other partners contributing $20 million to assist in user recovery following the attack on April 1. The support plan includes a $100 million revenue-linked credit line, ecosystem grants, and loans to market makers. Drift will establish a dedicated user recovery pool aimed at gradually addressing the $295 million in outstanding user losses as trading revenues increase. Additionally, Drift will issue independent recovery tokens to affected users, which represent a claim to the recovery pool and can be transferred. Drift is currently working on restarting the protocol and has hired Ottersec and Asymmetric for audits, while migrating the settlement layer from USDC to USDT. The previous attack resulted in the theft of approximately $295 million in assets, while the insurance fund's assets remained unaffected.

  • TAO Falls Below $240

    Market data shows that TAO has fallen below $240, currently priced at $239.9, with a 24-hour decline of 3.62%. The market is experiencing significant volatility, so please ensure proper risk management.

  • US Secretary: Military Ready to Resume Operations if Iran Fails to Reach Peace Agreement

    On April 16, US Secretary of Defense Lloyd Austin stated at a Pentagon press conference on Thursday that if Iran does not agree to a peace agreement, US troops stationed in the Middle East are prepared to resume military operations. "Iran, you can choose a prosperous future, a golden bridge, and we hope you do this for the Iranian people," he said. "But if Iran makes the wrong choice, they will face blockades, and their infrastructure, electricity, and energy will suffer bombings." As part of efforts to pressure Tehran to reach an agreement, the US military is implementing a blockade on all vessels attempting to enter or exit Iran.

  • U.S. Launches Operation 'Economic Fury' Against Iran

    On April 16, U.S. Secretary of Defense Lloyd Austin stated at a press conference that the U.S. Treasury Department is launching an operation codenamed 'Economic Fury' to 'maximize economic pressure on Iran.' (CCTV)

  • US Expands Shipping Blockade Against Iran

    According to a report by Reuters on the 16th, the US military announced that it has expanded the blockade on Iranian shipping materials, now including weapons, ammunition, crude oil, refined oil, steel, and aluminum. (Xinhua News Agency)

  • Abraxas Capital Deposits 1,993 Bitcoins Worth $148.32 Million to Kraken

    On April 16, according to monitoring by Lookonchain, Abraxas Capital (Alpha Bitcoin Fund) has just deposited 1,993 bitcoins, valued at $148.32 million, to Kraken. Since March 14, Abraxas Capital (Alpha Bitcoin Fund) has cumulatively deposited 9,582 bitcoins, worth $691 million, to Kraken, and currently holds 20,337 bitcoins, valued at $1.51 billion.

  • National Cyberspace Administration Continues to Address Online Financial Information Chaos

    On April 16, it was reported that the National Cyberspace Administration continues to rectify the chaos surrounding online financial information. (Xinhua News Agency)

  • China Responds to Trump's Sanctions on Countries Purchasing Iranian Oil

    On April 16, Foreign Ministry spokesperson Guo Jiaqin held a regular press conference. A Reuters reporter asked about U.S. President Trump's statement yesterday, in which he expressed confidence that China would not stop buying Iranian oil. He also mentioned that sanctions would be imposed on countries purchasing Iranian oil. Guo Jiaqin stated that China has always opposed illegal unilateral sanctions that lack international legal basis and are not authorized by the United Nations Security Council. (Beijing Daily)

  • Solana Institute-backed super PAC pours $8 million against Sherrod Brown in Ohio race

    Sentinel Action Fund said it will spend $8 million with its sister advocacy group to back Republican Senator Jon Husted against Sherrod Brown in the upcoming race.