Cointime

Download App
iOS & Android

AI agents like OpenClaw could drain crypto wallets via ‘malicious skills’: CertiK

Validated Individual Expert

The widespread integration of AI assistants such as OpenClaw introduces critical security risks that open up users to unauthorized actions, data exposure, system compromises and drained crypto wallets, according to cybersecurity firm CertiK.

OpenClaw is a self-hosted AI agent that integrates with messaging platforms such as WhatsApp, Slack, and Telegram and can autonomously take actions on users' computers, such as managing email, calendars, and files. 

It’s estimated there are around 2 million active monthly users of the platform, according to Openclaw.vps. A McKinsey study in November revealed that 62% of survey respondents said their organizations were already experimenting with AI agents.

However, CertiK warns that it has become a “primary supply chain attack vector at scale.”

OpenClaw grew from a side project called Clawdbot, launched in November 2025, to over 300,000 GitHub stars, a bookmarking or “like” feature on the developer platform, signaling a surge in popularity but accumulating serious “security debt” in the process, noted CertiK. 

However, within weeks of launch, Bitsight identified 30,000 internet-exposed instances of OpenClaw, and SecurityScorecard researchers found 135,000 instances across 82 countries, with 15,200 specifically vulnerable to remote code execution.

OpenClaw has also become the most “aggressively scrutinized AI agent platform from a security standpoint,” accumulating more than 280 GitHub Security Advisories, 100 Common Vulnerabilities and Exposures (CVEs), and a “string of ecosystem-level attacks” since its November launch, CertiK researchers wrote in a report shared with Cointelegraph.

Rapid growth of the OpenClaw ecosystem. Source: CertiK 

Crypto wallet credentials at risk

Because OpenClaw acts as a bridge between external inputs and local system execution, “it introduces classic attack vectors,” the researchers said.

These include local gateway hijacking, where malicious websites or payloads could exploit the agent’s local machine presence to extract sensitive user data or execute unauthorized commands.

CertiK warned of the dangers of plugins, which could add channels, tools, HTTP routes, services, and providers, while malicious skills could be installed from local or marketplace sources. 

Unlike traditional malware, “malicious skills” can manipulate behavior through natural language, resisting conventional scanning. 

“Once launched, the malware can exfiltrate sensitive information such as passwords and cryptocurrency wallet credentials.”

Malicious backdoors may also be hidden within legitimate functional codebases, “where they fetch seemingly benign URLs that ultimately deliver shell commands or malware payloads,” they added.

CertiK researchers told Cointelegraph that attackers strategically seeded malicious skills across various high-value categories, “including utilities for Phantom, wallet trackers, insider-wallet finders, Polymarket tools, and Google Workspace integrations.” 

“They cast a remarkably wide net across the crypto ecosystem, with the primary payload designed to target a large number of browser extension wallets simultaneously, such as MetaMask, Phantom, Trust Wallet, Coinbase Wallet, OKX Wallet, and many others,” they said.

The researchers added that there was a “clear overlap in tradecraft with the broader crypto-theft ecosystem, like social engineering, fake utility lures, credential theft, wallet-focused phishing.”

“These are all well-known plays from the crypto drainer playbook, and we did see them used here.

OpenClaw founder Peter Steinberg, who recently joined OpenAI, said they are working on improving OpenClaw’s security.

"Something that we worked on for the last two months is security. So things are a lot better on that front," said Steinberg at the "ClawCon" event on Monday in Tokyo.

Don’t install OpenClaw unless you’re a geek

Earlier this month, cybersecurity firm OX Security reported a phishing campaign that used fake GitHub posts and a bogus “CLAW” token to lure OpenClaw developers into connecting crypto wallets.

CertiK advised ordinary users “who are not security professionals, developers, or experienced geeks,” not to install and use OpenClaw from scratch but wait for “more mature, hardened, and manageable versions.” 

Cybersecurity company SlowMist introduced a security framework for AI agents earlier in March, pitching it as a “digital fortress” to defend against risks that come with autonomous systems handling onchain actions and digital assets.

Comments

All Comments

Recommended for you

  • Zuckerberg: Selling Computing Power for Short-term Profits Is Foolish

    On July 30, according to CCTV Finance, after the U.S. stock market closed on the 29th local time, Meta disclosed its second-quarter earnings report for 2026. Although quarterly revenue slightly exceeded expectations, net profit fell by 14%, and the massive AI capital expenditure squeezed cash flow, causing the company's stock price to drop over 8% in after-hours trading. In the earnings report, Meta adjusted its full-year capital expenditure forecast range to $130 billion to $145 billion, compared to the previous forecast of $125 billion to $145 billion. The sharp increase in AI capital expenditure has hurt the company's profitability and severely squeezed cash flow. Meta's free cash flow in the second quarter fell to its lowest level in nearly four years, reaching only $784 million. Facing market concerns, Meta CEO Zuckerberg stated in the earnings conference call on the 29th that the company's current massive investment is aimed at seizing the AI infrastructure window, and the returns will gradually materialize through multiple paths, including improvements in the core advertising business, enterprise services, and computing power leasing. When mentioning the possibility of "selling computing power," Zuckerberg said that Meta has received a large number of quotes for computing power, with prices far exceeding the company's procurement costs. However, Zuckerberg stated that merely selling computing power to obtain short-term profits is foolish, and a "significant portion" of Meta's computing power will be used to drive its own models and products.

  • Traders Increase Bets on BOE Rate Hikes, Market Pricing Shows 39-Basis-Point Hike by Year-End

    On July 30, traders increased their bets on the Bank of England raising interest rates, with market pricing indicating a 39-basis-point hike by the end of the year.

  • Bank of England Keeps Interest Rate Unchanged as Expected

    On July 30, the Bank of England kept its policy rate unchanged at 3.75% for the fifth consecutive meeting, in line with market expectations. (Jin Shi)

  • Bank of England sees 3 rate hike votes

    On July 30, the Bank of England: The interest rate decision this time saw a vote of 6-3 to keep rates unchanged versus a hike (compared to 7-2 in the previous meeting). Bank of England Monetary Policy Committee members Greene, Mann, and Chief Economist Pill supported a rate hike. (Jin10)

  • TSMC Leak Case: Two Former Engineers Sentenced to 10 and 6 Years Respectively

    On July 30, according to market sources, four former TSMC engineers—Chen Liming, Wu Bingjun, Ge Yiping, and Chen Weijie—were sentenced by the Taiwan Intellectual Property and Commercial Court in the first instance to 10 years, 3 years, 2 years, and 6 years in prison respectively for stealing and leaking confidential data including 2-nanometer process technology. Chen Liming and Chen Weijie appealed, but the Taiwan Supreme Court rejected the appeal on the 30th, and the two will be directly sent to prison. According to reports, Wu Bingjun and Ge Yiping did not appeal after the first-instance verdict, and the prosecution also did not appeal, so their sentences were finalized first. Chen Liming originally worked as a yield engineer at TSMC's Fab 12. After leaving, he moved to Tokyo Electron (Taiwan), a supplier of semiconductor manufacturing equipment to TSMC, to work in the marketing department. In an effort to perform well and secure more equipment supply positions for Tokyo Electron in TSMC's advanced process nodes, he repeatedly leveraged his former colleague relationships with Wu, Ge, and Chen, asking them to photograph TSMC's confidential files. The four engineers used the work laptops of the still-employed involved engineers to open confidential files for Chen Liming to photograph, or they photographed and transmitted the files to Chen Liming.

  • SK Hynix Rises Over 1% in Pre-Market Trading

    On July 30, SK Hynix ADR rose over 1% in pre-market trading, after previously falling nearly 5%. On the news front, SK Group Chairman Chey Tae-won purchased 3,620 shares of SK Hynix. Based on today's closing price of SK Hynix's Korean stock at 1,322,000 won (approximately $922.8), the total amount is about 4.8 billion won (approximately $3.34 million).

  • Iran's IRGC Claims Attack on US Base in Jordan Thursday Morning

    Iran's Islamic Revolutionary Guard Corps: Attacked a US military base in Jordan on Thursday morning local time. (Jin10)

  • SK Group Chairman Chey Tae-won Buys 3,620 Shares of SK Hynix Stock

    On July 30, according to Korean media, SK Group Chairman Chey Tae-won purchased 3,620 shares of SK Hynix stock.

  • Meta: Holds 20% Stake in Louisiana Data Center Project

    On July 30, Meta stated that it holds a 20% stake in the Louisiana data center project. Meta Platforms: In the three months ended June 30, employee compensation expenses included $1.18 billion in severance costs related to the layoff action in May 2026. (Jin Shi)

  • USD/JPY Briefly Drops 70 Points Then Quickly Rebounds

    USD/JPY briefly dropped 70 points then quickly rebounded, now down about 0.4% at 162.75. (Jin Shi)