Cointime

Download App
iOS & Android

AI agents like OpenClaw could drain crypto wallets via ‘malicious skills’: CertiK

Validated Individual Expert

The widespread integration of AI assistants such as OpenClaw introduces critical security risks that open up users to unauthorized actions, data exposure, system compromises and drained crypto wallets, according to cybersecurity firm CertiK.

OpenClaw is a self-hosted AI agent that integrates with messaging platforms such as WhatsApp, Slack, and Telegram and can autonomously take actions on users' computers, such as managing email, calendars, and files. 

It’s estimated there are around 2 million active monthly users of the platform, according to Openclaw.vps. A McKinsey study in November revealed that 62% of survey respondents said their organizations were already experimenting with AI agents.

However, CertiK warns that it has become a “primary supply chain attack vector at scale.”

OpenClaw grew from a side project called Clawdbot, launched in November 2025, to over 300,000 GitHub stars, a bookmarking or “like” feature on the developer platform, signaling a surge in popularity but accumulating serious “security debt” in the process, noted CertiK. 

However, within weeks of launch, Bitsight identified 30,000 internet-exposed instances of OpenClaw, and SecurityScorecard researchers found 135,000 instances across 82 countries, with 15,200 specifically vulnerable to remote code execution.

OpenClaw has also become the most “aggressively scrutinized AI agent platform from a security standpoint,” accumulating more than 280 GitHub Security Advisories, 100 Common Vulnerabilities and Exposures (CVEs), and a “string of ecosystem-level attacks” since its November launch, CertiK researchers wrote in a report shared with Cointelegraph.

Rapid growth of the OpenClaw ecosystem. Source: CertiK 

Crypto wallet credentials at risk

Because OpenClaw acts as a bridge between external inputs and local system execution, “it introduces classic attack vectors,” the researchers said.

These include local gateway hijacking, where malicious websites or payloads could exploit the agent’s local machine presence to extract sensitive user data or execute unauthorized commands.

CertiK warned of the dangers of plugins, which could add channels, tools, HTTP routes, services, and providers, while malicious skills could be installed from local or marketplace sources. 

Unlike traditional malware, “malicious skills” can manipulate behavior through natural language, resisting conventional scanning. 

“Once launched, the malware can exfiltrate sensitive information such as passwords and cryptocurrency wallet credentials.”

Malicious backdoors may also be hidden within legitimate functional codebases, “where they fetch seemingly benign URLs that ultimately deliver shell commands or malware payloads,” they added.

CertiK researchers told Cointelegraph that attackers strategically seeded malicious skills across various high-value categories, “including utilities for Phantom, wallet trackers, insider-wallet finders, Polymarket tools, and Google Workspace integrations.” 

“They cast a remarkably wide net across the crypto ecosystem, with the primary payload designed to target a large number of browser extension wallets simultaneously, such as MetaMask, Phantom, Trust Wallet, Coinbase Wallet, OKX Wallet, and many others,” they said.

The researchers added that there was a “clear overlap in tradecraft with the broader crypto-theft ecosystem, like social engineering, fake utility lures, credential theft, wallet-focused phishing.”

“These are all well-known plays from the crypto drainer playbook, and we did see them used here.

OpenClaw founder Peter Steinberg, who recently joined OpenAI, said they are working on improving OpenClaw’s security.

"Something that we worked on for the last two months is security. So things are a lot better on that front," said Steinberg at the "ClawCon" event on Monday in Tokyo.

Don’t install OpenClaw unless you’re a geek

Earlier this month, cybersecurity firm OX Security reported a phishing campaign that used fake GitHub posts and a bogus “CLAW” token to lure OpenClaw developers into connecting crypto wallets.

CertiK advised ordinary users “who are not security professionals, developers, or experienced geeks,” not to install and use OpenClaw from scratch but wait for “more mature, hardened, and manageable versions.” 

Cybersecurity company SlowMist introduced a security framework for AI agents earlier in March, pitching it as a “digital fortress” to defend against risks that come with autonomous systems handling onchain actions and digital assets.

Comments

All Comments

Recommended for you

  • Anthropic Chooses Nasdaq for IPO

    On September 14, Business Insider reported, citing an informed source, that Anthropic has selected Nasdaq as the potential listing venue for its IPO. According to another insider, the company, which plans to go public in October, has chosen Nasdaq, marking a significant win for the exchange in its competitive landscape. Earlier this year, Nasdaq successfully secured the listing of SpaceX, which is valued at $1.75 trillion, while some estimates suggest that Anthropic's valuation could reach $2 trillion, although this figure has not yet been finalized. Previously, OpenAI CEO Sam Altman stated that OpenAI would not go public at this time due to concerns regarding the existential threats AI may pose to humanity.

  • Anthropic Chooses Nasdaq for IPO

    On September 14, Business Insider reported, citing an informed source, that Anthropic has chosen Nasdaq as the potential listing venue for its IPO. According to another source, the company, which plans to go public in October, selecting Nasdaq signifies a significant win in the competition among exchanges. Earlier this year, Nasdaq successfully secured the listing of SpaceX, which is valued at $1.75 trillion, while some estimates suggest that Anthropic's valuation could reach $2 trillion, although this figure has not yet been finalized. Previously, OpenAI CEO Sam Altman stated that OpenAI would not go public at this time due to concerns regarding the existential threats AI may pose to humanity.

  • Anthropic Chooses Nasdaq for IPO

    On September 14, Business Insider reported, citing an informed source, that Anthropic has selected Nasdaq as the potential listing venue for its IPO. According to another insider, the company, which plans to go public in October, has chosen Nasdaq, marking a significant win for the exchange in its competitive landscape. Earlier this year, Nasdaq successfully secured the listing for SpaceX, which is valued at $1.75 trillion. Some estimates suggest that Anthropic's valuation could reach $2 trillion, although this figure has not yet been finalized. Previously, OpenAI CEO Sam Altman stated that OpenAI would not go public at this time due to concerns about the existential threats AI may pose to humanity.

  • Bitfinex Sees 1,377 BTC Inflow in 24 Hours

    According to monitoring by AiCoin, there has been a significant flow of funds at the Bitfinex exchange. In the past 24 hours, the exchange's wallet has received an inflow of 1,377 BTC, valued at $138 million. Currently, its BTC wallet balance stands at 420,400 BTC.

  • Bitfinex Sees 1,377 BTC Inflow in 24 Hours

    According to monitoring by AiCoin, there has been a significant flow of funds at the Bitfinex exchange. In the past 24 hours, the exchange's wallet has received an inflow of 1,377 BTC, valued at $138 million. Currently, its BTC wallet balance stands at 420,400 BTC.

  • Trump: Iran War Will End, Possibly Before Midterm Elections

    On September 13, U.S. President Trump stated that the Iran war will end, possibly before the midterm elections or immediately after. Iran is very eager to reach an agreement. He does not care whether Gulf countries meet with Iran, as that is their choice. When asked if the artificial intelligence industry should slow its development pace, Trump remarked that whoever wins in artificial intelligence will win the future.

  • Trump: Iran War Will End, Possibly Before Midterm Elections

    On September 13, U.S. President Trump stated that the Iran war will end, potentially before the midterm elections or immediately after. Iran is very eager to reach an agreement. He does not care whether Gulf countries meet with Iran, as that is their choice. When asked if the artificial intelligence industry should slow down its development pace, Trump remarked that whoever wins in AI will win the future.

  • Hassett: Cautious Approach to Interest Rate Hikes

    On September 3, White House economic advisor Hassett stated that he would take a cautious approach to interest rate hikes based on inflation data. Previously, when asked whether the Federal Reserve would raise interest rates in its decision next week, Trump said, 'I don't know, but we should have the lowest interest rates in the world.' (CLS)

  • Hassett: Cautious Approach to Interest Rate Hikes

    On September 3, White House economic advisor Hassett stated that he would take a cautious approach to interest rate hikes based on inflation data. Previously, when asked whether the Federal Reserve would raise rates at its decision next week, Trump said, 'I don't know, but we should have the lowest rates in the world.' (CLS)

  • Trump: Whoever Wins AI, Wins the Future

    On September 3, U.S. President Trump was asked whether the artificial intelligence industry should slow down its development pace. He stated that whoever wins in artificial intelligence will win the future. We can set up safeguards regarding AI, but some voices are overly negative. (CLS)