ClawHub Exposed for 1,184 Malicious Skills Targeting Wallet Keys and SSH Credentials

ClawHub Exposed for 1,184 Malicious Skills Targeting Wallet Keys and SSH Credentials

N
News Editor 01
2026-07-23 22:15:16
OpenClaw’s official marketplace ClawHub was found to host 1,184 malicious skills designed to steal wallet private keys, SSH credentials, and browser passwords, adding to concerns over default trust in AI tool ecosystems.
ClawHubOpenClawwallet-securityAI-securityWeb3-security

OpenClaw’s official skill marketplace, ClawHub, has been found to contain 1,184 malicious skill plugins capable of stealing SSH keys, crypto wallet private keys, browser passwords, and even planting reverse shell backdoors. SlowMist founder Cos pointed to the issue in a warning posted on X, saying the highest-ranked malicious skill carried 9 vulnerabilities and had already been downloaded thousands of times.

ClawHub serves as the official marketplace for OpenClaw, formerly known as clawbot. Users install third-party extensions there so AI agents can handle tasks ranging from code deployment to wallet operations. That setup creates a dangerous assumption: users are expected to trust what is listed before they can verify it.

Attack campaign expanded from 341 to 1,184 malicious skills

Security firm Koi Security first disclosed the campaign, named “ClawHavoc,” in late January and initially identified 341 malicious skills. Independent security researchers and Antiy CERT later expanded the count to 1,184, spread across 12 publisher accounts. One attacker using the alias hightower6eu was said to have uploaded 677 packages alone, more than half of the total.

The scale matters. A single actor was able to flood the marketplace with malicious content, while the platform’s review process failed to stop it. In practical terms, that means the threat was embedded directly in tools users might install for everyday workflows.

Malicious instructions were hidden in setup documentation

The skills were not presented as obvious malware. They were disguised as crypto trading bots, Solana wallet trackers, Polymarket strategy tools, and YouTube summarizers, complete with polished documentation. The key trap sat in the “prerequisites” section of the SKILL.md file, where users were instructed to copy an obfuscated shell script from an external site and run it in a terminal.

That script would then pull Atomic Stealer, or AMOS, from a C2 server. The report described AMOS as a macOS infostealer sold for $500 to $1,000 per month. Its collection range includes browser passwords, SSH keys, Telegram chat history, Phantom wallet private keys, exchange API keys, and files stored on the desktop and in documents folders.

Researchers also found typo-squatted domain names such as clawhub1, clawhubb, and cllawhub. Two skills themed around Polymarket reportedly contained reverse shell backdoors. The documentation also embedded prompts crafted to manipulate the OpenClaw agent itself, pushing the AI to recommend malicious commands back to the user. As Cos put it, text is no longer just text; it can become an instruction.

Moonwell incident cited as a separate warning on AI-assisted code

In the same warning, Cos referenced Moonwell’s oracle failure on February 15, which resulted in $1.78 million in bad debt. The issue came from code that calculated the dollar price of cbETH but failed to multiply the cbETH/ETH exchange rate by the ETH/USD price. That left cbETH valued at about $1.12 instead of its actual level near $2,200.

Liquidation bots then swept positions using cbETH as collateral, and 181 borrowers lost roughly $2.68 million. Blockchain security auditor Krum Pashov said the relevant GitHub commit was marked “Co-Authored-By: Claude Opus 4.6.” NeuralTrust described the flaw as code that looked correct, compiled successfully, and passed basic unit tests, but failed completely in a hostile DeFi environment.

According to the source material, human review, GitHub Copilot, and OpenZeppelin Code Inspector all missed the absent multiplication step. The community labeled the incident a major security failure in the era of “Vibe Coding.” The point was not limited to one protocol. AI tools are now part of the security surface.

Default trust in AI tools is becoming a Web3 risk

OpenClaw founder Peter Steinberger has since added a community reporting mechanism, with suspicious skills automatically hidden after 3 reports. Koi Security also released a scanning tool called Clawdex. Those measures came after the marketplace had already been polluted at scale.

The source argues that the deeper problem lies in the AI tool ecosystem’s default assumptions: trust that listed skills are safe, trust that AI recommendations are sound, and trust that generated code is production-ready. Once those systems are connected to wallets and DeFi protocols, a bad default can turn directly into financial loss. The article also cited VanEck data saying the crypto sector had more than 10,000 AI agents by the end of 2025, with the figure expected to exceed 1 million in 2026.

This article was originally published by Bit.Fan. For more cryptocurrency news and market insights, visit www.bit.fan.
500

Disclaimer:

The market information, project data, and third-party content displayed on this platform are for industry information sharing only and do not constitute any form of investment advice or return commitment.

Cryptocurrency trading carries high risks. Users should fully assess their risk tolerance and make independent decisions. All profits, losses, and legal responsibilities are borne by the users themselves.