Bitget warned users this week after its security team discovered malicious plugins on ClawHub, the community repository for the AI assistant OpenClaw. The exchangeBitget warned users this week after its security team discovered malicious plugins on ClawHub, the community repository for the AI assistant OpenClaw. The exchange

Malicious OpenClaw Plugins Target Crypto Traders, Bitget Urges Immediate Key Resets

2026/02/12 07:00
3 min read
hack 23

Bitget warned users this week after its security team discovered malicious plugins on ClawHub, the community repository for the AI assistant OpenClaw. The exchange said the entries were disguised as helpful “skills” but in several cases prompted people to paste terminal commands or to download utilities that quietly installed malware designed to steal account credentials, API keys and wallet data.

The mechanics are simple and effective. A skill will walk a user through a short setup and ask them to run a single obfuscated command; that command fetches and executes a remote script, which then scours the machine for browser sessions, saved keys and other secrets. In a number of reported cases, a malicious skill briefly appeared on ClawHub’s front page, raising the chance that nontechnical users would follow instructions without realizing the risk.

Security teams that have been scanning the marketplace say the scale is alarming. Audits of thousands of skills turned up well over three hundred entries that behave maliciously, with many delivering information-stealing payloads such as variants of Atomic Stealer and related trojans. Those findings have framed the incident as a coordinated supply-chain poisoning campaign rather than a handful of accidental bad uploads.

From Convenience to Compromise

Analysts say attackers relied heavily on social engineering, publishing skills that posed as crypto trading helpers or wallet utilities and instructing users to perform setup steps that seemed routine. In several incidents, skills uploaded within a window tricked users by mimicking legitimate tools, a technique that helped the malware spread before defenders removed the listings.

Part of the problem is the platform’s power. OpenClaw runs locally and can legitimately execute shell commands, read files and interact with networks on behalf of its user; that capability makes useful automations possible but also gives a malicious skill direct access to sensitive data. The OpenClaw project and several security vendors have begun adding automated scanning, including VirusTotal checks and blocking of suspicious bundles, but researchers say automated checks must be paired with stronger human review, tighter publishing rules and clearer warnings to end users.

For traders and exchanges, the message is immediate and practical. Bitget told customers to stop using third-party tools, plugins or bots to connect to trading accounts and to use only the official app or website for deposits, withdrawals and trading. The exchange also urged anyone who has authorized API keys for a plugin to revoke them, change passwords and enable two-factor authentication to reduce the chance of an account compromise.

The episode is a reminder that convenience and attack surface often rise together. Agent-style AI can automate tedious tasks and boost productivity, but community ecosystems that allow unvetted code create attractive avenues for attackers. Until marketplaces adopt stronger vetting and platforms build more robust safeguards, users should treat third-party skills as untrusted code, refuse to run unfamiliar terminal commands, rotate API keys regularly and isolate wallet operations on well-protected devices. Those habits remain the best short-term defense while the ecosystem catches up.

Market Opportunity
OpenClaw Logo
OpenClaw Price(OPENCLAW)
$0.0004754
$0.0004754$0.0004754
-34.63%
USD
OpenClaw (OPENCLAW) Live Price Chart
Disclaimer: The articles reposted on this site are sourced from public platforms and are provided for informational purposes only. They do not necessarily reflect the views of MEXC. All rights remain with the original authors. If you believe any content infringes on third-party rights, please contact [email protected] for removal. MEXC makes no guarantees regarding the accuracy, completeness, or timeliness of the content and is not responsible for any actions taken based on the information provided. The content does not constitute financial, legal, or other professional advice, nor should it be considered a recommendation or endorsement by MEXC.

You May Also Like

NVIDIA Partners With India’s Top Manufacturers in $134B AI Factory Push

NVIDIA Partners With India’s Top Manufacturers in $134B AI Factory Push

The post NVIDIA Partners With India’s Top Manufacturers in $134B AI Factory Push appeared on BitcoinEthereumNews.com. Alvin Lang Feb 18, 2026 01:02 NVIDIA teams
Share
BitcoinEthereumNews2026/02/18 09:12
Tesla's brand has gone negative, says investor who wants Rivian to buy the EV business

Tesla's brand has gone negative, says investor who wants Rivian to buy the EV business

Ross Gerber prominent Wall Street investor is calling on Tesla to sell its electric vehicle business to rival Rivian, saying the Tesla name has become a liability
Share
Cryptopolitan2026/02/18 09:38
Metaplanet Stock Slides as Top Japanese Bitcoin Treasury Sets Up Shop in Miami

Metaplanet Stock Slides as Top Japanese Bitcoin Treasury Sets Up Shop in Miami

The post Metaplanet Stock Slides as Top Japanese Bitcoin Treasury Sets Up Shop in Miami appeared on BitcoinEthereumNews.com. In brief Tokyo-listed Metaplanet is expanding to the U.S. Its Miami-based subsidiary will initially have $15 million in capital. The firm meanwhile closed on its $1.45 billion public offering. Metaplanet, a Tokyo-listed hotel group that owns $2.3 billion worth of Bitcoin, said on Wednesday that its business is expanding to the U.S. The firm, which owns more than 20,000 Bitcoin, is establishing a subsidiary in Miami, Florida, to “manage and grow income-generation activities,” according to a press release. Metaplanet said the wholly-owned firm, dubbed Metaplanet Income Corp., will initially have $15 million in capital. It will provide its parent company with a better opportunity to “pursue derivatives operations and related activities that produce revenue,” Metaplanet added. The company’s shares changed hands around $4.06, falling nearly 4% on Wednesday, according to Yahoo Finance. The company’s stock price has plunged roughly 68% over the past three months from $12.90, although it has still increased 74% year-to-date.  Founded in 1999, Metaplanet has managed budget hotels across Japan, including “love hotels,” but Wednesday’s announcement makes no mention of hospitality. Rather, Metaplanet said the new subsidiary will be separate from its treasury operations. In the second quarter, Metaplanet disclosed an operating profit of ¥817 million ($5.5 million) on ¥1.23 billion ($8.4 million) in total sales, according to a shareholder presentation.  The performance was largely driven by Metaplanet’s income-generation segment, which generated ¥1.13 billion ($7.7 million) by selling Bitcoin put options. The derivatives are only profitable for buyers when Bitcoin’s spot price falls below an option’s given strike price. “This business has become our engine of growth, generating consistent revenue and net income,” Metaplanet President Simon Gerovich said on X on Wednesday. Gerovich separately said on Wednesday that Metaplanet had officially closed on its $1.45 billion offering of 385 million shares. More than 70 investors…
Share
BitcoinEthereumNews2025/09/18 13:49