Home TechnologyHundreds of Malicious Crypto Trading Add-Ons Found...
Technology⭐ Featured

Hundreds of Malicious Crypto Trading Add-Ons Found in Moltbot/OpenClaw

A security researcher found 386 malicious ‘skills’ published on ClawHub, a skill repository for the popular OpenClaw AI assistant project

7 April 2026 at 08:08 am
1 views
Hundreds of Malicious Crypto Trading Add-Ons Found in Moltbot/OpenClaw

A security researcher has recently uncovered a significant threat to cryptocurrency users, discovering 386 malicious 'skills' published on ClawHub, a repository for the popular OpenClaw AI assistant project. These malicious add-ons, known as 'skills,' are designed to exploit the OpenClaw platform, which is widely used by traders to automate their cryptocurrency trading activities.

OpenClaw, developed by Moltbot, is a powerful AI assistant that enables users to create custom trading bots and automate complex trading strategies. Its popularity stems from its flexibility and ease of use, allowing traders to leverage AI to make informed decisions in the volatile cryptocurrency market. However, the recent discovery of these malicious skills highlights a critical vulnerability in the platform's security measures.

The researcher, who wishes to remain anonymous, conducted a thorough examination of ClawHub, the official repository for OpenClaw skills. During this investigation, they identified 386 skills that were designed to steal user credentials, manipulate trades, and even drain funds from cryptocurrency wallets. These malicious add-ons were disguised as legitimate trading tools, making it challenging for users to distinguish them from benign skills.

Among the most common tactics employed by these malicious skills are phishing attacks and keylogging. The skills intercept user input, such as login credentials and private keys, and transmit this sensitive information to attackers. Additionally, some skills are programmed to execute trades that result in significant financial losses for the affected users, often through rapid and unauthorized transactions.

The presence of these malicious skills on ClawHub raises concerns about the security practices of the OpenClaw community. While OpenClaw's popularity undoubtedly benefits traders, the lack of robust security measures has inadvertently created an environment ripe for exploitation. The researcher has emphasized the need for improved monitoring and verification processes to ensure that only legitimate and secure skills are published on ClawHub.

In response to these findings, Moltbot, the developer of OpenClaw, has stated that they are actively working to enhance their security protocols. The company has pledged to implement stricter review processes for skills submitted to ClawHub, as well as to improve user authentication and data encryption to protect sensitive information.

Despite these assurances, cryptocurrency traders remain at risk, as the malicious skills have already been distributed and installed by unsuspecting users. Many traders who have incorporated these skills into their trading strategies are now facing significant financial losses and compromised security.

The discovery of these malicious add-ons serves as a stark reminder of the importance of vigilance in the rapidly evolving world of cryptocurrency trading. Users must be cautious when selecting and installing skills, and it is crucial for platforms like OpenClaw to prioritize security and user protection.

As the OpenClaw community navigates this newfound vulnerability, the broader cryptocurrency ecosystem must also confront the growing threat of malicious software and unscrupulous actors. The recent findings underscore the need for enhanced collaboration between developers, security researchers, and users to create a more secure and trustworthy digital landscape for all participants.

In conclusion, the discovery of 386 malicious skills on ClawHub highlights a critical security flaw in the OpenClaw AI assistant project. These add-ons pose a significant threat to cryptocurrency traders, exploiting the platform's popularity to steal credentials, manipulate trades, and drain funds. While Moltbot has pledged to improve security measures, the incident serves as a call to action for the entire cryptocurrency community to prioritize security and user protection in the face of evolving threats.

📰 Related News
Ekaya Banaras Founder Palak Shah’s ₹40 Lakh Billboard Mistake Became a Masterclass in Startup Marketing
Ekaya Banaras Founder Palak Shah’s ₹40 Lakh Billboard Mistake Became a Masterclass in Startup Marketing
Ekaya Banaras founder Palak Shah recently opened up about one of the most expensive mistakes she made while building her luxury textile brand. During the early years of the company, Shah rented a premium billboard near Delhi’s DLF Emporio to increase brand visibility. However, after forgetting to cancel the campaign, the hoarding reportedly continued running for months — resulting in losses of nearly ₹40 lakh. The incident has now become a viral example of how small operational oversights can turn into costly business lessons for startups and entrepreneurs.
28 May
Betting On AI: Jensen Huang And NVIDIA’s Rise To The Top
Betting On AI: Jensen Huang And NVIDIA’s Rise To The Top
Before AI was inevitable, it was a gamble—and Jensen Huang went all in.
14 Apr
Red Hat OpenShift sandboxed containers 1.12 and Red Hat build of Trustee 1.1 bring confidential computing to bare metal and AI workloads
Red Hat OpenShift sandboxed containers 1.12 and Red Hat build of Trustee 1.1 bring confidential computing to bare metal and AI workloads
Red Hat is excited to announce the release of Red Hat OpenShift sandboxed containers 1.12 and Red Hat build of Trustee 1.1, marking a major leap forward in our confidential computing journey. These releases graduate confidential containers on bare metal from …
14 Apr
Large AI firms hoovering maximum funding, not enough for smaller startups: Y Combinator’s Ankit Gupta
Large AI firms hoovering maximum funding, not enough for smaller startups: Y Combinator’s Ankit Gupta
YC Startup School: India’s talent pool across colleges and universities are key for building next-gen startups, which is what YC is looking to tap into. It wants to target entrepreneurs building for global markets, focussed on fintech, consumer, B2B, and ecom…
14 Apr
TSMC likely to book fourth straight quarter of record profit on insatiable AI demand
TSMC likely to book fourth straight quarter of record profit on insatiable AI demand
TSMC-RESULTS/ (PREVIEW, PIX):PREVIEW-TSMC likely to book fourth straight quarter of record profit on insatiable AI demand
14 Apr
TSMC likely to book fourth straight quarter of record profit on insatiable AI demand
TSMC likely to book fourth straight quarter of record profit on insatiable AI demand
Any profit result ‌above T$505.7 billion would mark the company's highest-ever quarterly net income ​and its ninth consecutive quarter of profit growth
14 Apr
TSMC likely to book fourth straight quarter of record profit on insatiable AI demand
TSMC likely to book fourth straight quarter of record profit on insatiable AI demand
On Thursday, ​TSMC is expected to report a net profit of $17.1 billion for the quarter, according to an LSEG SmartEstimate compiled from 19 analysts. The war in the Middle East threatens to disrupt the supply of production materials for semiconductors such as…
14 Apr
If we can’t kick the habit, how do we manage AI’s energy needs?
If we can’t kick the habit, how do we manage AI’s energy needs?
One can only hope that OpenAI’s Sam Altman was joking when he sought to justify the immense energy consumption of artificial intelligence
14 Apr
What caused Nvidia Blackwell GPU prices to spike? #tech
What caused Nvidia Blackwell GPU prices to spike? #tech
Blackwell GPU hourly “rent” surges on agentic AI demand A compute pricing index tracking hourly costs for Nvidia Blackwell GPUs shows a sharp climb: hourly rental hit $4.08 , up 48% from $2.75 just two months earlier. The reported driver is rising demand tied…
14 Apr
Anthropic Releases Claude Mythos Preview with Cybersecurity Capabilities but Withholds Public Access
Anthropic Releases Claude Mythos Preview with Cybersecurity Capabilities but Withholds Public Access
Anthropic has introduced Claude Mythos Preview, its most advanced AI model, improving significantly in reasoning, coding, and cybersecurity. Unlike previous releases, it will not be publicly available. Access is limited to a consortium of tech companies throu…
14 Apr