BlockBeats News, February 20 — Co-founder of SlowMist, Yu Xian, reposted a security alert. Currently, OpenClaw’s ClawHub marketplace has identified 1,184 malicious skills that can steal SSH keys, crypto wallets, browser passwords, and open reverse shells. A single attacker has uploaded 677 packages. The top-ranked skill contains 9 vulnerabilities and has been downloaded thousands of times.
Yu Xian warned users that text is no longer just text, but instructions. It is recommended to use AI tools in a separate environment, as many OpenClaw skills pose potential risks. Additionally, in Web3 security, smart contracts are only part of the picture; the true causes of incidents have long gone beyond just the contracts. A few days ago, Moonwell was hacked for $1.78 million, with the flawed code originating from Co-Authored-By: Claude Opus 4.6.
Disclaimer: The information on this page may come from third parties and does not represent the views or opinions of Gate. The content displayed on this page is for reference only and does not constitute any financial, investment, or legal advice. Gate does not guarantee the accuracy or completeness of the information and shall not be liable for any losses arising from the use of this information. Virtual asset investments carry high risks and are subject to significant price volatility. You may lose all of your invested principal. Please fully understand the relevant risks and make prudent decisions based on your own financial situation and risk tolerance. For details, please refer to
Disclaimer.
Related Articles
Lido responds to liquidation event: a DeFi lending protocol oracle error caused the liquidation, unrelated to the Lido protocol
Lido responded to the liquidation event on March 10 caused by the CAPO oracle price error, stating that there will be no bad debt and that affected users will be fully compensated. The Lido Earn product was unaffected, and user funds are safe.
GateNews2m ago
BWA Chairman Dilip Chenoy Advocates Investor Education and Responsible Crypto Ecosystem
BWA Chairman Dilip Chenoy participated in the Q & A.
He called for thorough independent verification before crypto investment.
The immediate step for victims is to register a complaint with the authorities.
Dilip Chenoy, Chairman of Bharat Web3 Association (BWA), interacted with the media and pa
TheNewsCrypto2h ago
Aave Oracle Failure Triggers Chain Liquidation: $26 Million Position Vanishes, DAO Promises Full Compensation
On March 11th, the decentralized lending protocol Aave experienced a large-scale liquidation event due to a misconfiguration of the price oracle. Approximately 34 accounts were liquidated, involving $26 million. The issue stemmed from desynchronized CAPO mechanism settings, which caused a brief misjudgment of the wstETH price. Although some users were affected, the Aave protocol remained financially unaffected and will initiate a compensation mechanism. Following the incident, the market reaction was stable, and the AAVE price increased.
GateNews3h ago
French Cryptocurrency Robbery Reappears: Couple Threatened with Knife by Impersonators Claiming to Be Police, Forced to Transfer Nearly $1 Million in Bitcoin
On March 11, a violent robbery occurred in western Paris, France, where three assailants posing as police officers forced a couple to transfer approximately 900,000 euros worth of Bitcoin. The incident exposed the risks of "wrench attack," making France a high-risk area for such crimes. Law enforcement agencies have launched an investigation, and security experts warn cryptocurrency holders to prioritize personal safety and information protection.
GateNews3h ago
Bloomberg: Prince Group's Chen Zhi Demands NY Court "Return All Bitcoins," The Complete Record of a Money Laundering Empire's Fall
Bloomberg investigation reveals that Cambodian Crown Prince Group founder Chen Zhi has built a "pig slaughter" scam empire that earns 30 million USD daily through political and business connections. The empire ultimately collapsed after the United States confiscated 127,271 Bitcoins. Chen Zhi's criminal activities and international sanctions demonstrate the size and influence of his organization. Although he was arrested and extradited to China, the residual impact of the scam industry continues.
動區BlockTempo3h ago
Bitcoin ATMs are listed as major tools for scams, with annual losses exceeding hundreds of millions in the US and Australia.
The U.S. Department of the Treasury reports that Bitcoin ATMs are becoming tools for scams. In 2024, the FBI received over 10,900 complaints, with losses totaling approximately $246.7 million. Scammers exploit the anonymity and irreversibility of cryptocurrency ATMs, especially targeting the elderly. Australia is also facing similar challenges, with the industry calling for increased regulation and implementing transaction limits, but experts believe that limits alone are insufficient to curb scams.
MarketWhisper4h ago