PANews reported on February 20th that Yu Xian, founder of SlowMist, stated on the X platform that 1184 malicious skills have been discovered on OpenClaw's ClawHubPANews reported on February 20th that Yu Xian, founder of SlowMist, stated on the X platform that 1184 malicious skills have been discovered on OpenClaw's ClawHub

SlowMist Cosine: ClawHub Marketplace Discovers Malicious Skills Potentially Stealing SSH Keys, Cryptographic Wallets, etc.

2026/02/20 11:07
1 min read

PANews reported on February 20th that Yu Xian, founder of SlowMist, stated on the X platform that 1184 malicious skills have been discovered on OpenClaw's ClawHub marketplace. These skills steal SSH keys, encrypted wallets, browser passwords, and open reverse shells. One attacker alone uploaded 677 software packages. The top-ranked skill has nine vulnerabilities and has been downloaded thousands of times.

Yu Xian reminds users that text is no longer just text, but instructions. He recommends using AI tools in a separate environment, as many OpenClaw skills carry potential risks. Furthermore, contracts are only one part of Web3 security; the real causes of incidents are no longer limited to contracts. A few days ago, Moonwell suffered a $1.78 million theft, with the flawed code originating from Co-Authored-By: Claude Opus 4.6.

Market Opportunity
OpenClaw Logo
OpenClaw Price(OPENCLAW)
$0.0004051
$0.0004051$0.0004051
-6.03%
USD
OpenClaw (OPENCLAW) Live Price Chart
Disclaimer: The articles reposted on this site are sourced from public platforms and are provided for informational purposes only. They do not necessarily reflect the views of MEXC. All rights remain with the original authors. If you believe any content infringes on third-party rights, please contact service@support.mexc.com for removal. MEXC makes no guarantees regarding the accuracy, completeness, or timeliness of the content and is not responsible for any actions taken based on the information provided. The content does not constitute financial, legal, or other professional advice, nor should it be considered a recommendation or endorsement by MEXC.