PANews reported on February 20th that Yu Xian, founder of SlowMist, stated on the X platform that 1184 malicious skills have been discovered on OpenClaw's ClawHub marketplace. These skills steal SSH keys, encrypted wallets, browser passwords, and open reverse shells. One attacker alone uploaded 677 software packages. The top-ranked skill has nine vulnerabilities and has been downloaded thousands of times.
Yu Xian reminds users that text is no longer just text, but instructions. He recommends using AI tools in a separate environment, as many OpenClaw skills carry potential risks. Furthermore, contracts are only one part of Web3 security; the real causes of incidents are no longer limited to contracts. A few days ago, Moonwell suffered a $1.78 million theft, with the flawed code originating from Co-Authored-By: Claude Opus 4.6.
![Will dogwifhat [WIF] break $1.29 or stay stuck in consolidation?](https://ambcrypto.com/wp-content/uploads/2025/09/Erastus-2025-09-17T121713.938-min.png)

