The post Critical Exploit in Openclaw Allows Full Administrative Hijacking – Featured Bitcoin News appeared on BitcoinEthereumNews.com. The ‘Trusted EnvironmentThe post Critical Exploit in Openclaw Allows Full Administrative Hijacking – Featured Bitcoin News appeared on BitcoinEthereumNews.com. The ‘Trusted Environment

Critical Exploit in Openclaw Allows Full Administrative Hijacking – Featured Bitcoin News

2026/04/01 14:48
Okuma süresi: 3 dk
Bu içerikle ilgili geri bildirim veya endişeleriniz için lütfen [email protected] üzerinden bizimle iletişime geçin.

The ‘Trusted Environment’ Fallacy

A March 31 study by Web3 security firm Certik has pulled back the curtain on a “systemic collapse” of security boundaries within Openclaw, an open-source artificial intelligence (AI) platform. Despite its rapid ascent to more than 300,000 Github stars, the framework has accumulated more than 100 CVEs and 280 security advisories in just four months, creating what researchers call an “unbounded” attack surface.

The report highlights a fundamental architectural flaw: Openclaw was originally designed for “trusted local environments.” However, as the platform’s popularity exploded, users began deploying it on internet-facing servers—a transition the software was never equipped to handle.

According to the study report, researchers identified several high-risk failure points that jeopardize user data, including the critical vulnerability, CVE-2026-25253, which allows attackers to seize full administrative control. By tricking a user into clicking a single malicious link, hackers can steal authentication tokens and hijack the AI agent.

Meanwhile, global scans revealed more than 135,000 internet-exposed Openclaw instances across 82 countries. Many of these had authentication disabled by default, leaking API keys, chat histories and sensitive credentials in plaintext. The report also asserts that the platform’s repository for user-shared “skills” has been infiltrated by malware and hundreds of these extensions were found to be bundling infostealers designed to siphon saved passwords and cryptocurrency wallets.

Furthermore, attackers are now hiding malicious instructions within emails and webpages. When the AI agent processes these documents, it can be forced to exfiltrate files or execute unauthorized commands without the user’s knowledge.

“Openclaw has become a case study in what happens when large language models stop being isolated chat systems and start acting inside real environments,” said a lead auditor from Penligent. “It aggregates classic software defects into a runtime with high delegated authority, making the blast radius of any single bug massive.”

Mitigation and Safety Recommendations

In response to these findings, experts are urging a “security-first” approach for both developers and end users. For developers, the study recommends establishing formal threat models from day one, enforcing strict sandbox isolation and ensuring that any AI-spawned subprocess inherits only low-privilege, immutable permissions.

For enterprise users, security teams are urged to use endpoint detection and response (EDR) tools to locate unauthorized Openclaw installations within corporate networks. On the other hand, individual users are encouraged to run the tool exclusively in a sandboxed environment with no access to production data. Most importantly, users must update to version 2026.1.29 or later to patch known remote code execution (RCE) flaws.

While Openclaw’s developers recently partnered with Virustotal to scan uploaded skills, Certik researchers warn this is “no silver bullet.” Until the platform reaches a more stable security phase, the industry consensus is to treat the software as inherently untrusted.

FAQ ❓

  • What is Openclaw? Openclaw is an open‑source AI framework that quickly grew to 300,000+ GitHub stars.
  • Why is it risky? It was built for trusted local use but is now widely deployed online, exposing major flaws.
  • What threats exist? Critical CVEs, malware‑infected extensions, and 135,000+ exposed instances across 82 countries.
  • How can users stay safe? Run only in sandboxed environments and update to version 2026.1.29 or later.

Source: https://news.bitcoin.com/study-critical-exploit-in-openclaw-allows-full-administrative-hijacking/

Piyasa Fırsatı
LETSTOP Logosu
LETSTOP Fiyatı(STOP)
$0.00995
$0.00995$0.00995
-1.67%
USD
LETSTOP (STOP) Canlı Fiyat Grafiği
Sorumluluk Reddi: Bu sitede yeniden yayınlanan makaleler, halka açık platformlardan alınmıştır ve yalnızca bilgilendirme amaçlıdır. MEXC'nin görüşlerini yansıtmayabilir. Tüm hakları telif sahiplerine aittir. Herhangi bir içeriğin üçüncü taraf haklarını ihlal ettiğini düşünüyorsanız, kaldırılması için lütfen [email protected] ile iletişime geçin. MEXC, içeriğin doğruluğu, eksiksizliği veya güncelliği konusunda hiçbir garanti vermez ve sağlanan bilgilere dayalı olarak alınan herhangi bir eylemden sorumlu değildir. İçerik, finansal, yasal veya diğer profesyonel tavsiye niteliğinde değildir ve MEXC tarafından bir tavsiye veya onay olarak değerlendirilmemelidir.

Ayrıca Şunları da Beğenebilirsiniz

Etsy witches can apparently turn you into a crypto millionaire for $73

Etsy witches can apparently turn you into a crypto millionaire for $73

                                                                               New snake oil? Etsy witches are hawking spells they claim can change the weather on your wedding day, help you with your love life, or fatten your crypto portfolio.                     Etsy witches have become a massive trend on social media this year — from romance spells to helping manifest fame. Did you know they can also apparently help you become a crypto millionaire? The practice of witchcraft, once punishable by death by fire (or being pushed off a cliff), has become a talking point on TikTok. Online marketplace Etsy, which allows people to sell their handmade beanies and custom dog collars, has become a hub for the spellcasters despite having a ban on “metaphysical services.” Read more
Paylaş
Coinstats2025/10/03 10:08
Ripple CEO Reacts to BBB Rating for Ripple Prime, Lists Three Points It Validates

Ripple CEO Reacts to BBB Rating for Ripple Prime, Lists Three Points It Validates

The post Ripple CEO Reacts to BBB Rating for Ripple Prime, Lists Three Points It Validates appeared on BitcoinEthereumNews.com. Brad Garlinghouse, CEO of Ripple
Paylaş
BitcoinEthereumNews2026/04/03 11:28
REX-Osprey DOJE ETF Launch Drives Dogecoin Surge to $0.28

REX-Osprey DOJE ETF Launch Drives Dogecoin Surge to $0.28

The post REX-Osprey DOJE ETF Launch Drives Dogecoin Surge to $0.28 appeared on BitcoinEthereumNews.com. DOJE ETF Offers Direct Spot Exposure to Dogecoin In a press release, REX-Osprey announced the launch of the first-ever publicly traded ETF to provide exposure to Dogecoin (DOGE). The latest fund is the REX-OspreyDOGE ETF (CBOE: DOJE), an innovation in the cryptocurrency market. It is a unique exchange-traded fund (ETF) that offers direct spot exposure to Dogecoin, which has gained legendary popularity due to its Shiba Inu mascot and fan base of Shiba Inu followers. The introduction of the DOJE ETF is revolutionary for several reasons. It is the first ETF in the United States that provides investors direct access to the spot price of Dogecoin, a widely known cryptocurrency, which lacks inherent utility. This provides a controlled and smooth method for people to invest into DOGE through a regular brokerage account. Using this new product, REX-Osprey remains on the edge of digital asset integration into the regulated financial frameworks. Greg King, CEO of REX Financial and Osprey Funds, expressed his pride in this achievement: “Investors look to ETFs as trading and access vehicles. The digital asset revolution is already underway, and to be able to offer exposure to some of the most popular digital assets within the protections of the U.S. ’40 Act ETF regime is something REX-Osprey™ is proud of and has worked diligently to achieve.” SSK’s Success Sets the Stage for DOGE ETF Launch The DOJE ETF follows the successful launch of REX-Osprey’s SOL + Staking ETF (SSK) in July 2025. This fund became the first-ever U.S.-listed ETF to offer spot Solana exposure alongside on-chain staking rewards. Since its launch, SSK has been a significant success, accumulating over $275 million in assets under management. REX-Osprey has now expanded its crypto offerings with the addition of both DOGE and XRP ETFs, offering investors more opportunities to diversify their…
Paylaş
BitcoinEthereumNews2025/09/19 00:52

Trade GOLD, Share 1,000,000 USDT

Trade GOLD, Share 1,000,000 USDTTrade GOLD, Share 1,000,000 USDT

0 fees, up to 1,000x leverage, deep liquidity