216.73.217.22

Hundreds of Malicious Crypto Trading Add-Ons Found in Moltbot/OpenClaw

· Published 04/02/2026 11:13 · Modified 05/02/2026 11:22

Export JSON

Essential information

Published
04/02/2026 11:13
Modified
05/02/2026 11:22
Tags
2026-02-04 ai agents ai assistant cryptocurrency endpoint security information-stealing openclaw social engineering supply chain attack
Related entities
1 observables, 8 techniques (mitre), 2 others

Description

Almost 400 fake crypto trading add-ons in the Moltbot/ project have been discovered, potentially leading users to install malware. These add-ons, known as skills, masquerade as trading automation tools and target various platforms. The malicious skills share the same command-and-control infrastructure and use to convince users to execute commands that steal crypto assets. The relies on and lacks security review in the skills publication process. Security experts warn about the inherent risks of endpoint-native and emphasize the need for proper security controls and architectural design considerations.

External references