安全提醒:ClawHub市场共发现1184个恶意技能,可能窃取SSH密钥、加密钱包等

WELL7,87%

BlockBeats 消息,2 月 20 日,慢雾创始人余弦转帖发布安全提醒,目前 OpenClaw 的 ClawHub 市场共发现 1184 个恶意技能,这些技能会窃取 SSH 密钥、加密钱包、浏览器密码并打开反向 shell。仅一名攻击者就上传了 677 个软件包。排名第一的技能存在 9 个漏洞,下载量达数千次。

余弦提醒用户,文本不再是文本,而是指令。建议通过独立环境使用 AI 工具,许多 OpenClaw 技能存在潜在风险。此外,Web3 安全里合约只是一部分,真正事故原因早已不仅仅是合约。前几日 Moonwell 被盗 178 万美元,缺陷代码来自 Co-Authored-By:Claude Opus 4.6。

Disclaimer: The information on this page may come from third parties and does not represent the views or opinions of Gate. The content displayed on this page is for reference only and does not constitute any financial, investment, or legal advice. Gate does not guarantee the accuracy or completeness of the information and shall not be liable for any losses arising from the use of this information. Virtual asset investments carry high risks and are subject to significant price volatility. You may lose all of your invested principal. Please fully understand the relevant risks and make prudent decisions based on your own financial situation and risk tolerance. For details, please refer to Disclaimer.

Articoli correlati

用戶錢包資訊看光光!鏈上偵探 ZachXBT 曝 Axiom 員工涉嫌內線交易

知名鏈上偵探ZachXBT揭露加密交易平台Axiom員工濫用內部工具偷窺用戶錢包,並可能利用這些資訊進行內線交易。Axiom已撤回相關存取權限並表示將對違紀行為調查,強調不代表整體團隊價值。調查引發市場熱議,並有交易者因預測事件而獲利。

区块客4h fa

XRP Ledger Dev Raises Alert on Fake 'Passes' Scam Targeting Wallets - U.Today

Wietse Wind alerts the XRP community about scams involving fake NFTs and phishing attempts targeting wallet holders. He advises users to verify offers, avoid engagement with suspicious accounts, and underscores the importance of security practices to prevent fraud.

UToday5h fa

Bitcoin Extortion Plot Turns Violent as Fake Mailman Forces Way Into Home

Alleged bitcoin extortion turned violent in Seattle as prosecutors say a suspect posed as a postal worker, forced entry into a home, and demanded cryptocurrency. Seattle Couple Terrorized in Alleged Bitcoin Extortion Home Invasion Extortion schemes targeting digital assets such as bitcoin can

Coinpedia6h fa

Mỹ thu giữ hơn 61 triệu USD USDT liên quan lừa đảo “mổ heo”

U.S. federal agents seized over $61 million in USDT linked to "pig butchering" scams, where victims were lured by fake relationships and promised high crypto returns. Tether cooperated with authorities in asset freezes tied to money laundering and fraud cases.

TapChiBitcoin9h fa

六个Polymarket账户疑涉嫌内幕交易,押注美国打击伊朗盈利100万美元

分析公司BubblemapsSA预测,六个新开的账户通过押注美国在2月28日前打击伊朗,赚取约100万美元。这引发了对内幕交易的怀疑,类似模式曾在其他预测市场案件中出现。

GateNews10h fa

Suspected Insider Earns $1.25M Profit in 5 Hours Through Sports Betting

Gate News bot message, a wallet named "majorexploiter" generated $1.25M profit within 5 hours through sports betting. The wallet was created 5 days ago and received $3.28M in funds. 5 hours ago, it spent $1.19M to bet on Stade Rennais FC 1901 winning on 2026-02-28. The bet won shortly after, resulti

GateNews12h fa
Commento
0/400
Nessun commento
Trading di criptovalute ovunque e in qualsiasi momento
qrCode
Scansiona per scaricare Gate app
Notizie
  • 简体中文
  • English
  • Tiếng Việt
  • 繁體中文
  • Español
  • Русский
  • Français (Afrique)
  • Português (Portugal)
  • Bahasa Indonesia
  • 日本語
  • بالعربية
  • Українська
  • Português (Brasil)