A security researcher has discovered that numerous skills published on ClawHub, a registry for OpenClaw skills, are secretly enlisting AI agents to mine cryptocurrency. These skills, downloaded thousands of times, operate without user consent or traditional malware, instead leveraging the agents' capabilities and instruction files. The agents register with a third-party server, generate crypto wallets, and perform tasks, all without the user's explicit approval or knowledge, mirroring previous token farming campaigns. AI
Summary written by gemini-2.5-flash-lite from 3 sources. How we write summaries →
IMPACT Raises concerns about AI agent security and the potential for unauthorized resource utilization without user knowledge or consent.
RANK_REASON Discovery of a method to co-opt AI agents for unauthorized cryptocurrency mining via a skills registry.