1,184 malicious skills found in OpenClaw's marketplace The open-source AI agent OpenClaw is facing a full-blown security crisis after researchers this week identified 1,184 malicious "skills" on its ClawHub marketplace, the latest and most alarming escalation in a series of vulnerabilities that have plagued the platform since it went viral in late January. The findings have prompted Meta and other tech companies to ban the tool from corporate networks, while security auditors have given it some of the lowest safety ratings ever recorded for a A Marketplace Turned Malware Hub According to a report published February 19 by Antiy CERT and amplified by SlowMist founder Yu Xian, the 1,184 malicious skills discovered on ClawHub are capable of stealing SSH keys, cryptocurrency wallet data, browser passwords, and opening reverse shells on victims' machines. A single threat actor uploaded 677 of the packages, accounting for 57 percent of all malicious listings. The top-ranked skill on the marketplace, called "What Would Elon Do?", was found by Cisco's AI Defense team to The crisis built rapidly. Koi Security first audited 2,857 ClawHub skills in early February and flagged 341 malicious entries tied to a coordinated campaign it named ClawHavoc. Snyk's separate scan of nearly 4,000 skills found 283, about 7.1 percent of the registry, leaked sensitive credentials including API keys and passwords in plaintext. Security researcher Paul McCarty identified 386 malicious add-ons posing as cryptocurrency trading tools between February 1 and 3 alone, all sharing the same Exposed Instances and Rock-Bottom Scores Beyond the marketplace threat, Censys identified 21,639 publicly exposed OpenClaw instances as of January 31, many with no authentication, leaving API keys, conversation histories, and OAuth credentials visible to anyone who found them. By February 9, exposure had ballooned to over 135,000 instances across 82 countries, according to a separate Security Scorecard audit. ZeroLeaks , a security scanner built by 16-year-old researcher Lucas Valbuena, gave OpenClaw a score of just 2 out of 100, with The platform's real-world harm extends to users who gave OpenClaw agents access to financial systems. WIRED senior writer Will Knight documented how an unaligned OpenClaw agent, after being given autonomy over financial tasks, turned on its own user and attempted to scam him through phishing emails rather than completing its assigned negotiation. Separately, users experimenting with OpenClaw -driven crypto trading reported steep losses as agents racked up excessive fees and made poor autonomous Enterprise Bans and an Uncertain Path Forward The accumulating risks have triggered corporate action. A Meta executive recently warned his team that using OpenClaw on work laptops could result in termination, according to WIRED, while multiple startup CEOs have banned the tool outright. "If it got access to one of our developer's machines, it could get access to our cloud services and our clients' sensitive information," Valere CEO Guy Pistone told WIRED. OpenClaw has partnered with Google's VirusTotal to scan all uploaded skills and has patched six newly disclosed vulnerabilities identified by Endor Labs, including SSRF, authentication bypass, and path traversal flaws. But security researchers say the platform's fundamental architecture, broad system permissions, weak sandboxing, and persistent memory that can store fragmented attack payloads, remains a structural concern. "In security, we never assume perfection. We assume zero-trust," JFrog