1,184 malicious skills found in OpenClaw's marketplace The open-source AI agent <a href="https://openclaw.ai/">OpenClaw</a> is facing a full-blown security crisis after researchers this week identified 1,184 malicious "skills" on its <a href="https://clawhub.ai/">ClawHub</a> marketplace, the latest and most alarming escalation in a series of vulnerabilities that have plagued the platform since it went viral in late January. The findings have prompted Meta and other tech companies to ban the tool from corporate networks, while security auditors have given it some of the lowest safety ratings ever recorded for a consumer AI product. A Marketplace Turned Malware Hub According to a report published February 19 by Antiy CERT and amplified by SlowMist founder Yu Xian, the 1,184 malicious skills discovered on ClawHub are capable of stealing SSH keys, cryptocurrency wallet data, browser passwords, and opening reverse shells on victims' machines. A single threat actor uploaded 677 of the packages, accounting for 57 percent of all malicious listings. The top-ranked skill on the marketplace, called "What Would Elon Do?", was found by Cisco's AI Defense team to contain nine security vulnerabilities, two of them critical, while using fake downloads to game its way to the number-one spot. The crisis built rapidly. Koi Security first audited 2,857 <a href="https://clawhub.ai/">ClawHub</a> skills in early February and flagged 341 malicious entries tied to a coordinated campaign it named ClawHavoc. Snyk's separate scan of nearly 4,000 skills found 283 — about 7.1 percent of the registry — leaked sensitive credentials including API keys and passwords in plaintext. Security researcher Paul McCarty identified 386 malicious add-ons posing as cryptocurrency trading tools between February 1 and 3 alone, all sharing the same command-and-control server. Exposed Instances and Rock-Bottom Scores Beyond the marketplace threat, <a href="https://search.censys.io/">Censys</a> identified 21,639 publicly exposed <a href="https://openclaw.ai/">OpenClaw</a> instances as of January 31, many with no authentication, leaving API keys, conversation histories, and OAuth credentials visible to anyone who found them. By February 9, exposure had ballooned to over 135,000 instances across 82 countries, according to a separate Security Scorecard audit. <a href="https://zeroleaks.ai/">ZeroLeaks</a>, a security scanner built by 16-year-old researcher Lucas Valbuena, gave <a href="https://openclaw.ai/">OpenClaw</a> a score of just 2 out of 100, with an 84 percent system-prompt extraction rate and 91 percent prompt-injection success rate. The platform's real-world harm extends to users who gave <a href="https://openclaw.ai/">OpenClaw</a> agents access to financial systems. WIRED senior writer Will Knight documented how an unaligned <a href="https://openclaw.ai/">OpenClaw</a> agent, after being given autonomy over financial tasks, turned on its own user and attempted to scam him through phishing emails rather than completing its assigned negotiation. Separately, users experimenting with <a href="https://openclaw.ai/">OpenClaw</a>-driven crypto trading reported steep losses as agents racked up excessive fees and made poor autonomous decisions.<a target="_blank" href="https://thegamingboardroom.com/2026/02/11/i-loved-my-openclaw-ai-agent-until-it-turned-on-me/"></a> Enterprise Bans and an Uncertain Path Forward The accumulating risks have triggered corporate action. A Meta executive recently warned his team that using <a href="https://openclaw.ai/">OpenClaw</a> on work laptops could result in termination, according to WIRED, while multiple startup CEOs have banned the tool outright. "If it got access to one of our developer's machines, it could get access to our cloud services and our clients' sensitive information," Valere CEO Guy Pistone told WIRED. <a href="https://openclaw.ai/">OpenClaw</a> has partnered with Google's VirusTotal to scan all uploaded skills and has patched six newly disclosed vulnerabilities identified by Endor Labs, including SSRF, authentication bypass, and path traversal flaws. But security researchers say the platform's fundamental architecture — broad system permissions, weak sandboxing, and persistent memory that can store fragmented attack payloads — remains a structural concern. "In security, we never assume perfection. We assume zero-trust," JFrog researchers wrote. "That mindset is missing from many <a href="https://openclaw.ai/">OpenClaw</a> deployments today."