• bitcoinBitcoin (BTC) $ 89,261.00
  • ethereumEthereum (ETH) $ 3,013.96
  • tetherTether (USDT) $ 0.998564
  • bnbBNB (BNB) $ 903.30
  • xrpXRP (XRP) $ 1.91
  • usd-coinUSDC (USDC) $ 0.999615
  • jusdJUSD (JUSD) $ 0.999053
  • staked-etherLido Staked Ether (STETH) $ 3,012.17
  • tronTRON (TRX) $ 0.294601
  • dogecoinDogecoin (DOGE) $ 0.125363
  • figure-helocFigure Heloc (FIGR_HELOC) $ 1.03
  • cardanoCardano (ADA) $ 0.359855
  • wrapped-stethWrapped stETH (WSTETH) $ 3,696.56
  • bitcoin-cashBitcoin Cash (BCH) $ 590.44
  • whitebitWhiteBIT Coin (WBT) $ 54.46
  • wrapped-bitcoinWrapped Bitcoin (WBTC) $ 89,117.00
  • wrapped-beacon-ethWrapped Beacon ETH (WBETH) $ 3,288.28
  • wrapped-eethWrapped eETH (WEETH) $ 3,276.95
  • usdsUSDS (USDS) $ 0.999647
  • binance-bridged-usdt-bnb-smart-chainBinance Bridged USDT (BNB Smart Chain) (BSC-USD) $ 0.998479
  • moneroMonero (XMR) $ 470.61
  • leo-tokenLEO Token (LEO) $ 9.21
  • chainlinkChainlink (LINK) $ 11.89
  • hyperliquidHyperliquid (HYPE) $ 33.32
  • coinbase-wrapped-btcCoinbase Wrapped BTC (CBBTC) $ 89,238.00
  • wethWETH (WETH) $ 3,015.50
  • stellarStellar (XLM) $ 0.210580
  • ethena-usdeEthena USDe (USDE) $ 0.998589
  • zcashZcash (ZEC) $ 372.56
  • canton-networkCanton (CC) $ 0.161168
  • suiSui (SUI) $ 1.41
  • litecoinLitecoin (LTC) $ 69.56
  • avalanche-2Avalanche (AVAX) $ 12.11
  • usd1-wlfiUSD1 (USD1) $ 0.999265
  • hedera-hashgraphHedera (HBAR) $ 0.107618
  • shiba-inuShiba Inu (SHIB) $ 0.000008
  • world-liberty-financialWorld Liberty Financial (WLFI) $ 0.164354
  • usdt0USDT0 (USDT0) $ 0.998443
  • daiDai (DAI) $ 0.999213
  • susdssUSDS (SUSDS) $ 1.08
  • paypal-usdPayPal USD (PYUSD) $ 0.999773
  • ethena-staked-usdeEthena Staked USDe (SUSDE) $ 1.22
  • the-open-networkToncoin (TON) $ 1.54
  • crypto-com-chainCronos (CRO) $ 0.090738
  • rainRain (RAIN) $ 0.009983
  • polkadotPolkadot (DOT) $ 1.88
  • uniswapUniswap (UNI) $ 4.85
  • mantleMantle (MNT) $ 0.916063
  • tether-goldTether Gold (XAUT) $ 5,440.54
  • memecoreMemeCore (M) $ 1.53
  • bitget-tokenBitget Token (BGB) $ 3.58
  • aaveAave (AAVE) $ 160.79
  • bittensorBittensor (TAO) $ 240.24
  • pax-goldPAX Gold (PAXG) $ 5,456.15
  • okbOKB (OKB) $ 106.45
  • falcon-financeFalcon USD (USDF) $ 0.994246
  • pepePepe (PEPE) $ 0.000005
  • nearNEAR Protocol (NEAR) $ 1.50
  • pump-funPump.fun (PUMP) $ 0.003085
  • binance-peg-wethBinance-Peg WETH (WETH) $ 3,014.64
  • kelp-dao-restaked-ethKelp DAO Restaked ETH (RSETH) $ 3,204.86
  • ethereum-classicEthereum Classic (ETC) $ 11.59
  • jito-staked-solJito Staked SOL (JITOSOL) $ 157.71
  • internet-computerInternet Computer (ICP) $ 3.24
  • worldcoin-wldWorldcoin (WLD) $ 0.633422
  • ondo-financeOndo (ONDO) $ 0.348293
  • blackrock-usd-institutional-digital-liquidity-fundBlackRock USD Institutional Digital Liquidity Fund (BUIDL) $ 1.00
  • aster-2Aster (ASTER) $ 0.668798
  • htx-daoHTX DAO (HTX) $ 0.000002
  • jupiter-perpetuals-liquidity-provider-tokenJupiter Perpetuals Liquidity Provider Token (JLP) $ 4.59
  • hashnote-usycCircle USYC (USYC) $ 1.11
  • global-dollarGlobal Dollar (USDG) $ 0.999765
  • solanaWrapped SOL (SOL) $ 125.51
  • skySky (SKY) $ 0.066958
  • pi-networkPi Network (PI) $ 0.171049
  • kucoin-sharesKuCoin (KCS) $ 10.83
  • ripple-usdRipple USD (RLUSD) $ 0.999751
  • ethenaEthena (ENA) $ 0.174118
  • wbnbWrapped BNB (WBNB) $ 903.45
  • binance-staked-solBinance Staked SOL (BNSOL) $ 137.43
  • syrupusdcsyrupUSDC (SYRUPUSDC) $ 1.15
  • hash-2Provenance Blockchain (HASH) $ 0.024478
  • bfusdBFUSD (BFUSD) $ 0.997943
  • binance-bridged-usdc-bnb-smart-chainBinance Bridged USDC (BNB Smart Chain) (USDC) $ 0.999617
  • rocket-pool-ethRocket Pool ETH (RETH) $ 3,487.06
  • polygon-ecosystem-tokenPOL (ex-MATIC) (POL) $ 0.119147
  • aptosAptos (APT) $ 1.62
  • gatechain-tokenGate (GT) $ 9.97
  • myx-financeMYX Finance (MYX) $ 5.91
  • quant-networkQuant (QNT) $ 77.42
  • usddUSDD (USDD) $ 0.999403
  • cosmosCosmos Hub (ATOM) $ 2.25
  • algorandAlgorand (ALGO) $ 0.122430
  • kaspaKaspa (KAS) $ 0.040033
  • render-tokenRender (RENDER) $ 1.98
  • arbitrumArbitrum (ARB) $ 0.172437
  • lombard-staked-btcLombard Staked BTC (LBTC) $ 89,406.00
  • ignition-fbtcFunction FBTC (FBTC) $ 89,517.00
  • midnight-3Midnight (NIGHT) $ 0.058424
  • official-trumpOfficial Trump (TRUMP) $ 4.78
  • filecoinFilecoin (FIL) $ 1.29
  • riverRiver (RIVER) $ 48.46
  • nexoNEXO (NEXO) $ 0.945923
  • vechainVeChain (VET) $ 0.010278
  • flare-networksFlare (FLR) $ 0.010620
  • bridged-usdc-polygon-pos-bridgePolygon Bridged USDC (Polygon PoS) (USDC.E) $ 0.999614
  • mantle-staked-etherMantle Staked Ether (METH) $ 3,263.13
  • usdtbUSDtb (USDTB) $ 0.998808
  • liquid-staked-ethereumLiquid Staked ETH (LSETH) $ 3,236.61
  • syrupusdtsyrupUSDT (SYRUPUSDT) $ 1.11
  • superstate-short-duration-us-government-securities-fund-ustbSuperstate Short Duration U.S. Government Securities Fund (USTB) (USTB) $ 10.97
  • bonkBonk (BONK) $ 0.000009
  • kinetic-staked-hypeKinetiq Staked HYPE (KHYPE) $ 33.67
  • wrappedm-by-m0WrappedM by M0 (WM) $ 0.999460
  • dashDash (DASH) $ 59.09
  • story-2Story (IP) $ 2.11
  • xdce-crowd-saleXDC Network (XDC) $ 0.038596
  • janus-henderson-anemoy-aaa-clo-fundJanus Henderson Anemoy AAA CLO Fund (JAAA) $ 1.02
  • solv-btcSolv Protocol BTC (SOLVBTC) $ 89,245.00
  • sei-networkSei (SEI) $ 0.107203
  • arbitrum-bridged-wbtc-arbitrum-oneArbitrum Bridged WBTC (Arbitrum One) (WBTC) $ 89,382.00
  • jupiter-exchange-solanaJupiter (JUP) $ 0.214469
  • ondo-us-dollar-yieldOndo US Dollar Yield (USDY) $ 1.10
  • stakewise-v3-osethStakeWise Staked ETH (OSETH) $ 3,207.09
  • clbtcclBTC (CLBTC) $ 89,485.00
  • ousgOUSG (OUSG) $ 114.12
  • renzo-restaked-ethRenzo Restaked ETH (EZETH) $ 3,225.35
  • morphoMorpho (MORPHO) $ 1.21
  • l2-standard-bridged-weth-baseL2 Standard Bridged WETH (Base) (WETH) $ 3,014.84
  • polygon-pos-bridged-dai-polygon-posPolygon PoS Bridged DAI (Polygon POS) (DAI) $ 0.999808
  • eutblSpiko EU T-Bills Money Market Fund (EUTBL) $ 1.25
  • usdaiUSDai (USDAI) $ 0.999722
  • pancakeswap-tokenPancakeSwap (CAKE) $ 1.91
  • pudgy-penguinsPudgy Penguins (PENGU) $ 0.010091
  • jupiter-staked-solJupiter Staked SOL (JUPSOL) $ 146.19
  • binance-peg-xrpBinance-Peg XRP (XRP) $ 1.92
  • cocaCOCA (COCA) $ 1.29
  • wrapped-flareWrapped Flare (WFLR) $ 0.010609
  • beldexBeldex (BDX) $ 0.078759
  • optimismOptimism (OP) $ 0.303133
  • usual-usdUsual USD (USD0) $ 0.997147
  • chilizChiliz (CHZ) $ 0.056719
  • tezosTezos (XTZ) $ 0.540025
  • virtual-protocolVirtuals Protocol (VIRTUAL) $ 0.889846
  • arbitrum-bridged-weth-arbitrum-oneArbitrum Bridged WETH (Arbitrum One) (WETH) $ 3,015.22
  • fetch-aiArtificial Superintelligence Alliance (FET) $ 0.237222
  • c8ntinuumc8ntinuum (CTM) $ 0.123298
  • blockstackStacks (STX) $ 0.303053
  • tbtctBTC (TBTC) $ 89,393.00
  • janus-henderson-anemoy-treasury-fundJanus Henderson Anemoy Treasury Fund (JTRSY) $ 1.09
  • curve-dao-tokenCurve DAO (CRV) $ 0.356835
  • a7a5A7A5 (A7A5) $ 0.013091
  • ghoGHO (GHO) $ 0.998874
  • gtethGTETH (GTETH) $ 3,013.99
  • true-usdTrueUSD (TUSD) $ 0.998173
  • lighterLighter (LIT) $ 1.91
  • fasttokenFasttoken (FTN) $ 1.09
  • first-digital-usdFirst Digital USD (FDUSD) $ 0.998615
  • stable-2​​Stable (STABLE) $ 0.025281
  • injective-protocolInjective (INJ) $ 4.54
  • ether-fi-liquid-ethEther.Fi Liquid ETH (LIQUIDETH) $ 3,244.12
  • lido-daoLido DAO (LDO) $ 0.526866
  • doublezeroDoubleZero (2Z) $ 0.126357
  • ether-fiEther.fi (ETHFI) $ 0.626202
  • kinesis-silverKinesis Silver (KAG) $ 117.00
  • cap-usdCap USD (CUSD) $ 0.992716
  • coinbase-wrapped-staked-ethCoinbase Wrapped Staked ETH (CBETH) $ 3,380.36
  • msolMarinade Staked SOL (MSOL) $ 170.03
  • aerodrome-financeAerodrome Finance (AERO) $ 0.467649
  • steakhouse-usdc-morpho-vaultSteakhouse USDC Morpho Vault (STEAKUSDC) $ 1.12
  • kinesis-goldKinesis Gold (KAU) $ 173.69
  • stader-ethxStader ETHx (ETHX) $ 3,254.91
  • syrupMaple Finance (SYRUP) $ 0.355410
  • pippinpippin (PIPPIN) $ 0.410325
  • celestiaCelestia (TIA) $ 0.469156
  • layerzeroLayerZero (ZRO) $ 2.01
  • euro-coinEURC (EURC) $ 1.20
  • usdbUSDB (USDB) $ 1.00
  • flokiFLOKI (FLOKI) $ 0.000042
  • sbtc-2sBTC (SBTC) $ 88,987.00
  • staked-aaveStaked Aave (STKAAVE) $ 159.38
  • bittorrentBitTorrent (BTT) $ 0.00000040
  • resolv-usrResolv USR (USR) $ 0.999490
  • justJUST (JST) $ 0.044965
  • the-graphThe Graph (GRT) $ 0.036712
  • axie-infinityAxie Infinity (AXS) $ 2.32
  • resolv-wstusrResolv wstUSR (WSTUSR) $ 1.13
  • kaiaKaia (KAIA) $ 0.066688
  • pyth-networkPyth Network (PYTH) $ 0.064884
  • gnosisGnosis (GNO) $ 141.78
  • wrapped-apecoinWrapped ApeCoin (WAPE) $ 0.184449
  • trust-wallet-tokenTrust Wallet (TWT) $ 0.884853
  • iotaIOTA (IOTA) $ 0.086224
  • starknetStarknet (STRK) $ 0.069709
  • bitcoin-svBitcoin SV (BSV) $ 17.93
  • sun-tokenSun Token (SUN) $ 0.018447
  • crvusdcrvUSD (CRVUSD) $ 0.999392
  • spx6900SPX6900 (SPX) $ 0.380483
  • conflux-tokenConflux (CFX) $ 0.068301
  • ethereum-name-serviceEthereum Name Service (ENS) $ 9.18

Clawdbot Chaos: A Forced Rebrand, Crypto Scam and 24-Hour Meltdown

0 1

Clawdbot Chaos: A Forced Rebrand, Crypto Scam and 24-Hour Meltdown

A few days ago, Clawdbot was one of GitHub’s hottest open-source projects, boasting more than 80,000 stars. It’s an impressive piece of engineering that lets you run an AI assistant locally with full system access through messaging apps like WhatsApp, Telegram, and Discord.

Today, it’s been forced into a legal rebrand, overrun by crypto scammers, linked to a fake token that briefly hit a $16 million market cap before collapsing, and criticized by researchers who found exposed gateways and accessible credentials.

The reckoning started after Anthropic sent founder Peter Steinberger a trademark claim. The AI company—whose Claude models power many Clawdbot installations—decided that “Clawd” looked too much like “Claude.” Fair enough. Trademark law is trademark law.

That, however, triggered a variety of problems that soon cascaded.

Do I have anyone from GitHub in my timeline who could help me get my account on GitHub back?
It was snatched by crypto scammers.

— Peter Steinberger 🦞 (@steipete) January 27, 2026

Steinberger announced the rebrand from Clawdbot—the name was a play on lobsters, apparent (don’t ask)—to Moltbot on X. The community seemed fine with it. “Same lobster soul, new shell,” the project’s account wrote.

Next, Steinberger renamed the GitHub organization and the X account simultaneously. But in the short gap between releasing the old handles and securing the new ones, crypto scammers hijacked both accounts.

The hacked accounts immediately started pumping a fake token called CLAWD on Solana. Within hours, speculative traders drove the token to over $16 million in market capitalization.

Some early buyers claimed massive gains. Steinberger denied any involvement with the token. The capitalization collapsed and late buyers got wrecked.

“To all crypto folks: Please stop pinging me, stop harassing me,” Steinberger wrote. “I will never do a coin. Any project that lists me as coin owner is a SCAM. No, I will not accept fees. You are actively damaging the project.”

To all crypto folks:
Please stop pinging me, stop harassing me.
I will never do a coin.
Any project that lists me as coin owner is a SCAM.
No, I will not accept fees.
You are actively damanging the project.

— Peter Steinberger 🦞 (@steipete) January 27, 2026

The crypto crowd didn’t take the rejection well. Some speculators believed Steinberger’s denial caused their losses and launched harassment campaigns. He faced accusations of betrayal, demands that he “take responsibility,” and coordinated pressure to endorse projects he’d never heard of.

Steinberger was ultimately able to gain control of the accounts. But in the meantime, security researchers decided this was a good time to point out that hundreds of Clawdbot instances were exposed to the public internet with zero authentication. In other words, users would give unsupervised permissions to the AI that could easily be exploited by bad guys.

As reported by Decrypt, AI developer Luis Catacora ran Shodan scans and found a lot of problems were caused basically by novice users giving the agent too many permissions. “I just checked Shodan and there are exposed gateways on port 18789 with zero auth,” he wrote. “That’s shell access, browser automation, your API keys. Cloudflare Tunnel is free, there’s no excuse.”

Jamieson O’Reilly, founder of red-teaming company Dvuln, also found it was very easy to identify vulnerable servers. “Of the instances I’ve examined manually, eight were open with no authentication at all,” O’Reilly told The Register. Dozens more had partial protections that didn’t fully eliminate exposure.

The technical problem? Clawdbot’s authentication system automatically approves localhost connections—that is, connections to your own machine. When users run the software behind a reverse proxy, which most do, all connections appear to come from 127.0.0.1 and get automatically authorized, even when they originate externally.

Blockchain security firm SlowMist confirmed the vulnerability and warned that multiple code flaws could lead to credential theft and remote code execution. Researchers have demonstrated different prompt injection attacks, including one via email that tricked an AI instance into forwarding private messages to an attacker. It took mere minutes.

🚨SlowMist TI Alert🚨

Clawdbot gateway exposure identified: hundreds of API keys and private chat logs are at risk. Multiple unauthenticated instances are publicly accessible, and several code flaws may lead to credential theft and even remote code execution (RCE).

We strongly… https://t.co/j2ERoWPFnh

— SlowMist (@SlowMist_Team) January 27, 2026

“This is what happens when viral growth hits before security audit,” FounderOS developer Abdulmuiz Adeyemo wrote. “‘Build in public’ has a dark side nobody talks about.”

The good news for AI hobbyists and devs that the project itself hasn’t died. Moltbot is the same software Clawdbot was; the code is solid and, despite the hype, not especially noob-friendly. The use cases are real, but still not ready for mainstream adoption. And the security issues remain.



Running an autonomous AI agent with shell access, browser control, and credential management creates attack surfaces that traditional security models weren’t designed for. The economics of these systems—local deployment, persistent memory, and proactive tasks—drive adoption faster than the industry’s security posture can adapt.

And the crypto scammers are still out there, watching for the next chaos window. All it takes is one oversight, one mistake, or one gap. Ten seconds, as it turns out, is plenty.

Source

Leave A Reply

Your email address will not be published.