• bitcoinBitcoin (BTC) $ 66,801.00
  • ethereumEthereum (ETH) $ 2,004.02
  • tetherTether (USDT) $ 0.999274
  • bnbBNB (BNB) $ 613.57
  • xrpXRP (XRP) $ 1.34
  • usd-coinUSDC (USDC) $ 0.999834
  • solanaSolana (SOL) $ 82.53
  • tronTRON (TRX) $ 0.319093
  • staked-etherLido Staked Ether (STETH) $ 2,265.05
  • figure-helocFigure Heloc (FIGR_HELOC) $ 1.02
  • dogecoinDogecoin (DOGE) $ 0.091038
  • usdsUSDS (USDS) $ 0.999727
  • whitebitWhiteBIT Coin (WBT) $ 51.58
  • bitcoin-cashBitcoin Cash (BCH) $ 482.50
  • hyperliquidHyperliquid (HYPE) $ 39.44
  • wrapped-stethWrapped stETH (WSTETH) $ 2,779.67
  • cardanoCardano (ADA) $ 0.243814
  • leo-tokenLEO Token (LEO) $ 9.65
  • wrapped-bitcoinWrapped Bitcoin (WBTC) $ 76,243.00
  • moneroMonero (XMR) $ 327.08
  • binance-bridged-usdt-bnb-smart-chainBinance Bridged USDT (BNB Smart Chain) (BSC-USD) $ 0.998762
  • chainlinkChainlink (LINK) $ 8.50
  • wrapped-beacon-ethWrapped Beacon ETH (WBETH) $ 2,466.93
  • canton-networkCanton (CC) $ 0.154101
  • ethena-usdeEthena USDe (USDE) $ 0.999179
  • stellarStellar (XLM) $ 0.167610
  • wrapped-eethWrapped eETH (WEETH) $ 2,465.31
  • usd1-wlfiUSD1 (USD1) $ 0.999475
  • daiDai (DAI) $ 0.999974
  • susdssUSDS (SUSDS) $ 1.08
  • litecoinLitecoin (LTC) $ 53.88
  • rainRain (RAIN) $ 0.008372
  • hedera-hashgraphHedera (HBAR) $ 0.089535
  • coinbase-wrapped-btcCoinbase Wrapped BTC (CBBTC) $ 76,366.00
  • paypal-usdPayPal USD (PYUSD) $ 0.999767
  • memecoreMemeCore (M) $ 2.19
  • avalanche-2Avalanche (AVAX) $ 8.73
  • wethWETH (WETH) $ 2,268.37
  • zcashZcash (ZEC) $ 216.25
  • shiba-inuShiba Inu (SHIB) $ 0.000006
  • suiSui (SUI) $ 0.861854
  • usdt0USDT0 (USDT0) $ 0.998824
  • bittensorBittensor (TAO) $ 319.90
  • the-open-networkToncoin (TON) $ 1.24
  • crypto-com-chainCronos (CRO) $ 0.070811
  • world-liberty-financialWorld Liberty Financial (WLFI) $ 0.098048
  • hashnote-usycCircle USYC (USYC) $ 1.12
  • tether-goldTether Gold (XAUT) $ 4,484.88
  • pax-goldPAX Gold (PAXG) $ 4,492.14
  • ethena-staked-usdeEthena Staked USDe (SUSDE) $ 1.22
  • mantleMantle (MNT) $ 0.678316
  • blackrock-usd-institutional-digital-liquidity-fundBlackRock USD Institutional Digital Liquidity Fund (BUIDL) $ 1.00
  • uniswapUniswap (UNI) $ 3.38
  • polkadotPolkadot (DOT) $ 1.27
  • global-dollarGlobal Dollar (USDG) $ 0.999740
  • okbOKB (OKB) $ 85.28
  • pi-networkPi Network (PI) $ 0.178676
  • falcon-financeFalcon USD (USDF) $ 0.997850
  • skySky (SKY) $ 0.070586
  • aster-2Aster (ASTER) $ 0.659233
  • htx-daoHTX DAO (HTX) $ 0.000002
  • syrupusdcsyrupUSDC (SYRUPUSDC) $ 1.15
  • nearNEAR Protocol (NEAR) $ 1.16
  • aaveAave (AAVE) $ 96.04
  • ripple-usdRipple USD (RLUSD) $ 1.00
  • pepePepe (PEPE) $ 0.000003
  • bitget-tokenBitget Token (BGB) $ 1.95
  • bfusdBFUSD (BFUSD) $ 0.999300
  • ondo-financeOndo (ONDO) $ 0.268973
  • ondo-us-dollar-yieldOndo US Dollar Yield (USDY) $ 1.12
  • siren-2Siren (SIREN) $ 1.77
  • ethereum-classicEthereum Classic (ETC) $ 8.01
  • internet-computerInternet Computer (ICP) $ 2.23
  • gatechain-tokenGate (GT) $ 6.55
  • janus-henderson-anemoy-treasury-fundJanus Henderson Anemoy Treasury Fund (JTRSY) $ 1.10
  • kucoin-sharesKuCoin (KCS) $ 7.96
  • quant-networkQuant (QNT) $ 70.80
  • jupiter-perpetuals-liquidity-provider-tokenJupiter Perpetuals Liquidity Provider Token (JLP) $ 4.00
  • pump-funPump.fun (PUMP) $ 0.001714
  • polygon-ecosystem-tokenPOL (ex-MATIC) (POL) $ 0.092339
  • eutblSpiko EU T-Bills Money Market Fund (EUTBL) $ 1.21
  • kaspaKaspa (KAS) $ 0.034874
  • nexoNEXO (NEXO) $ 0.881700
  • jito-staked-solJito Staked SOL (JITOSOL) $ 124.46
  • usdtbUSDtb (USDTB) $ 0.999958
  • render-tokenRender (RENDER) $ 1.69
  • kelp-dao-restaked-ethKelp DAO Restaked ETH (RSETH) $ 2,404.69
  • worldcoin-wldWorldcoin (WLD) $ 0.275980
  • cosmosCosmos Hub (ATOM) $ 1.65
  • binance-peg-wethBinance-Peg WETH (WETH) $ 2,262.26
  • morphoMorpho (MORPHO) $ 1.49
  • rocket-pool-ethRocket Pool ETH (RETH) $ 2,631.35
  • midnight-3Midnight (NIGHT) $ 0.049059
  • usddUSDD (USDD) $ 0.997513
  • binance-bridged-usdc-bnb-smart-chainBinance Bridged USDC (BNB Smart Chain) (USDC) $ 0.999945
  • ethenaEthena (ENA) $ 0.091850
  • superstate-short-duration-us-government-securities-fund-ustbSuperstate Short Duration U.S. Government Securities Fund (USTB) (USTB) $ 11.03
  • wbnbWrapped BNB (WBNB) $ 759.61
  • aptosAptos (APT) $ 0.928165
  • ignition-fbtcFunction FBTC (FBTC) $ 76,389.00
  • algorandAlgorand (ALGO) $ 0.081457
  • official-trumpOfficial Trump (TRUMP) $ 2.87
  • flare-networksFlare (FLR) $ 0.007739
  • hash-2Provenance Blockchain (HASH) $ 0.011140
  • ousgOUSG (OUSG) $ 114.73
  • syrupusdtsyrupUSDT (SYRUPUSDT) $ 1.11
  • filecoinFilecoin (FIL) $ 0.810956
  • beldexBeldex (BDX) $ 0.080087
  • xdce-crowd-saleXDC Network (XDC) $ 0.030384
  • binance-staked-solBinance Staked SOL (BNSOL) $ 108.24
  • yldsYLDS (YLDS) $ 0.999882
  • ghoGHO (GHO) $ 0.999002
  • vechainVeChain (VET) $ 0.006632
  • usual-usdUsual USD (USD0) $ 0.998712
  • fetch-aiArtificial Superintelligence Alliance (FET) $ 0.244461
  • new-x-ceo-is-backNEW X CEO IS BACK (XFLOKI) $ 0.506041
  • arbitrumArbitrum (ARB) $ 0.089385
  • bridged-usdc-polygon-pos-bridgePolygon Bridged USDC (Polygon PoS) (USDC.E) $ 0.999720
  • justJUST (JST) $ 0.060704
  • solv-btcSolv Protocol BTC (SOLVBTC) $ 76,461.00
  • stable-2​​Stable (STABLE) $ 0.024842
  • lombard-staked-btcLombard Staked BTC (LBTC) $ 76,491.00
  • jupiter-exchange-solanaJupiter (JUP) $ 0.143949
  • layerzeroLayerZero (ZRO) $ 2.01
  • bonkBonk (BONK) $ 0.000006
  • clbtcclBTC (CLBTC) $ 76,920.00
  • true-usdTrueUSD (TUSD) $ 0.997768
  • a7a5A7A5 (A7A5) $ 0.012292
  • fasttokenFasttoken (FTN) $ 1.09
  • pancakeswap-tokenPancakeSwap (CAKE) $ 1.37
  • virtual-protocolVirtuals Protocol (VIRTUAL) $ 0.657327
  • euro-coinEURC (EURC) $ 1.15
  • stakewise-v3-osethStakeWise Staked ETH (OSETH) $ 2,419.84
  • dashDash (DASH) $ 31.89
  • chilizChiliz (CHZ) $ 0.039277
  • kinetic-staked-hypeKinetiq Staked HYPE (KHYPE) $ 33.97
  • tbtctBTC (TBTC) $ 70,942.00
  • blockstackStacks (STX) $ 0.218439
  • pudgy-penguinsPudgy Penguins (PENGU) $ 0.006341
  • wrappedm-by-m0WrappedM by M0 (WM) $ 1.00
  • first-digital-usdFirst Digital USD (FDUSD) $ 0.998917
  • janus-henderson-anemoy-aaa-clo-fundJanus Henderson Anemoy AAA CLO Fund (JAAA) $ 1.03
  • tezosTezos (XTZ) $ 0.342833
  • hastra-primePRIME (PRIME) $ 1.03
  • kinesis-goldKinesis Gold (KAU) $ 151.94
  • c8ntinuumc8ntinuum (CTM) $ 0.087592
  • sei-networkSei (SEI) $ 0.053791
  • decredDecred (DCR) $ 20.77
  • mantle-staked-etherMantle Staked Ether (METH) $ 2,455.82
  • ether-fiEther.fi (ETHFI) $ 0.457830
  • usxUSX (USX) $ 0.999517
  • polygon-pos-bridged-dai-polygon-posPolygon PoS Bridged DAI (Polygon POS) (DAI) $ 0.999983
  • dexeDeXe (DEXE) $ 7.47
  • resolv-wstusrResolv wstUSR (WSTUSR) $ 1.13
  • sun-tokenSun Token (SUN) $ 0.017334
  • cocaCOCA (COCA) $ 1.30
  • adi-tokenADI (ADI) $ 4.05
  • apenftAINFT (NFT) $ 0.00000033
  • doge-strategyDoge Strategy (DOGESTR) $ 0.288297
  • curve-dao-tokenCurve DAO (CRV) $ 0.210381
  • liquid-staked-ethereumLiquid Staked ETH (LSETH) $ 2,406.26
  • gnosisGnosis (GNO) $ 118.47
  • arbitrum-bridged-wbtc-arbitrum-oneArbitrum Bridged WBTC (Arbitrum One) (WBTC) $ 76,200.00
  • bittorrentBitTorrent (BTT) $ 0.00000032
  • usdaiUSDai (USDAI) $ 0.999787
  • aerodrome-financeAerodrome Finance (AERO) $ 0.323941
  • conflux-tokenConflux (CFX) $ 0.056068
  • wrapped-flareWrapped Flare (WFLR) $ 0.009961
  • kite-2Kite (KITE) $ 0.160422
  • injective-protocolInjective (INJ) $ 2.82
  • l2-standard-bridged-weth-baseL2 Standard Bridged WETH (Base) (WETH) $ 2,266.86
  • bitcoin-svBitcoin SV (BSV) $ 13.72
  • steakhouse-usdc-morpho-vaultSteakhouse USDC Morpho Vault (STEAKUSDC) $ 1.12
  • riverRiver (RIVER) $ 13.98
  • fraxLegacy Frax Dollar (FRAX) $ 0.983068
  • kaiaKaia (KAIA) $ 0.046049
  • venice-tokenVenice Token (VVV) $ 5.99
  • flokiFLOKI (FLOKI) $ 0.000028
  • binance-peg-xrpBinance-Peg XRP (XRP) $ 1.59
  • jasmycoinJasmyCoin (JASMY) $ 0.005362
  • ether-fi-liquid-ethEther.Fi Liquid ETH (LIQUIDETH) $ 2,443.47
  • kinesis-silverKinesis Silver (KAG) $ 69.77
  • renzo-restaked-ethRenzo Restaked ETH (EZETH) $ 2,421.84
  • celestiaCelestia (TIA) $ 0.294252
  • crvusdcrvUSD (CRVUSD) $ 1.00
  • noonNoon (NOON) $ 0.751949
  • sbtc-2sBTC (SBTC) $ 77,039.00
  • official-foOfficial FO (FO) $ 0.263121
  • lido-daoLido DAO (LDO) $ 0.304880
  • the-graphThe Graph (GRT) $ 0.023668
  • jupiter-staked-solJupiter Staked SOL (JUPSOL) $ 115.56
  • spx6900SPX6900 (SPX) $ 0.270466
  • savings-usddSavings USDD (SUSDD) $ 1.03
  • ape-and-pepeApe and Pepe (APEPE) $ 0.000001
  • monadMonad (MON) $ 0.022636
  • olympusOlympus (OHM) $ 15.54
  • msolMarinade Staked SOL (MSOL) $ 133.18
  • btse-tokenBTSE Token (BTSE) $ 1.47
  • arbitrum-bridged-weth-arbitrum-oneArbitrum Bridged WETH (Arbitrum One) (WETH) $ 2,265.06
  • iotaIOTA (IOTA) $ 0.054536

Malicious OpenClaw Plugins Target Crypto Traders, Bitget Urges Immediate Key Resets

0 28

Malicious OpenClaw Plugins Target Crypto Traders, Bitget Urges Immediate Key Resets

Bitget warned users this week after its security team discovered malicious plugins on ClawHub, the community repository for the AI assistant OpenClaw. The exchange said the entries were disguised as helpful “skills” but in several cases prompted people to paste terminal commands or to download utilities that quietly installed malware designed to steal account credentials, API keys and wallet data.

The mechanics are simple and effective. A skill will walk a user through a short setup and ask them to run a single obfuscated command; that command fetches and executes a remote script, which then scours the machine for browser sessions, saved keys and other secrets. In a number of reported cases, a malicious skill briefly appeared on ClawHub’s front page, raising the chance that nontechnical users would follow instructions without realizing the risk.

Security teams that have been scanning the marketplace say the scale is alarming. Audits of thousands of skills turned up well over three hundred entries that behave maliciously, with many delivering information-stealing payloads such as variants of Atomic Stealer and related trojans. Those findings have framed the incident as a coordinated supply-chain poisoning campaign rather than a handful of accidental bad uploads.

From Convenience to Compromise

Analysts say attackers relied heavily on social engineering, publishing skills that posed as crypto trading helpers or wallet utilities and instructing users to perform setup steps that seemed routine. In several incidents, skills uploaded within a window tricked users by mimicking legitimate tools, a technique that helped the malware spread before defenders removed the listings.

Part of the problem is the platform’s power. OpenClaw runs locally and can legitimately execute shell commands, read files and interact with networks on behalf of its user; that capability makes useful automations possible but also gives a malicious skill direct access to sensitive data. The OpenClaw project and several security vendors have begun adding automated scanning, including VirusTotal checks and blocking of suspicious bundles, but researchers say automated checks must be paired with stronger human review, tighter publishing rules and clearer warnings to end users.

For traders and exchanges, the message is immediate and practical. Bitget told customers to stop using third-party tools, plugins or bots to connect to trading accounts and to use only the official app or website for deposits, withdrawals and trading. The exchange also urged anyone who has authorized API keys for a plugin to revoke them, change passwords and enable two-factor authentication to reduce the chance of an account compromise.

The episode is a reminder that convenience and attack surface often rise together. Agent-style AI can automate tedious tasks and boost productivity, but community ecosystems that allow unvetted code create attractive avenues for attackers. Until marketplaces adopt stronger vetting and platforms build more robust safeguards, users should treat third-party skills as untrusted code, refuse to run unfamiliar terminal commands, rotate API keys regularly and isolate wallet operations on well-protected devices. Those habits remain the best short-term defense while the ecosystem catches up.

Source

Leave A Reply

Your email address will not be published.