• bitcoinBitcoin (BTC) $ 87,776.00
  • ethereumEthereum (ETH) $ 2,904.89
  • tetherTether (USDT) $ 0.998653
  • bnbBNB (BNB) $ 877.19
  • xrpXRP (XRP) $ 1.88
  • usd-coinUSDC (USDC) $ 0.999576
  • jusdJUSD (JUSD) $ 0.999053
  • tronTRON (TRX) $ 0.293834
  • staked-etherLido Staked Ether (STETH) $ 2,903.95
  • dogecoinDogecoin (DOGE) $ 0.121590
  • figure-helocFigure Heloc (FIGR_HELOC) $ 1.03
  • cardanoCardano (ADA) $ 0.349214
  • wrapped-stethWrapped stETH (WSTETH) $ 3,559.45
  • bitcoin-cashBitcoin Cash (BCH) $ 589.26
  • whitebitWhiteBIT Coin (WBT) $ 53.50
  • wrapped-bitcoinWrapped Bitcoin (WBTC) $ 87,290.00
  • wrapped-beacon-ethWrapped Beacon ETH (WBETH) $ 3,162.71
  • wrapped-eethWrapped eETH (WEETH) $ 3,154.44
  • usdsUSDS (USDS) $ 0.999610
  • binance-bridged-usdt-bnb-smart-chainBinance Bridged USDT (BNB Smart Chain) (BSC-USD) $ 0.998532
  • moneroMonero (XMR) $ 476.54
  • leo-tokenLEO Token (LEO) $ 9.23
  • chainlinkChainlink (LINK) $ 11.87
  • coinbase-wrapped-btcCoinbase Wrapped BTC (CBBTC) $ 87,735.00
  • wethWETH (WETH) $ 2,905.01
  • stellarStellar (XLM) $ 0.205100
  • ethena-usdeEthena USDe (USDE) $ 0.998866
  • hyperliquidHyperliquid (HYPE) $ 27.52
  • zcashZcash (ZEC) $ 382.16
  • canton-networkCanton (CC) $ 0.148013
  • suiSui (SUI) $ 1.44
  • litecoinLitecoin (LTC) $ 69.19
  • avalanche-2Avalanche (AVAX) $ 11.66
  • usd1-wlfiUSD1 (USD1) $ 0.999557
  • usdt0USDT0 (USDT0) $ 0.998668
  • hedera-hashgraphHedera (HBAR) $ 0.105682
  • shiba-inuShiba Inu (SHIB) $ 0.000008
  • daiDai (DAI) $ 0.999693
  • world-liberty-financialWorld Liberty Financial (WLFI) $ 0.156618
  • susdssUSDS (SUSDS) $ 1.09
  • paypal-usdPayPal USD (PYUSD) $ 0.999929
  • ethena-staked-usdeEthena Staked USDe (SUSDE) $ 1.22
  • the-open-networkToncoin (TON) $ 1.51
  • crypto-com-chainCronos (CRO) $ 0.090484
  • rainRain (RAIN) $ 0.010088
  • polkadotPolkadot (DOT) $ 1.85
  • uniswapUniswap (UNI) $ 4.65
  • mantleMantle (MNT) $ 0.866021
  • memecoreMemeCore (M) $ 1.55
  • tether-goldTether Gold (XAUT) $ 5,084.68
  • bitget-tokenBitget Token (BGB) $ 3.57
  • aaveAave (AAVE) $ 153.10
  • bittensorBittensor (TAO) $ 230.54
  • okbOKB (OKB) $ 103.82
  • falcon-financeFalcon USD (USDF) $ 0.995756
  • pepePepe (PEPE) $ 0.000005
  • pax-goldPAX Gold (PAXG) $ 5,100.02
  • nearNEAR Protocol (NEAR) $ 1.46
  • pump-funPump.fun (PUMP) $ 0.003144
  • internet-computerInternet Computer (ICP) $ 3.26
  • jito-staked-solJito Staked SOL (JITOSOL) $ 155.26
  • binance-peg-wethBinance-Peg WETH (WETH) $ 2,903.54
  • ethereum-classicEthereum Classic (ETC) $ 11.24
  • blackrock-usd-institutional-digital-liquidity-fundBlackRock USD Institutional Digital Liquidity Fund (BUIDL) $ 1.00
  • kelp-dao-restaked-ethKelp DAO Restaked ETH (RSETH) $ 3,092.66
  • htx-daoHTX DAO (HTX) $ 0.000002
  • ondo-financeOndo (ONDO) $ 0.331048
  • hashnote-usycCircle USYC (USYC) $ 1.11
  • global-dollarGlobal Dollar (USDG) $ 0.999544
  • aster-2Aster (ASTER) $ 0.649811
  • solanaWrapped SOL (SOL) $ 123.61
  • jupiter-perpetuals-liquidity-provider-tokenJupiter Perpetuals Liquidity Provider Token (JLP) $ 4.54
  • hash-2Provenance Blockchain (HASH) $ 0.027388
  • skySky (SKY) $ 0.062862
  • pi-networkPi Network (PI) $ 0.171371
  • ripple-usdRipple USD (RLUSD) $ 0.999679
  • kucoin-sharesKuCoin (KCS) $ 10.59
  • binance-staked-solBinance Staked SOL (BNSOL) $ 135.33
  • ethenaEthena (ENA) $ 0.167134
  • bfusdBFUSD (BFUSD) $ 0.998007
  • wbnbWrapped BNB (WBNB) $ 876.96
  • syrupusdcsyrupUSDC (SYRUPUSDC) $ 1.15
  • binance-bridged-usdc-bnb-smart-chainBinance Bridged USDC (BNB Smart Chain) (USDC) $ 0.999502
  • worldcoin-wldWorldcoin (WLD) $ 0.456216
  • polygon-ecosystem-tokenPOL (ex-MATIC) (POL) $ 0.117040
  • rocket-pool-ethRocket Pool ETH (RETH) $ 3,359.95
  • aptosAptos (APT) $ 1.53
  • myx-financeMYX Finance (MYX) $ 6.00
  • gatechain-tokenGate (GT) $ 9.82
  • usddUSDD (USDD) $ 0.998584
  • cosmosCosmos Hub (ATOM) $ 2.22
  • riverRiver (RIVER) $ 54.42
  • quant-networkQuant (QNT) $ 73.09
  • algorandAlgorand (ALGO) $ 0.118907
  • kaspaKaspa (KAS) $ 0.038958
  • lombard-staked-btcLombard Staked BTC (LBTC) $ 87,948.00
  • arbitrumArbitrum (ARB) $ 0.167820
  • midnight-3Midnight (NIGHT) $ 0.058552
  • ignition-fbtcFunction FBTC (FBTC) $ 87,495.00
  • official-trumpOfficial Trump (TRUMP) $ 4.76
  • render-tokenRender (RENDER) $ 1.82
  • filecoinFilecoin (FIL) $ 1.26
  • nexoNEXO (NEXO) $ 0.931888
  • bridged-usdc-polygon-pos-bridgePolygon Bridged USDC (Polygon PoS) (USDC.E) $ 0.999517
  • flare-networksFlare (FLR) $ 0.010484
  • vechainVeChain (VET) $ 0.010033
  • usdtbUSDtb (USDTB) $ 0.999529
  • mantle-staked-etherMantle Staked Ether (METH) $ 3,143.77
  • superstate-short-duration-us-government-securities-fund-ustbSuperstate Short Duration U.S. Government Securities Fund (USTB) (USTB) $ 10.97
  • syrupusdtsyrupUSDT (SYRUPUSDT) $ 1.11
  • solv-btcSolv Protocol BTC (SOLVBTC) $ 87,514.00
  • liquid-staked-ethereumLiquid Staked ETH (LSETH) $ 3,131.03
  • dashDash (DASH) $ 61.77
  • bonkBonk (BONK) $ 0.000009
  • wrappedm-by-m0WrappedM by M0 (WM) $ 0.999453
  • xdce-crowd-saleXDC Network (XDC) $ 0.038978
  • story-2Story (IP) $ 2.11
  • ousgOUSG (OUSG) $ 114.09
  • janus-henderson-anemoy-aaa-clo-fundJanus Henderson Anemoy AAA CLO Fund (JAAA) $ 1.02
  • ondo-us-dollar-yieldOndo US Dollar Yield (USDY) $ 1.11
  • sei-networkSei (SEI) $ 0.105312
  • arbitrum-bridged-wbtc-arbitrum-oneArbitrum Bridged WBTC (Arbitrum One) (WBTC) $ 87,563.00
  • renzo-restaked-ethRenzo Restaked ETH (EZETH) $ 3,112.25
  • stakewise-v3-osethStakeWise Staked ETH (OSETH) $ 3,088.15
  • clbtcclBTC (CLBTC) $ 86,786.00
  • morphoMorpho (MORPHO) $ 1.22
  • eutblSpiko EU T-Bills Money Market Fund (EUTBL) $ 1.24
  • polygon-pos-bridged-dai-polygon-posPolygon PoS Bridged DAI (Polygon POS) (DAI) $ 0.999863
  • usdaiUSDai (USDAI) $ 0.999458
  • kinetic-staked-hypeKinetiq Staked HYPE (KHYPE) $ 27.78
  • pancakeswap-tokenPancakeSwap (CAKE) $ 1.88
  • l2-standard-bridged-weth-baseL2 Standard Bridged WETH (Base) (WETH) $ 2,903.90
  • jupiter-exchange-solanaJupiter (JUP) $ 0.192592
  • jupiter-staked-solJupiter Staked SOL (JUPSOL) $ 143.83
  • binance-peg-xrpBinance-Peg XRP (XRP) $ 1.88
  • wrapped-flareWrapped Flare (WFLR) $ 0.010493
  • beldexBeldex (BDX) $ 0.079672
  • usual-usdUsual USD (USD0) $ 0.999327
  • tezosTezos (XTZ) $ 0.559127
  • pudgy-penguinsPudgy Penguins (PENGU) $ 0.009496
  • optimismOptimism (OP) $ 0.295326
  • chilizChiliz (CHZ) $ 0.054521
  • arbitrum-bridged-weth-arbitrum-oneArbitrum Bridged WETH (Arbitrum One) (WETH) $ 2,905.23
  • blockstackStacks (STX) $ 0.294252
  • c8ntinuumc8ntinuum (CTM) $ 0.119654
  • virtual-protocolVirtuals Protocol (VIRTUAL) $ 0.791678
  • tbtctBTC (TBTC) $ 87,323.00
  • a7a5A7A5 (A7A5) $ 0.013059
  • fetch-aiArtificial Superintelligence Alliance (FET) $ 0.220185
  • janus-henderson-anemoy-treasury-fundJanus Henderson Anemoy Treasury Fund (JTRSY) $ 1.09
  • curve-dao-tokenCurve DAO (CRV) $ 0.338593
  • ghoGHO (GHO) $ 0.999448
  • true-usdTrueUSD (TUSD) $ 0.998426
  • first-digital-usdFirst Digital USD (FDUSD) $ 0.997320
  • gtethGTETH (GTETH) $ 2,902.62
  • fasttokenFasttoken (FTN) $ 1.09
  • lighterLighter (LIT) $ 1.84
  • injective-protocolInjective (INJ) $ 4.37
  • axie-infinityAxie Infinity (AXS) $ 2.57
  • lido-daoLido DAO (LDO) $ 0.511022
  • ether-fi-liquid-ethEther.Fi Liquid ETH (LIQUIDETH) $ 3,125.86
  • cap-usdCap USD (CUSD) $ 0.984469
  • steakhouse-usdc-morpho-vaultSteakhouse USDC Morpho Vault (STEAKUSDC) $ 1.12
  • msolMarinade Staked SOL (MSOL) $ 167.18
  • kaiaKaia (KAIA) $ 0.071966
  • kinesis-silverKinesis Silver (KAG) $ 112.16
  • coinbase-wrapped-staked-ethCoinbase Wrapped Staked ETH (CBETH) $ 3,254.53
  • ether-fiEther.fi (ETHFI) $ 0.591914
  • usdbUSDB (USDB) $ 1.01
  • doublezeroDoubleZero (2Z) $ 0.118048
  • newton-projectAB (AB) $ 0.004128
  • aerodrome-financeAerodrome Finance (AERO) $ 0.441136
  • justJUST (JST) $ 0.045312
  • flokiFLOKI (FLOKI) $ 0.000041
  • stader-ethxStader ETHx (ETHX) $ 3,131.59
  • resolv-usrResolv USR (USR) $ 0.999666
  • bittorrentBitTorrent (BTT) $ 0.00000040
  • sbtc-2sBTC (SBTC) $ 87,246.00
  • kinesis-goldKinesis Gold (KAU) $ 163.60
  • resolv-wstusrResolv wstUSR (WSTUSR) $ 1.13
  • layerzeroLayerZero (ZRO) $ 1.92
  • stable-2​​Stable (STABLE) $ 0.021544
  • syrupMaple Finance (SYRUP) $ 0.334736
  • celestiaCelestia (TIA) $ 0.439853
  • staked-aaveStaked Aave (STKAAVE) $ 151.53
  • euro-coinEURC (EURC) $ 1.19
  • the-graphThe Graph (GRT) $ 0.035598
  • gnosisGnosis (GNO) $ 138.65
  • wrapped-apecoinWrapped ApeCoin (WAPE) $ 0.180395
  • iotaIOTA (IOTA) $ 0.084672
  • decredDecred (DCR) $ 20.63
  • starknetStarknet (STRK) $ 0.068233
  • bitcoin-svBitcoin SV (BSV) $ 17.67
  • trust-wallet-tokenTrust Wallet (TWT) $ 0.838554
  • apenftAINFT (NFT) $ 0.00000035
  • crvusdcrvUSD (CRVUSD) $ 1.00
  • the-sandboxThe Sandbox (SAND) $ 0.130332
  • conflux-tokenConflux (CFX) $ 0.067263
  • spx6900SPX6900 (SPX) $ 0.371556
  • sun-tokenSun Token (SUN) $ 0.017844

Viral AI assistant ‘Clawdbot’ risks leaking private messages, credentials

0 1

Viral AI assistant 'Clawdbot' risks leaking private messages, credentials

Cybersecurity researchers have raised red flags about a new artificial intelligence personal assistant called Clawdbot, warning it could inadvertently expose personal data and API keys to the public.

On Tuesday, Blockchain security firm SlowMist said a Clawdbot “gateway exposure” has been identified, putting “hundreds of API keys and private chat logs at risk.”

“Multiple unauthenticated instances are publicly accessible, and several code flaws may lead to credential theft and even remote code execution,” it added.

Security researcher Jamieson O’Reilly originally detailed the findings on Sunday, stating that “hundreds of people have set up their Clawdbot control servers exposed to the public” over the past few days.

Clawdbot is an open-source AI assistant built by developer and entrepreneur Peter Steinberger that runs locally on a user’s device. Over the weekend, online chatter about the tool “reached viral status,” Mashable reported on Tuesday.

Scanning for “Clawdbot Control” exposes credentials

The AI agent gateway connects large language models (LLMs) to messaging platforms and executes commands on users’ behalf using a web admin interface called “Clawdbot Control.”

The authentication bypass vulnerability in Clawdbot occurs when its gateway is placed behind an unconfigured reverse proxy, O’Reilly explained.

Using internet scanning tools like Shodan, the researcher could easily find these exposed servers by searching for distinctive fingerprints in the HTML.

“Searching for ‘Clawdbot Control’ – the query took seconds. I got back hundreds of hits based on multiple tools,” he said.

Related: Matcha Meta breach tied to SwapNet exploit drains up to $16.8M

The researcher said he could access complete credentials such as API keys, bot tokens, OAuth secrets, signing keys, full conversation histories across all chat platforms, the ability to send messages as the user, and command execution capabilities.

“If you’re running agent infrastructure, audit your configuration today. Check what’s actually exposed to the internet. Understand what you’re trusting with that deployment and what you’re trading away,” advised O’Reilly

“The butler is brilliant. Just make sure he remembers to lock the door.”

Extracting a private key took five minutes

The AI assistant could also be exploited for more nefarious purposes regarding crypto asset security.

Matvey Kukuy, CEO at Archestra AI, took things a step further in an attempt to extract a private key.

He shared a screenshot of sending Clawdbot an email with prompt injection, asking Clawdbot to check the email and receive the private key from the exploited machine, saying it “took 5 minutes.”

Viral AI assistant 'Clawdbot' risks leaking private messages, credentials

Source: Matvey Kukuy

Clawdbot is slightly different from other agentic AI bots because it has full system access to users’ machines, which means it can read and write files, run commands, execute scripts and control browsers.

“Running an AI agent with shell access on your machine is… spicy,” reads the Clawdbot FAQ. “There is no ‘perfectly secure’ setup.”

The FAQ also highlighted the threat model, stating malicious actors can “try to trick your AI into doing bad things, social engineer access to your data, and probe for infrastructure details.”

“We strongly recommend applying strict IP whitelisting on exposed ports,” advised SlowMist.

Magazine: The critical reason you should never ask ChatGPT for legal advice

Source

Leave A Reply

Your email address will not be published.