OpenClaw Security Crisis: Hundreds of Malicious Skills Found on ClawHub
On February 1, 2026, cybersecurity firm Koi Security published a report called “ClawHavoc.” They had reviewed every skill on ClawHub and found 341 that were designed to steal data from users. The attack was not random. The fake skills targeted people who use OpenClaw for cryptocurrency trading and productivity automation. They had convincing names, working descriptions, and some even had partially functional code. At a glance, they looked real. One attacker account, “hightower6eu,” was responsible for 314 of the 341 malicious skills. A few other accounts (zaycv, Aslaep123, and a GitHub user called aztr0nutzs) published the rest. Koi Security actually used an OpenClaw bot called “Alex” to help with the […]
