ClawHavoc weaponized OpenClaw skills to deliver wallet-stealing malware
Trellix documented ClawHavoc, a malicious-skill supply-chain campaign targeting OpenClaw's ecosystem. More than 350 malicious or typosquatted skills were identified; instructions could lead agents or users toward malware installation, and the delivered stealer targeted more than 60 cryptocurrency wallets. Trellix emphasized that the OpenClaw issues it reproduced were associated mainly with older releases and were absent from current versions at publication.
The attack path combined malicious skill instructions with host-level command execution and malware delivery, exploiting the fact that agent frameworks can act directly on the operating system.
The attack path combined malicious skill instructions with host-level command execution and malware delivery, exploiting the fact that agent frameworks can act directly on the operating system.
reported findingsupported
Trellix identified more than 350 malicious or typosquatted skills in the ClawHub/OpenClaw ecosystem.
Trellix identified more than 350 malicious or typosquatted OpenClaw skills in the ClawHavoc campaign.
reported findingsupported
Trellix stated that the specific OpenClaw issues it reproduced were principally from older releases and were not present in current versions at publication.
Trellix stated that the specific OpenClaw issues it reproduced were principally from older releases and were not present in current versions at publication.
reported findingsupported
Trellix says the delivered stealer targeted more than 60 cryptocurrency wallets.
DiggingBeagle. “ClawHavoc weaponized OpenClaw skills to deliver wallet-stealing malware.” First seen Aug 19, 2026. https://diggingbeagle.com/cases/clawhavoc-weaponized-openclaw-skills-to-deliver-wallet-stealing-malware/
DiggingBeagle is a non profit research project documenting AI security incidents, agent failures, vulnerabilities and AI-assisted operations. A case keeps its claims beside the sources that support, contest or limit them. Later updates stay visible, so a reader can see when the account changed.
We publish case reconstructions, dated reporting and analysis across records. Each has a different evidentiary role. About the project and our methodology explain how the work is reviewed.