Detect Deepfakesby Resemble AI
Agentic AI attack

OpenClaw users agentic AI attack — Jun 2026

Malicious actors exploited the OpenClaw AI marketplace by distributing compromised skills that enabled financial fraud and unauthorized agentic control

Reported date
Jun 23, 2026
Target
OpenClaw users
Agent type
Other AI agent
Agent role
Used by the attacker

The exact incident date was not established. This entry is dated by its source report.

Updated Sep 26, 2026 · 2 min read

Overview

Researchers at Unit 42 identified a series of malicious campaigns targeting the OpenClaw AI agent ecosystem, where attackers published compromised skills on the ClawHub marketplace. These skills leveraged the agent's broad local system access to perform unauthorized financial activities and deliver malware, bypassing existing security screening mechanisms.

What happened

Between February and May 2026, malicious actors utilized the OpenClaw marketplace to distribute skills that exploited the agentic execution model. Unlike traditional software supply chain attacks, these threats used semantic instruction hijacking to manipulate the agent's operational context, including file systems and credential managers, without requiring conventional exploits.

Unit 42 identified three primary categories of malicious activity:

  • Infostealers: Several skills, such as those posing as TradingView assistants, used paste-site redirects and Base64-encoded payloads to deliver macOS infostealers. These skills often bypassed automated auditing by using established delivery templates and fresh backend infrastructure.
  • Defense Evasion: Attackers employed file padding techniques, such as adding 22 MB of characters to a README.md file, to exceed the file size limits of content-analysis pipelines, allowing malicious payloads to remain undetected by scanners like ClawScan and VirusTotal.
  • Agentic Financial Fraud: Researchers discovered novel techniques including runtime affiliate injection and agentic front-running. In the affiliate injection case, a skill weaponized the agent's advisory authority to route financial recommendations through attacker-controlled affiliate links. In the front-running scheme, the 'letssendit' skill coordinated a network of autonomous agents to pool cryptocurrency and purchase meme tokens before a public launch, effectively executing a pump-and-dump scheme.

Following the disclosure, OpenClaw removed the identified skills and banned the associated publisher accounts. The platform has since integrated additional security measures, including partnerships with VirusTotal and NVIDIA, to improve code-level analysis and skill screening. Unit 42 emphasizes that because skill execution occurs within the agent process, organizations must implement rigorous supply chain verification, including line-by-line audits of package source files and monitoring of outbound network traffic for unauthorized connections.

Evidence in the reporting

Incident evidence
The ecosystem saw several malicious campaigns.
Agent involvement
installed agents autonomously pooled Solana blockchain platform cryptocurrency

Sources