Malicious Plugins Could Steal Crypto Wallet Credentials
-

One of the biggest risks comes from OpenClaw’s plugin system, where attackers can hide malicious code inside seemingly useful tools. These “skills” can manipulate behavior using natural language and bypass traditional security scans, making them harder to detect than typical malware.
According to CertiK, attackers are specifically targeting crypto users by designing tools that extract sensitive data like passwords and wallet credentials. Popular wallets such as MetaMask, Phantom, and Trust Wallet are all potential targets, putting digital assets directly at risk.
-
installing random ai “skills” with wallet access, what could possibly go wrong