PANews March 2 News, GoPlus Chinese Community issued an alert: OpenClaw Gateway currently has a high-severity vulnerability. Please upgrade immediately to version 2026.2.25 or higher, audit and revoke unnecessary credentials, API keys, and node permissions granted to Agent instances. The analysis states that OpenClaw runs through a WebSocket Gateway bound to the localhost, which serves as the core coordination layer for the Agent and is an important component of OpenClaw. The attack targets the weakness in the Gateway layer, requiring only one condition: the user accesses a malicious website controlled by hackers in their browser.
The complete attack chain is as follows:
- The victim visits a malicious website controlled by the attacker in their browser;
- JavaScript on the page initiates a WebSocket connection to the OpenClaw Gateway on the localhost;
- Subsequently, the attack script attempts to brute-force the gateway password hundreds of times per second;
- After successfully cracking the password, the attack script silently registers as a trusted device;
- The attacker gains administrator-level control of the Agent.
Disclaimer: The information on this page may come from third parties and does not represent the views or opinions of Gate. The content displayed on this page is for reference only and does not constitute any financial, investment, or legal advice. Gate does not guarantee the accuracy or completeness of the information and shall not be liable for any losses arising from the use of this information. Virtual asset investments carry high risks and are subject to significant price volatility. You may lose all of your invested principal. Please fully understand the relevant risks and make prudent decisions based on your own financial situation and risk tolerance. For details, please refer to
Disclaimer.
Related Articles
TRM Labs Report: AI-Driven Crypto Scams Increase 500% Year-over-Year by 2025
TRM Labs report indicates that artificial intelligence is reshaping digital financial crime, with illegal cryptocurrency flows expected to reach $158 billion by 2025. AI-driven scam cases have surged by 500%. Autonomous AI agents accelerate money laundering, lower the barriers to evasion, and lead to a compliance crisis. Legal liabilities are difficult to trace, requiring international cooperation to resolve jurisdiction conflicts.
GateNews43m ago
White-hat hackers help Foom Cash recover $1.84 million stolen funds, accounting for approximately 81% of the total funds.
Decentralized anonymous lottery protocol Foom Cash lost approximately $2.26 million due to a security vulnerability. White hat hackers intervened in time to recover $1.84 million. The issue stemmed from a misconfiguration of the Groth16 verifier. White hat hackers collaborated with security companies to protect the funds and received bounties and security fees.
GateNews57m ago
South Korea to investigate cryptocurrency photo leak and seed phrase incident causing $4.8 million in tax authority losses
The Korea National Tax Service apologized after publicly sharing a photo of a hardware wallet seed phrase, which led to the theft of $4.8 million worth of cryptocurrency. The government has requested police intervention and will strengthen regulations on digital asset management.
GateNews1h ago
Sanae Takashi issues a statement regarding "SANAE TOKEN": Not related and unauthorized
PANews March 2 News, Japanese Prime Minister Sanae Takaichi (@takaichi_sanae) posted that she has learned that a virtual currency called "SANAE TOKEN" has been issued and is being traded to some extent, but the name has caused misunderstandings among the public; she and her office have no knowledge of the token, have not been informed of its nature, and have not approved or endorsed the related token in any way, warning the public not to be misled.
GateNews1h ago
Curve Finance: Investigation into sDOLA LlamaLend attack initiated; attacker profits are limited
Curve Finance has launched an investigation into the attack on Inverse Finance, confirming a loss of approximately $240,000. The cause of the attack is related to the sDOLA price oracle mechanism and the amount of sDOLA in the market. This incident serves as a reminder that more stringent measures are needed for treasury-type collateral management. The Curve team is currently assessing security measures to ensure the safety of similar markets in the future.
GateNews1h ago
The US authorities confiscated over 61 million USDT from the "fattening then slaughtering" scam network
Federal prosecutors in North Carolina seized over $61 million USDT related to a cryptocurrency scam known as "pump and dump." Authorities traced stolen funds through a complex network of wallets used for laundering money from global victims. The scam often starts with fake romantic relationships to gain trust, leading victims to invest in false trading platforms with fabricated profits. When attempting to withdraw funds, victims face blockages or fake fees. This action is part of a broader effort to eliminate illegal profits and deter online scams exploiting digital assets.
TapChiBitcoin4h ago