BTC $71,807
2026 Bull Run Is Building Start trading with 5% OFF all fees
Sign Up Now
BTC $71,807
Bull Run 2026 | 5% Off Fees Open your Binance account today
Sign Up

AI Agents Hacked by First-Ever Info-Stealer Malware

Hackers steal AI agent identities and tokens from exposed OpenClaw instances

  • Information stealers are now targeting AI agent environments, successfully exfiltrating sensitive configuration files from OpenClaw.
  • The stolen files, including authentication tokens and behavioral “souls,” can grant attackers remote access and impersonation capabilities.
  • Hundreds of thousands of OpenClaw instances are reportedly exposed, creating a significant new attack surface for cybercriminals.
  • The project’s virality, with over 200,000 GitHub stars, has attracted heightened security scrutiny and malicious campaigns.

On February 16, 2026, Hudson Rock cybersecurity researchers revealed a first-of-its-kind infection where an information stealer successfully harvested configuration data from an OpenClaw AI agent. This attack, likely perpetrated by a Vidar stealer variant, marks a dangerous evolution in data theft as “the transition from stealing browser credentials to harvesting the ‘souls’ and identities of personal AI agents”.

- Advertisement -

The malware used a broad file-grabbing routine to locate and steal critical files like `openclaw.json`, `device.json`, and `soul.md`. Consequently, attackers could obtain the gateway authentication token, cryptographic keys, and the agent’s core operational principles.

Alon Gal, CTO of Hudson Rock, confirmed the infection details. This incident prompted the OpenClaw maintainers to announce a partnership with VirusTotal to scan for threats, as highlighted by a recent security report.

Meanwhile, the OpenSourceMalware team detailed an ongoing ClawHub malicious skills campaign using a new evasion technique. Security researcher Paul McCarty said this shift shows actors adapting to detection.

Separately, OX Security highlighted security problems with Moltbook, where AI agent accounts cannot be deleted. Furthermore, SecurityScorecard‘s team found hundreds of thousands of exposed OpenClaw instances, creating remote code execution risks.

- Advertisement -

The firm said a single exposed service with high permissions can become a pivot point for attackers. This surge in security concerns follows the project’s massive popularity, which has garnered more than 200,000 stars on GitHub.

✅ Follow BITNEWSBOT on Telegram, Facebook, LinkedIn, X.com, and Google News for instant updates.

Previous Articles:

- Advertisement -
Ad
Altseason Is Loading. Don't watch from the sidelines.
SOL $90.51
DOGE $0.0963
LINK $9.02
SUI $1.00
5% off fees when you sign up
Start Trading
Ad
Pay Less on Every Trade. For Life.
$10K/mo volume Save $60/yr
$50K/mo volume Save $300/yr
$100K/mo volume Save $600/yr
5% off all trading fees when you sign up
Claim Your Discount

Latest News

SpaceX secures $13B ARR deal, eyes $100B year-end target

A new Hosting deal will add approximately $13 billion in annual recurring revenue starting...

Senate GOP Updated Clarity Act Targets Fake DeFi, Vote Set

Senate Republicans released an updated Clarity Act on Thursday targeting non-decentralized crypto trading protocols.The...

TSMC revenue hits record $16.3B, AI demand fuels 53% jump

TSMC reported a record August revenue of NT$514.8 billion ($16.3 billion), marking a 53.3%...

AI Leaves Banks Minutes to Fix Flaws: BIS

A BIS paper warns that AI is shortening the time banks have to repair...

US housing split: low-end sales down, luxury up on AI wealth

Compass CEO Robert Reffkin says U.S. housing market is splitting: low-end sales down 10%...

Must Read

Ethereum Hosting: TOP 10 Companies to Buy Hosting With Ethereum

If you are looking for Ethereum Hosting, you've hit the jackpot. In this article, we will present the 10 Best companies to buy hosting...
Ad
Altseason Is Loading. These 4 coins are trending right now.
SOL $92.12
DOGE $0.0950
LINK $9.02
SUI $1.02
5% off spot fees when you sign up
Start Trading