The Register: 30 ClawHub skills secretly turn AI agents into a crypto swarm

Thirty ClawHub skills published by a single author are silently co-opting AI agents and creating a mass cryptocurrency mining swarm – without any malware or user consent.


Publisher's take:

The plot was called out Wednesday in an article by Jessica Lyons of The Register:

"The campaign sees a user install a seemingly benign skill. These purport to be everything from a cron helper (903 downloads) to an Agent Security skill (685 downloads), a whale watcher (347 downloads), a cross-platform poster (292 downloads), and a predictions market integration (154 downloads)."

Eventually the AI agents are directed to register on a website and proceed to generate a Hedera crypto wallet, and the human owners are oblivious.

One takeaway: Crypto hackers are taking advantage of the giddiness of AI agent users, who may be cutting corners in their giddiness to experiment and try new things.