MarketAlert – Real-Time Market & Crypto News, Analysis & AlertsMarketAlert – Real-Time Market & Crypto News, Analysis & Alerts
Font ResizerAa
  • Crypto News
    • Altcoins
    • Bitcoin
    • Blockchain
    • DeFi
    • Ethereum
    • NFTs
    • Press Releases
    • Latest News
  • Blockchain Technology
    • Blockchain Developments
    • Blockchain Security
    • Layer 2 Solutions
    • Smart Contracts
  • Interviews
    • Crypto Investor Interviews
    • Developer Interviews
    • Founder Interviews
    • Industry Leader Insights
  • Regulations & Policies
    • Country-Specific Regulations
    • Crypto Taxation
    • Global Regulations
    • Government Policies
  • Learn
    • Crypto for Beginners
    • DeFi Guides
    • NFT Guides
    • Staking Guides
    • Trading Strategies
  • Research & Analysis
    • Blockchain Research
    • Coin Research
    • DeFi Research
    • Market Analysis
    • Regulation Reports
Reading: Viral AI assistant Clawdbot faces risk of leaking private messages and credentials
Share
Font ResizerAa
MarketAlert – Real-Time Market & Crypto News, Analysis & AlertsMarketAlert – Real-Time Market & Crypto News, Analysis & Alerts
Search
  • Crypto News
    • Altcoins
    • Bitcoin
    • Blockchain
    • DeFi
    • Ethereum
    • NFTs
    • Press Releases
    • Latest News
  • Blockchain Technology
    • Blockchain Developments
    • Blockchain Security
    • Layer 2 Solutions
    • Smart Contracts
  • Interviews
    • Crypto Investor Interviews
    • Developer Interviews
    • Founder Interviews
    • Industry Leader Insights
  • Regulations & Policies
    • Country-Specific Regulations
    • Crypto Taxation
    • Global Regulations
    • Government Policies
  • Learn
    • Crypto for Beginners
    • DeFi Guides
    • NFT Guides
    • Staking Guides
    • Trading Strategies
  • Research & Analysis
    • Blockchain Research
    • Coin Research
    • DeFi Research
    • Market Analysis
    • Regulation Reports
Have an existing account? Sign In
Follow US
© Market Alert News. All Rights Reserved.
  • bitcoinBitcoin(BTC)$69,811.00-0.53%
  • ethereumEthereum(ETH)$2,045.27-2.60%
  • tetherTether(USDT)$1.000.01%
  • rippleXRP(XRP)$1.40-3.16%
  • binancecoinBNB(BNB)$625.82-2.52%
  • usd-coinUSDC(USDC)$1.00-0.02%
  • solanaSolana(SOL)$84.46-4.17%
  • tronTRON(TRX)$0.2789810.64%
  • dogecoinDogecoin(DOGE)$0.094268-3.83%
  • Figure HelocFigure Heloc(FIGR_HELOC)$1.030.00%
Crypto NewsBlockchain

Viral AI assistant Clawdbot faces risk of leaking private messages and credentials

rahulbadiyafad150c105
Last updated: January 27, 2026 11:20 am
rahulbadiyafad150c105
Published: 2 weeks ago
Share

Cybersecurity researchers are sounding the alarm over a new AI personal assistant called Clawdbot, warning that misconfigured deployments could expose sensitive personal data and API credentials to the public.

Contents
  • Exposed Clawdbot Control servers leak credentials
  • Extracting a private key took five minutes

On Tuesday, blockchain security firm SlowMist said it identified a “gateway exposure” in Clawdbot that puts “hundreds of API keys and private chat logs at risk.”

“Multiple unauthenticated instances are publicly accessible, and several code flaws could lead to credential theft or even remote code execution,” SlowMist said.

The issue was first detailed on Sunday by security researcher Jamieson O’Reilly, who said that “hundreds of people” have unintentionally exposed their Clawdbot control servers to the internet in recent days.

Clawdbot is an open-source AI assistant built by developer and entrepreneur Peter Steinberger that runs locally on users’ devices. Interest in the tool surged over the weekend, with online discussion reaching “viral” levels, according to Mashable.

Exposed Clawdbot Control servers leak credentials

Clawdbot’s gateway links large language models to messaging platforms and allows command execution through a web-based admin interface known as “Clawdbot Control.”

O’Reilly said the vulnerability arises when the gateway is deployed behind an unconfigured reverse proxy, allowing attackers to bypass authentication. Using internet scanning tools such as Shodan, he was able to quickly locate exposed servers by searching for distinctive HTML identifiers.

“Searching for ‘Clawdbot Control’ took seconds and returned hundreds of results,” O’Reilly said.

According to the researcher, exposed instances could grant access to API keys, bot tokens, OAuth secrets, signing keys, full chat histories across platforms, the ability to send messages as the user, and command execution privileges.

“If you’re running agent infrastructure, audit your configuration today,” O’Reilly warned. “Check what’s actually exposed to the internet, understand what you’re trusting with that deployment, and what you’re trading away.”

“The butler is brilliant. Just make sure he remembers to lock the door.”

Extracting a private key took five minutes

Researchers warned that the AI assistant could also be exploited in more serious ways, including compromising crypto asset security.

Matvey Kukuy, CEO of Archestra AI, demonstrated the risk by attempting to extract a private key using prompt injection. He shared a screenshot showing that he sent Clawdbot an email designed to manipulate the assistant into checking the message and transmitting the private key from the compromised machine.

According to Kukuy, the entire process “took five minutes.”

Clawdbot differs from many other agentic AI tools in that it has full system-level access to users’ machines, allowing it to read and write files, run commands, execute scripts, and control browsers.

“Running an AI agent with shell access on your machine is… spicy,” the Clawdbot FAQ notes. “There is no ‘perfectly secure’ setup.”

The FAQ also outlines the threat model, warning that malicious actors may attempt to trick the AI into performing harmful actions, socially engineer access to user data, or probe for infrastructure details.

SlowMist advised users to mitigate these risks by applying strict IP whitelisting on any exposed ports.

Share this:

  • Share on X (Opens in new window) X
  • Share on Facebook (Opens in new window) Facebook

Like this:

Like Loading...

Related

Ethereum Approaches A “Never Broken” Support Line: Accumulators Step In
Sixteen More Palestinians Starve to Death in Gaza in Three Days Due to Israeli Siege
LETERS: Whimsical street names; politics and accountability
Jiuzi Holdings Launches $1 Billion Bitcoin Treasury with SOLV to Drive Institutional Yields and RWA Innovation | UseTheBitcoin
AM Best Removes From Under Review With Positive Implications and Upgrades Credit Ratings of Wolverine Insurance Company
TAGGED:AIAI & Hi-TechAltcoinBlockchaincryptocurrenciesCybersecurityPrivate KeysSecurity

Sign Up For Daily Newsletter

Be keep up! Get the latest breaking news delivered straight to your inbox.
By signing up, you agree to our Terms of Use and acknowledge the data practices in our Privacy Policy. You may unsubscribe at any time.
Share This Article
Facebook Email Copy Link Print
Previous Article Contractual Rights and Wrongs of International Economic Sanctions
Next Article Hyperliquid HIP-3 open interest reaches $793M amid commodities rally
© Market Alert News. All Rights Reserved.
 

Loading Comments...
 

    Welcome Back!

    Sign in to your account

    Username or Email Address
    Password

    Prove your humanity


    Lost your password?

    %d