PANews 3月2日消息,GoPlus中文社区发布预警,OpenClaw Gateway现高危漏洞,请立即升级至2026.2.25或更高版本,审计并撤销授予Agent实例的不必要凭证、API密钥和节点权限。其分析称,OpenClaw通过绑定到本地主机的WebSocket Gateway运行,该Gateway作为Agent的核心协调层,是OpenClaw的重要组成部分。此次攻击针对的就是Gateway层的弱点,只需满足一个条件:用户在浏览器中访问被黑客控制的恶意网站。
完整攻击链如下:
1.受害者在其浏览器中访问攻击者控制的恶意网站;
2.页面中的JavaScript向本地主机上的OpenClaw网关发起WebSocket连接;
3.之后,攻击脚本以每秒数百次尝试暴力破解网关密码;
4.破解成功后,攻击脚本静默注册为受信任设备;
5.攻击者获得Agent的管理员级控制权;
Disclaimer: The information on this page may come from third parties and does not represent the views or opinions of Gate. The content displayed on this page is for reference only and does not constitute any financial, investment, or legal advice. Gate does not guarantee the accuracy or completeness of the information and shall not be liable for any losses arising from the use of this information. Virtual asset investments carry high risks and are subject to significant price volatility. You may lose all of your invested principal. Please fully understand the relevant risks and make prudent decisions based on your own financial situation and risk tolerance. For details, please refer to
Disclaimer.
Articoli correlati
Hackers Hijack Bonk.fun Domain, Deploy Wallet-Draining Phishing Prompt
The Bonk.fun platform warns users to avoid its site after hackers compromised an account, deploying a phishing prompt to drain wallets. The attack impacted only users who engaged with the malicious prompt, and losses were limited due to quick detection.
Decrypt53m fa
Ayush Varshney 被捕,8 億比特幣龐氏案追訴十年終突破
Ayush Varshney 在試圖離境時被印度中央調查局逮捕,他被控涉入 GainBitcoin 騙局,該案至今已近十年,損失高達660億盧比。Varshney 透過 Darwin Labs 建構該騙局的技術基礎,案件因主謀死亡和資金流動複雜而拖延。若定罪,他可能面臨多年監禁。
MarketWhisper1h fa
Bonk.fun 团队称黑客劫持账户并在域名植入盗币程序
Gate News 消息,3 月 12 日,Bonk.fun 团队成员 Tom 在 X 平台发布紧急警告,提醒用户暂时不要使用 bonk.fun 域名,因黑客已劫持团队账户并在域名上强制植入盗币程序。
GateNews1h fa
BONK.fun预警:BONKfun域名遭入侵,请勿交互
3月12日消息,BONK.fun于X发文表示,恶意行为者已入侵 BONKfun 域名,在团队确保一切安全之前,请勿与该网站进行任何交互。
GateNews2h fa
Fantasy.top 捲款風波:天使投資人指控失聯,創辦人稱從未動用一分錢
Fantasy.top 的創辦人否認對天使投資者的退款指控,強調公司兩年來依靠產品收入運營并未動用投資者資金。部分投資者表示未收到應有的財務報告,呼籲創辦人負責。該平台曾獲得良好評價,但近期已轉向預測市場,仍待官方進一步說明。
MarketWhisper2h fa
某用户因签署恶意 Approve 交易被盗 5.3 万美元 PAXG
Gate News 消息,3 月 12 日,据 GoPlus 监测,某用户因签署恶意 Approve 交易后,被钓鱼者转走价值 5.3 万美元的 PAXG。
GateNews3h fa