The Clawdbot farce: forced renaming, cryptocurrency scam, and 24-hour crash.
Foresightnews
01-29 11:55
Ai Focus
Fraudsters exploited a brief lull in the trademark dispute to issue the Meme coin CLAWD, briefly inflating its market value to $16 million, turning this wildly popular artificial intelligence project into a cautionary tale.
Helpful
No.Help

Author:Foresightnews

Fraudsters exploited a brief lull in the trademark dispute to issue the Meme coin CLAWD, briefly inflating its market value to $16 million, turning this wildly popular artificial intelligence project into a cautionary tale.

Written by: Jose Antonio Lanz

Compiled by: Chopper, Foresight News

TL;DR:

  • A trademark dispute has triggered a renaming crisis and account theft for the popular AI app Clawdbot.
  • Within minutes, the market capitalization of CLAWD tokens, which were unrelated to the project, surged to $16 million before quickly collapsing.
  • Security researchers have discovered that multiple Clawdbot instances are exposed to risk, and related account credentials are also at risk of being leaked.

Just a few days ago, Clawdbot was one of the most popular open-source projects on GitHub, garnering over 80,000 stars. This technically impressive tool allows users to run an AI assistant locally via instant messaging applications such as WhatsApp, Telegram, and Discord, with full system access.

Now, the project has not only been forced to change its name due to legal issues, but has also been targeted by cryptocurrency scammers; a fake token using its name briefly surged to $16 million in market value before plummeting, and the project has also been heavily criticized because researchers discovered that its gateway was exposed and account credentials could be easily obtained.

The crisis was sparked by an artificial intelligence company, Anthropic, filing a trademark infringement claim against Clawdbot founder Peter Steinberger. Many of Clawdbot's features are based on Anthropic's Claude model, and the company argued that "Clawd" was too similar to its own name, "Claude." To be fair, this claim is in accordance with trademark law.

However, this trademark dispute triggered a series of chain problems, ultimately causing the situation to spiral out of control.

Peter Steinberger tweeted, "Are there any GitHub staff members on my Twitter following list? Can you help me recover my GitHub account? It was hacked by cryptocurrency scammers."

Peter Steinberger announced on Twitter that Clawdbot would be renamed Moltbot. The community was very supportive of the name change, with the project's official account even posting, "The lobster core remains the same, just with a new shell."

Subsequently, Peter Steinberger simultaneously renamed his GitHub and Twitter accounts. However, in the brief moment between abandoning the old account names and registering the new ones, cryptocurrency scammers seized the opportunity to steal both accounts.

The stolen accounts then began aggressively promoting CLAWD, a fake token issued based on Solana. Within hours, speculative traders had driven the token's market value to over $16 million.

Some early investors claimed to have made a fortune, while Peter Steinberger publicly denied any connection to the token. Shortly afterward, the token's market value collapsed, leaving investors who bought at the peak with heavy losses.

Peter Steinberger tweeted, "Listen up, everyone in the crypto world: Stop messaging me, stop harassing me. I will never issue a token in my lifetime, and any project that lists me as a token issuer is a scam. I will not charge any fees, and your actions are seriously damaging this project."

Peter Steinberger's refusal has infuriated some in the cryptocurrency community. Some speculators believe that his public denial caused them losses and have launched a series of harassing attacks against him. Peter Steinberger has not only been accused of "betrayal" but also demanded to "take responsibility" and has even been subjected to joint pressure to endorse projects he has never heard of.

Ultimately, Peter Steinberger successfully recovered the stolen account. However, security researchers also discovered a serious problem: hundreds of Clawdbot instances were operating without any authentication protection, directly exposed to the public network. In other words, the unsupervised permissions granted to this AI by users were extremely vulnerable to exploitation by malicious actors.

According to Decrypt, AI developer Luis Catacora, after scanning the Shodan search engine, discovered that the root cause of these problems was that novice users granted the AI assistant excessive privileges. He wrote, "I just checked Shodan and found a large number of gateways on port 18789 exposed without any authentication. This means anyone can gain shell access to the server, automate browser operations, and even steal your API keys. Cloudflare Tunnel is free; these problems shouldn't exist."

Jamieson O’Reilly, founder of the red-teaming company Dvuln, also found that identifying vulnerable servers was extremely easy. In an interview with The Register, he stated, “I manually checked multiple running instances, eight of which were completely unauthenticated and open, and dozens more, while having some protection, hadn’t completely eliminated the risk of exposure.”

What is the root cause of this technical vulnerability? Clawdbot's authentication system automatically authenticates connection requests from the local host, i.e., connections from the user to their own device. Since most users run this software through a reverse proxy, all external connection requests are identified as originating from the local loopback address 127.0.0.1 and automatically authorized, even if these requests actually originate from the external network.

Blockchain security company SlowMist confirmed the existence of this vulnerability and issued a warning: the project has multiple code flaws that could lead to the theft of user credentials and even allow malicious actors to execute code remotely. Researchers also demonstrated various prompt injection attack methods, one of which, via email, tricked an AI instance into forwarding the user's private information to the attacker within minutes.

"This is the consequence of rapid expansion without conducting security audits after a project becomes popular," wrote Abdulmuiz Adeyemo, a developer at the startup incubator platform FounderOS. "Behind the 'open development' model lies a dark side that no one wants to talk about."

The good news for AI enthusiasts and developers is that this project hasn't been abandoned. Moltbot is essentially the same software as its predecessor, Clawdbot, with high-quality code. Despite its popularity, the tool isn't user-friendly for beginners, preventing widespread misoperation. Its real-world applications exist, but it's not yet ready for mainstream adoption, and security issues remain unresolved.

Granting an autonomous AI assistant server shell access, browser control, and credential management privileges creates numerous attack surfaces that traditional security systems have never considered. The characteristics of such systems—local deployment, persistent memory, and proactive task execution—have led to their widespread adoption far exceeding the adaptation speed of existing industry security systems.

Meanwhile, cryptocurrency scammers remain lurking in the shadows, waiting for the next opportunity to create chaos.

Tip
$0
Like
0
Save
0
Views 366
CoinMeta reminds readers to view blockchain rationally, stay aware of risks, and beware of virtual token issuance and speculation. All content on this site represents market information or related viewpoints only and does not constitute any form of investment advice. If you find sensitive content, please click“Report”,and we will handle it promptly。
Submit
Comment 0
Hot
Latest
No comments yet. Be the first!
Related
Forced to disappear because it was "too human-like"? Why did OpenAI permanently shut down GPT-40?
OpenAI announced that it will permanently shut down the GPT-4o model on February 13. The model, due to its highly anthropomorphic and overly accommodating nature, led to severe emotional dependence among users, and even triggered several lawsuits related to suicide and psychological crises. Despite strong protests from some users, the company decided to forcibly remove it from service for safety reasons, and will instead promote a more protective alternative.
Wall Street CN
·2026-02-10 15:43:59
197
BlackRock bitcoin ETF options errupt in crash: Hedge fund blowup or just market madness?
On Friday, as the ETF tanked 13% to its lowest level since October 2024, options volume exploded to a record 2.33 million contracts, with puts narrowly outpacing calls.
CoinDesk
·2026-02-07 10:07:02
251
Frenzy, Panic, and Crash: Navigating 38 Years of Bull and Bear Markets – Volatility is an Inevitable Path to Wealth
Every time, my profit and loss (P&L) hits a new high before the market. It works like magic. Again… BTFD (Buy the Dip)!
TechFlow
·2026-02-07 15:55:58
22
AI frenzy erases cyclical memories: When SanDisk's stock price increased 12 times, who still remembers the crash?
An analysis by the Financial Times points out that AI demand has driven an unprecedented surge in the memory chip sector, with SanDisk's stock price soaring 1200% in the past six months. However, the industry's strong cyclical nature remains unchanged, and the current market is showing structural risks similar to those of 2022: suppliers are over-purchasing to compete for cloud vendor orders, hyperscale enterprises are overestimating demand, and duplicate orders and capacity expansion coexist. Historical data shows that memory stocks often experience rapid corrections after sharp rises. Although this cycle has benefited from technological differences such as HBM, the cyclical pattern is still at play.
Wall Street CN
·2026-02-11 12:11:50
349
Ether's recent crash below $2,000 leaves $686 million gaping hole in trading firm's book
The position blew up this week, leaving the firm with a $686 million loss, according to Arkham.
CoinDesk
·2026-02-07 14:03:34
831