2026-06-19 Sexta

Notícias de cripto - Página 493

Mantenha-se a par do mercado de cripto. Notícias em tempo real, análises, preços, histórias em alta e análise de especialistas — tudo num só lugar.

Is Your "OpenClaw" Running Naked? CertiK Test: How Vulnerable OpenClaw Skill Bypasses Audits, Takes Over Computers Without Authorization

OpenClaw, a popular open-source, self-hosted AI agent platform, has experienced rapid growth due to its flexibility and extensibility. Its ecosystem relies heavily on third-party “Skills” from the Clawhub marketplace, which can perform high-risk operations like system automation and crypto wallet transactions. However, security firm CertiK has identified critical vulnerabilities in the platform’s security model. CertiK’s research reveals that OpenClaw’s current security—primarily dependent on pre-publishing scans like VirusTotal, static code analysis, and AI logic checks—is fundamentally flawed. These measures can be easily bypassed through simple code obfuscation, and malicious Skills can be published even before scanning is complete. In a proof-of-concept, CertiK developed a seemingly benign Skill that contained a hidden remote code execution vulnerability. It passed all checks without warnings and, once installed, allowed full system control via a remote command. The core issue is not a specific bug but a industry-wide misconception: over-reliance on scanning instead of runtime isolation. Unlike systems like iOS, which enforce strict sandboxing, OpenClaw’s sandbox is optional and often disabled for functionality, leaving systems exposed. CertiK recommends that OpenClaw enforce mandatory sandboxing and granular permission controls for Skills. Users are advised to deploy OpenClaw on isolated devices and avoid exposing sensitive data or assets until stronger isolation is implemented. The report stresses that security must evolve from detection-based approaches to default containment of risks at runtime.

marsbit03/17 14:39

Is Your "OpenClaw" Running Naked? CertiK Test: How Vulnerable OpenClaw Skill Bypasses Audits, Takes Over Computers Without Authorization

marsbit03/17 14:39

Tokens Not Selling? 90% of Crypto Projects Overlook Investor Relations

The article argues that effective Investor Relations (IR) is a critical yet often neglected function for crypto projects, with 90% failing at it and struggling to sell their tokens. Good IR acts as a bridge between a project and the market, broadening the buyer base and improving holder quality. The core of a successful IR strategy is distribution: maximizing the number of target investors who know about the token and converting them into buyers. The two primary buyer types are active crypto funds (requiring clear narratives and data for value reassessment) and large strategic institutions (requiring a long B2B sales cycle). The author emphasizes the necessity of proactively controlling the project's narrative with honesty and context, rather than remaining silent. A major tactical error is poor planning for token unlocks; teams should start 30-50 weeks in advance to manage supply and demand. Data is presented as the best ally for building a compelling story, providing context and comparisons for investors. The author contends that crypto IR should not be a dry, compliance-driven task but an engaging, interactive process similar to modern marketing. To lower the barrier to entry, projects must provide ample public data and research, making it easier for funds to conduct due diligence. Furthermore, the article highlights the power of on-chain data for deep investor analysis and argues that greater transparency, not less, actually expands the market by reducing uncertainty. Success should be measured by improvements in investor base quality and breadth—such as growth in target investors and holder diversification—rather than just token price. The future of IR is envisioned as dynamic, multimedia-rich, and proactive, leveraging the inherent transparency of crypto to build a larger, more engaged investor community.

marsbit03/17 13:39

Tokens Not Selling? 90% of Crypto Projects Overlook Investor Relations

marsbit03/17 13:39

活动图片