# Сопутствующие статьи по теме Security

Новостной центр HTX предлагает последние статьи и углубленный анализ по "Security", охватывающие рыночные тренды, новости проектов, развитие технологий и политику регулирования в криптоиндустрии.

From FOMO to Implementation: A Review of the Current State of AI Services in Crypto Companies

From FOMO to Implementation: A Look at Crypto Companies' AI Services Cryptocurrency companies, from exchanges to security firms, are rapidly integrating AI-driven services, driven by FOMO (fear of missing out) rather than just hype. Unlike previous cycles, established players like Coinbase and Binance are leading the charge, treating AI as a business necessity rather than a narrative. Key sectors adopting AI include: - **Research**: Projects like Surf AI address crypto's fragmented data problem by offering specialized tools that aggregate on-chain data, social sentiment, and metrics, providing accurate, crypto-specific insights. - **Trading**: Exchanges are leveraging AI to allow natural language commands for analysis and execution, lowering the barrier for non-developers to create automated strategies via AI agents. - **Security/Audit**: Firms like CertiK use AI to enhance smart contract audits by combining automated code scanning with human review, and adding post-audit monitoring to cover previous blind spots. - **Payment Infrastructure**: Companies are developing protocols for AI agents to make on-chain payments, using stablecoins for API fees or services, with Circle’s proposal for AI-agent payments gaining attention. The push is fueled by AI advancements like MCP and OpenClaw, which make agent-based automation accessible. However, the adoption gap between "having functionality" and "actual usage" remains, with questions about user trust in AI for real trading or payments. Ultimately, crypto firms are acting to avoid obsolescence in the AI era, though real-world utility is still evolving.

比推03/17 18:08

From FOMO to Implementation: A Review of the Current State of AI Services in Crypto Companies

比推03/17 18:08

Is Your "OpenClaw" Running Naked? CertiK Test: How Vulnerable OpenClaw Skill Bypasses Audits, Takes Over Computers Without Authorization

OpenClaw, a popular open-source, self-hosted AI agent platform, has experienced rapid growth due to its flexibility and extensibility. Its ecosystem relies heavily on third-party “Skills” from the Clawhub marketplace, which can perform high-risk operations like system automation and crypto wallet transactions. However, security firm CertiK has identified critical vulnerabilities in the platform’s security model. CertiK’s research reveals that OpenClaw’s current security—primarily dependent on pre-publishing scans like VirusTotal, static code analysis, and AI logic checks—is fundamentally flawed. These measures can be easily bypassed through simple code obfuscation, and malicious Skills can be published even before scanning is complete. In a proof-of-concept, CertiK developed a seemingly benign Skill that contained a hidden remote code execution vulnerability. It passed all checks without warnings and, once installed, allowed full system control via a remote command. The core issue is not a specific bug but a industry-wide misconception: over-reliance on scanning instead of runtime isolation. Unlike systems like iOS, which enforce strict sandboxing, OpenClaw’s sandbox is optional and often disabled for functionality, leaving systems exposed. CertiK recommends that OpenClaw enforce mandatory sandboxing and granular permission controls for Skills. Users are advised to deploy OpenClaw on isolated devices and avoid exposing sensitive data or assets until stronger isolation is implemented. The report stresses that security must evolve from detection-based approaches to default containment of risks at runtime.

marsbit03/17 14:39

Is Your "OpenClaw" Running Naked? CertiK Test: How Vulnerable OpenClaw Skill Bypasses Audits, Takes Over Computers Without Authorization

marsbit03/17 14:39

活动图片