TechFlow Logo
Login/ Sign up
ETH Gas
Gwei
Fear
gas
Clawdbot Farce: Forced Rebranding, Cryptocurrency Scam, and 24-Hour Collapse

Clawdbot Farce: Forced Rebranding, Cryptocurrency Scam, and 24-Hour Collapse

2026.01.29
Share

TechFlow Selected TechFlow Selected

techFlow

Clawdbot Farce: Forced Rebranding, Cryptocurrency Scam, and 24-Hour Collapse

Within just a few minutes, the market cap of the CLAWD token—unrelated to this project—soared to $16 million before crashing rapidly.

2026.01.29 - 07:29:01
Clawdbot
Within just a few minutes, the market cap of the CLAWD token—unrelated to this project—soared to $16 million before crashing rapidly.

By: Jose Antonio Lanz

Translated by: Chopper, Foresight News

TL;DR

  • A trademark dispute triggered a naming controversy and account hijacking crisis for the viral AI application Clawdbot;
  • Within minutes, the unrelated CLAWD token surged to a $16 million market cap before collapsing;
  • Security researchers discovered multiple Clawdbot instances exposed online, with associated account credentials at risk of leakage.

Just days ago, Clawdbot was one of GitHub’s hottest open-source projects—amassing over 80,000 stars. This technically impressive tool enables users to run AI assistants locally via messaging apps like WhatsApp, Telegram, and Discord, granting them full system access.

Today, however, the project has not only been forced to rebrand due to legal issues but also targeted by cryptocurrency scammers. A fraudulent token launched under its name briefly spiked to a $16 million market cap before crashing—and the project itself drew criticism after researchers uncovered exposed gateways and easily accessible account credentials.

The crisis began when AI company Anthropic sent Peter Steinberger, Clawdbot’s founder, a trademark infringement claim. Many of Clawdbot’s features are built on Anthropic’s Claude model, and the company argued that “Clawd” is too similar to its trademarked name “Claude.” Objectively, this claim aligns with trademark law.

Yet this trademark dispute set off a chain reaction that ultimately spiraled out of control.

Peter Steinberger tweeted: “Does anyone in my Twitter following list work at GitHub? Can you help me recover my GitHub account? It’s been hijacked by crypto scammers.”

Peter Steinberger announced on Twitter that Clawdbot would be renamed Moltbot. The community responded with remarkable tolerance; the official project account even posted: “Same lobster kernel—just a new shell.”

Steinberger then proceeded to rename both his GitHub and Twitter accounts. But during the brief window between abandoning the old handles and registering the new ones, crypto scammers seized both accounts.

The compromised accounts immediately began aggressively promoting a fake CLAWD token issued on Solana. Within hours, speculative traders pushed its market cap above $16 million.

Some early investors claimed massive profits, while Steinberger publicly denied any affiliation with the token. Shortly thereafter, the token’s market cap collapsed—leaving late buyers with heavy losses.

Peter Steinberger tweeted: “To everyone in crypto: Stop messaging me. Stop harassing me. I will never launch a token. Any project listing me as a token issuer is a scam. I won’t charge anything—and your actions are seriously harming this project’s development.”

Steinberger’s firm rejection angered parts of the crypto community. Some speculators blamed his public denial for their losses and launched coordinated harassment campaigns against him. He was accused of “betrayal,” demanded to “take responsibility,” and pressured—despite having no knowledge of these projects—to endorse them.

Eventually, Steinberger successfully recovered his hijacked accounts. Meanwhile, security researchers uncovered a serious technical flaw: hundreds of Clawdbot instances were running without authentication, fully exposed to the public internet. In other words, the unmonitored permissions granted to this AI assistant could easily be exploited by malicious actors.

According to Decrypt, AI developer Luis Catacora used the Shodan search engine to scan for vulnerabilities and found the root cause lies largely in novice users assigning excessive permissions to the assistant. He wrote: “I just checked Shodan and found numerous port 18789 gateways exposed without any authentication. That means anyone can gain shell access to your server, automate browser actions, or even steal your API keys. Cloudflare Tunnel is free—this shouldn’t happen.”

Jamieson O’Reilly, founder of red-teaming firm Dvuln, also found it trivial to identify vulnerable servers. Speaking to The Register, he said: “I manually inspected several live instances—eight had absolutely no authentication and were wide open, while dozens more implemented partial protections but still left significant exposure risks.”

What’s the technical root cause? Clawdbot’s authentication system automatically trusts connections originating from localhost—that is, requests from the user’s own device. Most users deploy the software behind reverse proxies, causing all external requests to appear as if they originate from the local loopback address 127.0.0.1—and thus get automatically authorized—even though those requests actually come from outside the network.

Blockchain security firm SlowMist confirmed the vulnerability and issued a warning: the project contains multiple code flaws that could lead to credential theft or even remote code execution. Researchers demonstrated several prompt injection attack methods—including one delivered via email that, within minutes, tricked an AI instance into forwarding users’ private information to attackers.

“This is what happens when a project goes viral, expands rapidly, and skips security audits,” wrote Abdulmuiz Adeyemo, developer at startup incubator FounderOS. “The ‘open development’ model harbors a dark side nobody wants to talk about.”

For AI enthusiasts and developers, there’s good news: the project isn’t dead. Moltbot is functionally identical to Clawdbot—the underlying code is solid—and despite its popularity, the tool remains unintuitive for beginners, minimizing the risk of widespread misconfiguration. Its use cases are real, though it’s not yet ready for mainstream adoption. Meanwhile, its security issues remain unresolved.

Granting an autonomous AI assistant permissions like server shell access, browser control, and credential management introduces entirely new attack surfaces—ones traditional security frameworks weren’t designed to handle. These systems’ characteristics—local deployment, persistent memory, and proactive task execution—enable adoption speeds far exceeding the pace at which industry security practices can adapt.

And crypto scammers remain lurking in the shadows, waiting for their next opportunity to sow chaos.

Join TechFlow official community to stay tuned

Add to Favorites
Share to Social Media

Related Articles

2026.02.02

Interview with ClawdBot Founder: AI Is a Lever, Not a Replacement

“Programming languages no longer matter; what matters is my engineering mindset.”

Interview with ClawdBot Founder: AI Is a Lever, Not a Replacement
2026.02.02

No Humans Left: 150,000 Clawdbot Forum Posts Generated by Self-Developed AI—We Can’t Even Get a Word In

Does Moltbook represent a significant step forward in humanity’s understanding of AI—or is it merely an entertaining stunt?

No Humans Left: 150,000 Clawdbot Forum Posts Generated by Self-Developed AI—We Can’t Even Get a Word In
2026.01.29

Burnout, Restart, Viral Success: A 35-Minute Interview Transcript with Clawdbot’s Founder

“I hope this project outlives me. I think it’s too cool to let it rot.”

Burnout, Restart, Viral Success: A 35-Minute Interview Transcript with Clawdbot’s Founder
2026.01.27

ClawdBot Founder Says “Will Never Launch a Token”; Meme Trench Goes into Panic

Meme coins have evolved from “deifying,” “riding on the coattails of,” to “tying themselves to” deities.

ClawdBot Founder Says “Will Never Launch a Token”; Meme Trench Goes into Panic
2026.01.27

Clawdbot—the “Greatest AI Application to Date”—May Not Be for You

AI employees are wonderful, but they remain “dangerous” at this stage.

Clawdbot—the “Greatest AI Application to Date”—May Not Be for You
2026.01.27

Behind ClawdBot’s Viral Success: Founder PeterPeter and His Second Life

Clawdbot went from concept to prototype in just one hour, built by founder Peter.

Behind ClawdBot’s Viral Success: Founder PeterPeter and His Second Life
2026.01.26

I Spent 40 Hours Deeply Researching Clawdbot—Here’s the Truth Those Tweets Didn’t Tell You

The productivity tools leading us into the future are not magic—they require a continuous learning curve.

I Spent 40 Hours Deeply Researching Clawdbot—Here’s the Truth Those Tweets Didn’t Tell You
2026.07.27

Court Orders Seizure, Circle Refuses to Comply: A Tug-of-War Heading to Criminal Court

Tether can cooperate with law enforcement, why can't Circle?

Court Orders Seizure, Circle Refuses to Comply: A Tug-of-War Heading to Criminal Court
2026.07.27

"Disrupting Wall Street" Story Exits, Crypto Sector Shifts to Financial Underlying Infrastructure

Crypto companies are no longer attempting to replace Wall Street, but are instead charging Wall Street institutions technical service fees.

"Disrupting Wall Street" Story Exits, Crypto Sector Shifts to Financial Underlying Infrastructure
2026.07.27

Private Keys Are Math, Wallets Are Business: 2026 Web3 Wallet Chaos

Private keys are math, wallets are business.

Private Keys Are Math, Wallets Are Business: 2026 Web3 Wallet Chaos

7x24h News

TechFlow Logo

Navigating Web3 tides with focused insights

Contribute An Articleemail
Media Requestsmsg

Risk Disclosure: This website's content is not investment advice and offers no trading guidance or related services. Per regulations from the PBOC and other authorities, users must be aware of virtual currency risks. Contact us / [email protected] ICP License: 琼ICP备2022009338号