Multiple unauthenticated instances are publicly accessible, and several code flaws may lead to credential theft and even remote code execution.
π₯π₯π₯ This is fine π₯π₯π₯
πΏπΏπΏπππ
> But the optics are rough. A 3-month-old viral open-source project with 60K+ stars just got:
- Legal pressure from an $18B AI company
- Account-jacked by crypto scammers
- Exploited for millions in fake token scams
- Outed for serious security vulnerabilities
All in 72 hours.
---
https://dev.to/sivarampg/from-clawdbot-to-moltbot-how-a-cd-crypto-scammers-and-10-seconds-of-chaos-took-down-the-4eck
View quoted note →