AI tool OpenClaw encountered a “self-attack”: Bash command construction error led to key leak
Incident details: Web3 security company GoPlus disclosed that the AI development tool OpenClaw recently experienced a “self-attack.” The system, while automating the creation of GitHub Issues, triggered a command injection vulnerability due to an incorrectly wrapped backtick (set) in the Shell command constructed by AI. Leak details: The Bash environment interpreted the command as an execution command, causing the system to automatically output and publicly disclose over 100 lines of sensitive environment variables. The leaked information included core private data such as Telegram keys, authentication tokens, and more. Technical incentives: This incident highlights the uncontrollability of AI when executing low-level system commands. Due to a lack of syntactic validation of the generated content, the AI inadvertently exploited Bash features to push confidential information to public platforms. Security recommendations: GoPlus advises developers in AI automation scenarios: 1. Prioritize using API calls rather than directly concatenating Shell commands; 2. Follow the principle of least privilege to isolate environment variables; 3. Disable high-risk execution modes and introduce manual review.
The Trump family supports mining company ABTC's directors' large stake increase, holding 6,500 bitcoins, ranking 17th globally. Internal Increase: In the window period after the Q4 2025 financial report disclosure, two directors of American Bitcoin (ABTC) collectively increased their holdings by approximately 1.63 million shares. Justin Mateen purchased 1.3 million shares at an average price of $1, and Richard Busch bought 330,000 shares, demonstrating the core management's confidence in the company's prospects. Holding Data: Co-founder Eric Trump disclosed that the company currently holds over 6,500 bitcoins, an increase of about 500 from the last disclosure. This holding amount raises ABTC's rank among publicly listed companies holding bitcoin globally to 17th. Hybrid Strategy: ABTC adopts a dual-track model of 'mining + direct purchase of coins', with one-third of assets sourced from mining, and the remainder acquired through market purchases. This strategy is similar to a combination of MicroStrategy and Marathon. Expansion Plan: Despite a net loss of $59 million in Q4, the company announced the purchase of 11,298 ASIC mining machines, with pre-calculated computing power expected to increase by 12%. Currently, Eric Trump and Donald Trump Jr. collectively hold about 20% of the company's shares. #ABTC #特朗普 #比特币矿业 #EricTrump