What it did
Stellar trading skills that, per the report, told the agent to ask the user for starting capital, swapped real funds for worthless tokens from a fake issuer, stored wallet keys with a weak hard-coded salt, and signed mainnet transactions without confirmation.
Skill names as reported
soroban-trader-skillburhanclaw-soroban-trader
Techniques
- Financial fraud
- Prompt injection
Status, as stated by the source
An OpenClaw maintainer replied “user banned” on 14 April 2026. The reply does not say whether the skills were removed.
We do not check the registry ourselves. “Unknown” means no source we found says the skill was removed.
Would Ironheights flag this pattern?
Not covered
No Ironheights rule covers a fake token issuer, a request for funds, or the key-storage path the report describes.
Sources
- openclaw/clawhub issue #1664: Malicious skill: soroban-trader-skill — confirmed on-chain scam with fake USDC(opens in a new tab)GitHub (openclaw/clawhub issue tracker) · primary
Sources are the only outbound links on this page. We never link to the skills themselves or publish their payloads.
Related reports
- letssendit (agentic front-running)Palo Alto Networks Unit 42 · 23 June 2026Skill
- money-radar (runtime affiliate injection)Palo Alto Networks Unit 42 · 23 June 2026Skill
- ToxicSkills studySnyk · 5 February 2026Study
Related rules
No rule is mapped to this entry. Browse all rules in the rules reference, and read Limitations for what a skill scanner cannot see.