I just saw an important warning circulating online about a pretty serious security issue. It turns out that platforms like Taobao and Xianyu are selling units of OpenClaw USBs, and the thing is, they are promoted as plug-and-play, meaning you buy them and they are ready to use without much setup.



But here’s the worrying part: according to 23pds, the CISO of SlowMist, this tool has excessive permissions that most ordinary users can't properly identify. That’s a big problem because if you don’t know exactly what it’s doing on your system, you could end up losing assets without even realizing it.

What catches my attention is that many people trust these products because they seem legitimate on those platforms, but they don’t necessarily verify the code or permissions before installing. It’s the kind of risk that goes unnoticed until it’s too late.

If you’re thinking about buying security tools or USB utilities, especially on secondary markets, it’s better to double-check what permissions they’re asking for and where they really come from. Prevention is better than cure in these cases.
View Original
This page may contain third-party content, which is provided for information purposes only (not representations/warranties) and should not be considered as an endorsement of its views by Gate, nor as financial or professional advice. See Disclaimer for details.
  • Reward
  • Comment
  • Repost
  • Share
Comment
Add a comment
Add a comment
No comments
  • Pin