Clawdrain: Exploiting Tool-Calling Chains for Stealthy Token Exhaustion in OpenClaw Agents
Fuente:
arXiv
Saved in:
| Main Authors: | Dong, Ben, Feng, Hui, Wang, Qian |
|---|---|
| Format: | Preprint |
| Published: |
2026
|
| Subjects: | |
| Online Access: | |
| Tags: |
Add Tag
No Tags, Be the first to tag this record!
|
Similar Items
Exploiting LLM Agent Supply Chains via Payload-less Skills
by: Liu, Xinyu, et al.
Published: (2026)
by: Liu, Xinyu, et al.
Published: (2026)
Who Tests the Testers? Systematic Enumeration and Coverage Audit of LLM Agent Tool Call Safety
by: Chen, Xuan, et al.
Published: (2026)
by: Chen, Xuan, et al.
Published: (2026)
Sleeping Giants -- Activating Dormant Java Deserialization Gadget Chains through Stealthy Code Changes
by: Kreyssig, Bruno, et al.
Published: (2025)
by: Kreyssig, Bruno, et al.
Published: (2025)
ChainFuzzer: Greybox Fuzzing for Workflow-Level Multi-Tool Vulnerabilities in LLM Agents
by: Wu, Jiangrong, et al.
Published: (2026)
by: Wu, Jiangrong, et al.
Published: (2026)
QASecClaw: A Multi-Agent LLM Approach for False Positive Reduction in Static Application Security Testing
by: Ameen, Mohd Ruhul, et al.
Published: (2026)
by: Ameen, Mohd Ruhul, et al.
Published: (2026)
Maven-Hijack: Software Supply Chain Attack Exploiting Packaging Order
by: Reyes, Frank, et al.
Published: (2024)
by: Reyes, Frank, et al.
Published: (2024)
Patch2QL: Discover Cognate Defects in Open Source Software Supply Chain With Auto-generated Static Analysis Rules
by: Wang, Fuwei, et al.
Published: (2024)
by: Wang, Fuwei, et al.
Published: (2024)
Detecting Stealthy Data Poisoning Attacks in AI Code Generators
by: Improta, Cristina
Published: (2025)
by: Improta, Cristina
Published: (2025)
Toward Automated Security Risk Detection in Large Software Using Call Graph Analysis
by: Pecka, Nicholas, et al.
Published: (2025)
by: Pecka, Nicholas, et al.
Published: (2025)
SafeToolBench: Pioneering a Prospective Benchmark to Evaluating Tool Utilization Safety in LLMs
by: Xia, Hongfei, et al.
Published: (2025)
by: Xia, Hongfei, et al.
Published: (2025)
Towards Robust Detection of Open Source Software Supply Chain Poisoning Attacks in Industry Environments
by: Zheng, Xinyi, et al.
Published: (2024)
by: Zheng, Xinyi, et al.
Published: (2024)
ConfuGuard: Using Metadata to Detect Active and Stealthy Package Confusion Attacks Accurately and at Scale
by: Jiang, Wenxin, et al.
Published: (2025)
by: Jiang, Wenxin, et al.
Published: (2025)
Defensible Design for OpenClaw: Securing Autonomous Tool-Invoking Agents
by: Li, Zongwei, et al.
Published: (2026)
by: Li, Zongwei, et al.
Published: (2026)
Clawed and Dangerous: Can We Trust Open Agentic Systems?
by: Chen, Shiping, et al.
Published: (2026)
by: Chen, Shiping, et al.
Published: (2026)
Centralized Defense: Logging and Mitigation of Kubernetes Misconfigurations with Open Source Tools
by: Russell, Eoghan, et al.
Published: (2024)
by: Russell, Eoghan, et al.
Published: (2024)
ARMS: A Vision for Actor Reputation Metric Systems in the Open-Source Software Supply Chain
by: Kalu, Kelechi G., et al.
Published: (2025)
by: Kalu, Kelechi G., et al.
Published: (2025)
HarnessAgent: Scaling Automatic Fuzzing Harness Construction with Tool-Augmented LLM Pipelines
by: Yang, Kang, et al.
Published: (2025)
by: Yang, Kang, et al.
Published: (2025)
LineBreaker: Finding Token-Inconsistency Bugs with Large Language Models
by: Chen, Hongbo, et al.
Published: (2024)
by: Chen, Hongbo, et al.
Published: (2024)
EvoPoC: Automated Exploit Synthesis for DeFi Smart Contracts via Hierarchical Knowledge Graphs
by: Liang, Ruichao, et al.
Published: (2026)
by: Liang, Ruichao, et al.
Published: (2026)
Towards Understanding and Characterizing Vulnerabilities in Intelligent Connected Vehicles through Real-World Exploits
by: Wang, Yuelin, et al.
Published: (2026)
by: Wang, Yuelin, et al.
Published: (2026)
Smart Contract and DeFi Security Tools: Do They Meet the Needs of Practitioners?
by: Chaliasos, Stefanos, et al.
Published: (2023)
by: Chaliasos, Stefanos, et al.
Published: (2023)
Trojan's Whisper: Stealthy Manipulation of OpenClaw through Injected Bootstrapped Guidance
by: Liu, Fazhong, et al.
Published: (2026)
by: Liu, Fazhong, et al.
Published: (2026)
Decoding Secret Memorization in Code LLMs Through Token-Level Characterization
by: Nie, Yuqing, et al.
Published: (2024)
by: Nie, Yuqing, et al.
Published: (2024)
PoCGen: Generating Proof-of-Concept Exploits for Vulnerabilities in Npm Packages
by: Simsek, Deniz, et al.
Published: (2025)
by: Simsek, Deniz, et al.
Published: (2025)
HALURust: Exploiting Hallucinations of Large Language Models to Detect Vulnerabilities in Rust
by: Luo, Yu, et al.
Published: (2025)
by: Luo, Yu, et al.
Published: (2025)
OriginPruner: Leveraging Method Origins for Guided Call Graph Pruning
by: Mir, Amir M., et al.
Published: (2024)
by: Mir, Amir M., et al.
Published: (2024)
Building Call Graph of WebAssembly Programs via Abstract Semantics
by: Paccamiccio, Mattia, et al.
Published: (2024)
by: Paccamiccio, Mattia, et al.
Published: (2024)
Automated Repair of OpenID Connect Programs (Extended Version)
by: Rahat, Tamjid Al, et al.
Published: (2025)
by: Rahat, Tamjid Al, et al.
Published: (2025)
Call graph discovery in binary programs from unknown instruction set architectures
by: Pettersen, Håvard, et al.
Published: (2024)
by: Pettersen, Håvard, et al.
Published: (2024)
VulnRepairEval: An Exploit-Based Evaluation Framework for Assessing Large Language Model Vulnerability Repair Capabilities
by: Wang, Weizhe, et al.
Published: (2025)
by: Wang, Weizhe, et al.
Published: (2025)
A Large-scale Empirical Study on the Generalizability of Disclosed Java Library Vulnerability Exploits
by: Chen, Zirui, et al.
Published: (2026)
by: Chen, Zirui, et al.
Published: (2026)
What's in a Package? Getting Visibility Into Dependencies Using Security-Sensitive API Calls
by: Rahman, Imranur, et al.
Published: (2024)
by: Rahman, Imranur, et al.
Published: (2024)
From Transactions to Exploits: Automated PoC Synthesis for Real-World DeFi Attacks
by: Su, Xing, et al.
Published: (2026)
by: Su, Xing, et al.
Published: (2026)
PhaseSeed: Precise Call Graph Construction for Split-Phase Applications using Dynamic Seeding
by: Palit, Tapti, et al.
Published: (2025)
by: Palit, Tapti, et al.
Published: (2025)
All Your Tokens are Belong to Us: Demystifying Address Verification Vulnerabilities in Solidity Smart Contracts
by: Sun, Tianle, et al.
Published: (2024)
by: Sun, Tianle, et al.
Published: (2024)
Lightweight Vulnerability Detection from Code Metrics and Token Features
by: Chiu, Chun Yin
Published: (2026)
by: Chiu, Chun Yin
Published: (2026)
A Large-Scale Exploit Instrumentation Study of AI/ML Supply Chain Attacks in Hugging Face Models
by: Casey, Beatrice, et al.
Published: (2024)
by: Casey, Beatrice, et al.
Published: (2024)
OpenSCV: An Open Hierarchical Taxonomy for Smart Contract Vulnerabilities
by: Vidal, Fernando Richter, et al.
Published: (2023)
by: Vidal, Fernando Richter, et al.
Published: (2023)
From Obfuscated to Obvious: A Comprehensive JavaScript Deobfuscation Tool for Security Analysis
by: Zhou, Dongchao, et al.
Published: (2025)
by: Zhou, Dongchao, et al.
Published: (2025)
SABER: Benchmarking Operational Safety of LLM Coding Agents in Stateful Project Workspaces
by: Hu, Qi, et al.
Published: (2026)
by: Hu, Qi, et al.
Published: (2026)
Similar Items
-
Exploiting LLM Agent Supply Chains via Payload-less Skills
by: Liu, Xinyu, et al.
Published: (2026) -
Who Tests the Testers? Systematic Enumeration and Coverage Audit of LLM Agent Tool Call Safety
by: Chen, Xuan, et al.
Published: (2026) -
Sleeping Giants -- Activating Dormant Java Deserialization Gadget Chains through Stealthy Code Changes
by: Kreyssig, Bruno, et al.
Published: (2025) -
ChainFuzzer: Greybox Fuzzing for Workflow-Level Multi-Tool Vulnerabilities in LLM Agents
by: Wu, Jiangrong, et al.
Published: (2026) -
QASecClaw: A Multi-Agent LLM Approach for False Positive Reduction in Static Application Security Testing
by: Ameen, Mohd Ruhul, et al.
Published: (2026)