{"id":18447,"date":"2026-03-19T09:21:06","date_gmt":"2026-03-19T09:21:06","guid":{"rendered":"https:\/\/cryptoted.net\/index.php\/2026\/03\/19\/github-phishing-scam-uses-openclaw-branding-to-lure-developers-into-wallet-drain-report\/"},"modified":"2026-03-19T09:21:06","modified_gmt":"2026-03-19T09:21:06","slug":"github-phishing-scam-uses-openclaw-branding-to-lure-developers-into-wallet-drain-report","status":"publish","type":"post","link":"https:\/\/cryptoted.net\/index.php\/2026\/03\/19\/github-phishing-scam-uses-openclaw-branding-to-lure-developers-into-wallet-drain-report\/","title":{"rendered":"GitHub phishing scam uses OpenClaw branding to lure developers into wallet drain: report"},"content":{"rendered":"<p> <br \/>\n<br \/><img decoding=\"async\" src=\"https:\/\/crypto.news\/app\/uploads\/2023\/09\/crypto-news-phishing-computer-attack-Epic-NFT-on-the-background-neon-colors-hologram-style-v5.2.png\" \/><\/p>\n<div>\n<p>Crypto scammers are using OpenClaw\u2019s popularity to target developers via a new GitHub phishing campaign designed to drain their crypto wallets.<\/p>\n<div id=\"cn-block-summary-block_b68c65f47069f142b11b78ffbadd04a5\" class=\"cn-block-summary\">\n<p>\n        <span class=\"tabs__item is-selected\">Summary<\/span>\n    <\/p>\n<div class=\"cn-block-summary__content\">\n<ul class=\"wp-block-list\">\n<li>Attackers are impersonating OpenClaw on GitHub, creating fake accounts and tagging developers with messages offering $5,000 in $CLAW tokens.<\/li>\n<li>Victims are directed to a cloned website where a malicious wallet connection prompt is used to trigger wallet draining.<\/li>\n<li>OX Security says the campaign uses obfuscated code and targeted tactics, though no confirmed victims have been reported so far.<\/li>\n<\/ul><\/div>\n<\/div>\n<p><!-- .cn-block-summary --><\/p>\n<p>A <a href=\"https:\/\/www.ox.security\/blog\/openclaw-github-phishing-crypto-wallet-attack\/\" target=\"_blank\" rel=\"nofollow\">report<\/a> published by platform OX Security detailed an active <a href=\"https:\/\/crypto.news\/crypto-phishing-losses-plunge-83-to-84m-report-finds\/\" target=\"_blank\">phishing campaign<\/a> targeting OpenClaw via a coordinated effort on GitHub, where attackers create fake accounts, open issue threads in attacker-controlled repositories, and tag dozens of developers.<\/p>\n<p>One such post detailed how developers were approached with messages claiming they had been selected for an OpenClaw allocation, telling them they had won $5,000 worth of $CLAW tokens, and subsequently directing them to a fake website that closely resembles openclaw.ai.<\/p>\n<p>On the website, victims are presented with the option of connecting their wallets through a malicious \u201cConnect your wallet\u201d prompt that eventually leads to wallet draining.<\/p>\n<p>    <!-- .cn-block-related-link --><\/p>\n<p>The campaign has surfaced as OpenClaw has become a more visible project, especially after OpenAI CEO Sam Altman announced that OpenClaw creator Peter Steinberger would lead its push into personal AI agents. OpenClaw has since transitioned into a foundation-run open source project.<\/p>\n<p>Researchers at OX Security said attackers may be using GitHub\u2019s star feature to identify users who have starred OpenClaw-related repositories, thereby making it appear more targeted and credible.<\/p>\n<p>Scammers were seen using a file named \u201celeven.js\u201d to embed wallet-stealing code within obfuscated JavaScript. Once triggered, scammers used a built-in \u201cnuke\u201d function that wipes traces from the browser\u2019s local storage to avoid detection and continue tracking activity.<\/p>\n<p>The malware tracks user actions via commands such as PromptTx, Approved, and Declined, sending encoded data, including wallet addresses and transaction values, to a command and control server.<\/p>\n<p>Researchers have identified at least one wallet address believed to be linked to the attackers that was used to receive stolen funds. So far, there has been no confirmation of victims.<\/p>\n<p>OX Security has urged users to block token-claw[.]xyz and watery-compost[.]today, and avoid connecting crypto wallets to newly surfaced or unverified sites.<\/p>\n<p>In the meantime, OpenClaw creator Peter Steinberger has enforced a <a href=\"https:\/\/crypto.news\/openclaw-enforces-no-crypto-policy-across-discord\/\" target=\"_blank\">strict anti-crypto policy<\/a>. Any mention of cryptocurrencies across the project\u2019s Discord server can lead to removal.<\/p>\n<p>The decision stems from a scam that surfaced during its rebrand, where attackers promoted a Solana-based token called $CLAWD that surged to approximately $16 million in market capitalization before falling over 90% after Steinberger denied any involvement.<\/p>\n<p>    <!-- .cn-block-related-link --><\/p><\/div>\n<p><br \/>\n<br \/><a href=\"https:\/\/crypto.news\/github-phishing-scam-uses-openclaw-branding-to-lure-developers-into-wallet-drain-report\/\">Source link <\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Crypto scammers are using OpenClaw\u2019s popularity to target developers via a new GitHub phishing campaign designed to drain their crypto wallets. Summary Attackers are impersonating OpenClaw on GitHub, creating fake accounts and tagging developers with messages offering $5,000 in $CLAW tokens. Victims are directed to a cloned website where a malicious wallet connection prompt is [&hellip;]<\/p>\n","protected":false},"author":5,"featured_media":18448,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"tdm_status":"","tdm_grid_status":"","footnotes":""},"categories":[23],"tags":[],"kronos_expire_date":[],"class_list":["post-18447","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-crypto"],"_links":{"self":[{"href":"https:\/\/cryptoted.net\/index.php\/wp-json\/wp\/v2\/posts\/18447","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/cryptoted.net\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/cryptoted.net\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/cryptoted.net\/index.php\/wp-json\/wp\/v2\/users\/5"}],"replies":[{"embeddable":true,"href":"https:\/\/cryptoted.net\/index.php\/wp-json\/wp\/v2\/comments?post=18447"}],"version-history":[{"count":0,"href":"https:\/\/cryptoted.net\/index.php\/wp-json\/wp\/v2\/posts\/18447\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/cryptoted.net\/index.php\/wp-json\/wp\/v2\/media\/18448"}],"wp:attachment":[{"href":"https:\/\/cryptoted.net\/index.php\/wp-json\/wp\/v2\/media?parent=18447"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/cryptoted.net\/index.php\/wp-json\/wp\/v2\/categories?post=18447"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/cryptoted.net\/index.php\/wp-json\/wp\/v2\/tags?post=18447"},{"taxonomy":"kronos_expire_date","embeddable":true,"href":"https:\/\/cryptoted.net\/index.php\/wp-json\/wp\/v2\/kronos_expire_date?post=18447"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}