OpenClaw Developers Targeted in GitHub Phishing Scam Offering Fake Token Airdrops

iconCoinDesk
Share
Share IconShare IconShare IconShare IconShare IconShare IconCopy
AI summary iconSummary

expand icon
OpenClaw developers are being targeted in a GitHub phishing scam offering fake token airdrops. Attackers created fake accounts and tagged devs in issue threads, claiming they were selected for $5,000 in CLAW tokens. The phishing site mimics the OpenClaw website and tricks users into connecting wallets. OpenClaw, an open-source AI agent framework, has faced recent token launch news linked to scams using its name. New token listings often attract bad actors, and this case highlights the risks of wallet connection requests disguised as airdrops. Developers are urged to verify all links and avoid suspicious activity.

OpenClaw developers on GitHub, a platform for collaboration and version control, are being targeted in a phishing campaign using fake token giveaways to lure victims into connecting crypto wallets that can then be drained.

The attackers created bogus GitHub accounts and tagged developers in issue threads, claiming they had been selected to receive roughly $5,000 worth of CLAW tokens, Tel Aviv-based cybersecurity company OX Security said in a blog post on Wednesday.

The attackers' posts link to a near-identical clone of the OpenClaw website, but with a key addition: a prompt to connect a crypto wallet. Once a wallet is connected, malicious code can trigger transactions or approvals that allow attackers to siphon funds. The phishing page supports major wallets including MetaMask, WalletConnect and Trust Wallet, widening the potential impact, OX said.

The campaign highlights an increasingly common attack vector in crypto: social engineering paired with wallet connection requests, often disguised as airdrops or developer rewards. By targeting GitHub users who interacted with OpenClaw-related repositories, the attackers made the outreach appear more credible.

OpenClaw is an open-source AI agent framework and developer tool that has recently attracted attention, and controversy, over crypto-related scams exploiting its name.

Peter Steinberger, the founder of OpenClaw, said last month he was about to delete the entire codebase because of crypto. "I didn't know that they're not just good at harassment, they are also really good at using scripts and tools."

His statement followed a blanket ban he imposed on any mention of crypto, including bitcoin BTC$69,216.55, in the project's Discord after scammers in January hijacked OpenClaw's old accounts. The hackers promoted a fake CLAWD token that briefly hit a $16 million market cap before collapsing after Steinberger When Steinberger publicly denied any involvement.

Disclaimer: The information on this page may have been obtained from third parties and does not necessarily reflect the views or opinions of KuCoin. This content is provided for general informational purposes only, without any representation or warranty of any kind, nor shall it be construed as financial or investment advice. KuCoin shall not be liable for any errors or omissions, or for any outcomes resulting from the use of this information. Investments in digital assets can be risky. Please carefully evaluate the risks of a product and your risk tolerance based on your own financial circumstances. For more information, please refer to our Terms of Use and Risk Disclosure.