OpenClaw developers targeted in GitHub phishing scam offering fake token airdrops
Security researchers said attackers are impersonating OpenClaw on GitHub, luring developers with bogus CLAW token giveaways that trick users into connecting their crypto wallets.

What to know:
- Attackers are targeting OpenClaw developers on GitHub and luring victims with fake $5,000 CLAW token giveaways that lead to wallet-draining sites.
- The phishing pages closely mimic the real OpenClaw website but add prompts to connect major crypto wallets like MetaMask, WalletConnect and Trust Wallet, enabling malicious transactions once users approve access.
- The campaign builds on a series of crypto-related scams exploiting OpenClaw's name, which previously prompted founder Peter Steinberger to ban all crypto discussion on the project's Discord after a fake token briefly reached a $16 million market cap.
OpenClaw developers on GitHub, a platform for collaboration and version control, are being targeted in a phishing campaign using fake token giveaways to lure victims into connecting crypto wallets that can then be drained.
The attackers created bogus GitHub accounts and tagged developers in issue threads, claiming they had been selected to receive roughly $5,000 worth of CLAW tokens, Tel Aviv-based cybersecurity company OX Security said in a blog post on Wednesday.
The attackers' posts link to a near-identical clone of the OpenClaw website, but with a key addition: a prompt to connect a crypto wallet. Once a wallet is connected, malicious code can trigger transactions or approvals that allow attackers to siphon funds. The phishing page supports major wallets including MetaMask, WalletConnect and Trust Wallet, widening the potential impact, OX said.
The campaign highlights an increasingly common attack vector in crypto: social engineering paired with wallet connection requests, often disguised as airdrops or developer rewards. By targeting GitHub users who interacted with OpenClaw-related repositories, the attackers made the outreach appear more credible.
OpenClaw is an open-source AI agent framework and developer tool that has recently attracted attention, and controversy, over crypto-related scams exploiting its name.
Peter Steinberger, the founder of OpenClaw, said last month he was about to delete the entire codebase because of crypto. "I didn't know that they're not just good at harassment, they are also really good at using scripts and tools."
His statement followed a blanket ban he imposed on any mention of crypto, including bitcoin
More For You

A wave of recent high-profile departures at the Ethereum Foundation has reignited longstanding questions from community members about what is going on inside the organization.
What to know:
- A wave of recent high-profile departures at the Ethereum Foundation has reignited longstanding questions from community members about what is going on inside the organization.
- The backlash echoes earlier debates surrounding former executive director Aya Miyaguchi’s transition and with the EF’s 2026 mandate, highlighting growing tensions between Ethereum’s decentralized ethos...











