Hackers exploit OpenClaw hype on GitHub to steal crypto funds

2026-3-19 12:57

Crypto scammers are exploiting the rising visibility of OpenClaw to target developers through a coordinated phishing campaign on GitHub, according to a report by OX Security.

The campaign centres on fake reward claims tied to $CLAW tokens and aims to trick users into connecting their crypto wallets to malicious websites.

The activity has emerged as OpenClaw gains traction following leadership changes and its transition into a foundation-run open source project.

Researchers say attackers are leveraging developer activity on GitHub to make the scheme appear credible and personalised.

GitHub targeting tactics

The phishing operation is being carried out through attacker-controlled GitHub repositories.

Malicious actors create fake accounts, open issue threads, and tag large numbers of developers to maximise visibility.

In one example highlighted by researchers, developers were told they had been selected for an OpenClaw allocation.

The message claimed recipients had won $5,000 worth of $CLAW tokens and directed them to a website designed to closely mimic openclaw.ai.

The attackers are believed to be identifying targets by analysing GitHub’s star feature.

By focusing on users who have starred repositories linked to OpenClaw, the messages appear more relevant and convincing.

Wallet drain mechanism

Once users land on the fake site, they are prompted to connect their crypto wallets through a “Connect your wallet” feature.

This step activates malicious scripts that enable attackers to drain funds.

OX Security reported that the phishing pages include obfuscated JavaScript designed to hide wallet-stealing functions.

A file named eleven.js has been identified as a key component of the attack.

The malware includes a built-in “nuke” function, which clears traces from the browser’s local storage after execution.

This helps attackers avoid detection while continuing to monitor user activity.

Data tracking and exfiltration

The malicious code tracks user behaviour through a series of commands such as PromptTx, Approved, and Declined.

These commands allow attackers to monitor interactions in real time.

Encoded data, including wallet addresses and transaction values, is sent to a command and control server.

Researchers said at least one wallet address linked to the campaign has already been identified as a destination for stolen funds.

There has been no confirmed number of victims so far. However, the infrastructure and targeting methods suggest the campaign is actively seeking new users.

OpenClaw distancing from crypto

The phishing campaign coincides with growing attention around OpenClaw.

The project gained visibility after OpenAI CEO Sam Altman announced that creator Peter Steinberger would lead its push into personal AI agents.

Despite the crypto-themed scam, Steinberger has taken a strict stance against cryptocurrencies within the OpenClaw ecosystem.

Any mention of crypto assets on the project’s Discord server can result in removal.

This policy follows an earlier incident during OpenClaw’s rebrand.

At that time, scammers promoted a Solana-based token called $CLAWD, which reached a market capitalisation of about $16 million before dropping more than 90% after Steinberger denied any connection.

OX Security has advised users to block domains such as token-claw[.]xyz and watery-compost[.]today and to avoid connecting wallets to newly discovered or unverified platforms.

The post Hackers exploit OpenClaw hype on GitHub to steal crypto funds appeared first on Invezz

origin »

Bitcoin price in Telegram @btc_price_every_hour

Emerald Crypto (EMD) на Currencies.ru

$ 0 (+0.00%)
Объем 24H $0
Изменеия 24h: 0.00 %, 7d: 4.67 %
Cегодня L: $0 - H: $0
Капитализация $0 Rank 99999
Доступно / Всего 19.117m EMD / 32m EMD

crypto github campaign openclaw tied claw claims

crypto github → Результатов: 83


The GitVenom Crypto-Stealing Scheme: Hackers Use Phony GitHub Projects to Steal Your Crypto

Key Takeaways: “GitVenom” exploits fake GitHub repositories embedded with malware to target cryptocurrency users. Cyber attackers are leveraging AI-driven deception tactics to trick users into downloading malicious software disguised as The post The GitVenom Crypto-Stealing Scheme: Hackers Use Phony GitHub Projects to Steal Your Crypto appeared first on CryptoNinjas.

2025-2-28 14:27


ChainSafe Unveils Polkadot Index Network ‘PINT’ Token

In an April 14 announcement, ChainSafe revealed that it will be building a Polkadot Index Network Token called PINT. The source code is now public on Github. The latest crypto index is part of a collaboration between ChainSafe, staking services provider Stateless Money, and DeFi organization StakerDAO, which voted on its creation using funds from … Continued The post ChainSafe Unveils Polkadot Index Network ‘PINT’ Token appeared first on BeInCrypto.

2021-4-15 08:29


640 Crypto Projects Out of 2,000 Haven’t Published a SIngle Line of Code in 2019: Report

Combined market cap of these cryptos is $415 million Ethereum, EOS, Cardano, Lisk Leads the Github Activity Exchanges prioritizing their own interest “Crypto landscape is full of lies and empty promises,” states the report analyzing cryptocurrencies’ Github activity, by CoinCodeCap, a code analysis, reporting, and API services for cryptocurrencies technology provider. On analyzing the development […]

2019-9-25 19:36