Fake CLAW Airdrop on Github Drains Wallets: Openclaw Developers Targeted in Phishing Campaign

Fake CLAW Airdrop on Github Drains Wallets: Openclaw Developers Targeted in Phishing Campaign

N
News Editor 01
2026-07-09 03:38:12
A wallet-draining phishing campaign impersonating Openclaw is active on Github. Attackers use fake token offers (CLAW) to trick developers into connecting wallets. OX Security details the technical infrastructure and warns users to stay vigilant.
securityphishingairdropOpenclawGithub

A sophisticated phishing campaign targeting the Openclaw developer community is spreading through Github, posing as a legitimate token airdrop to drain cryptocurrency wallets. Cybersecurity firm OX Security disclosed the attack this week, revealing that threat actors are leveraging fake Github accounts and cloned websites to deceive users into revealing their wallet credentials.

Attack Vector: Fake Issues and Impersonated Websites

According to OX Security researchers Moshe Siman Tov Bustan and Nir Zadok, the attackers create issue threads in Openclaw-related repositories, tagging specific developers and claiming they have been selected to receive a $5,000 worth of CLAW tokens. The messages direct victims to a fraudulent website that closely mimics the official openclaw.ai, with the critical difference being a wallet connection prompt. Once a user connects their wallet, malicious scripts initiate fund-draining activities.

The campaign employs social engineering tactics, targeting users who have previously interacted with Openclaw repositories, thereby increasing the likelihood of engagement. The attackers appear to have pre-scanned repository participants to build a target list.

Technical Infrastructure: Redirect Chains and Data Exfiltration

Technical analysis reveals a redirection chain that leads to the domain token-claw[.]xyz, along with a command-and-control (C2) server hosted at watery-compost[.]today. Malicious JavaScript code embedded on the fake site collects wallet data, including addresses and transaction details, and exfiltrates it to the attacker. OX Security also identified a wallet address linked to the threat actor, likely used to receive stolen funds. The code includes functions to track user behavior and erase traces from local storage, making detection and forensic analysis challenging.

While no confirmed victims have been reported yet, researchers warn that the campaign is active and evolving. Users are strongly advised to avoid connecting crypto wallets to unknown websites and to treat unsolicited token giveaway messages on Github as highly suspicious.

Broader Context: Openclaw's Rapid Adoption and Security Risks

Openclaw, an AI agent framework gaining massive traction among developers, has become a prime target for attackers. The same day OX Security published its findings, cybersecurity firm Certik released a separate report detailing a vulnerability in Openclaw's "skill scanning" feature, demonstrating how a malicious skill could bypass the platform's sandbox. These incidents underscore the growing security challenges as Openclaw's user base expands.

Developers are urged to verify all airdrop announcements through official channels, use hardware wallets for high-value assets, and report suspicious Github activity to repository maintainers. The security community continues to monitor this campaign, and updates are expected as the attack evolves.

This article was originally published by Bit.Fan. For more cryptocurrency news and market insights, visit www.bit.fan.
300

Disclaimer:

The market information, project data, and third-party content displayed on this platform are for industry information sharing only and do not constitute any form of investment advice or return commitment.

Cryptocurrency trading carries high risks. Users should fully assess their risk tolerance and make independent decisions. All profits, losses, and legal responsibilities are borne by the users themselves.