A targeted phishing campaign is hitting developers of OpenClaw, an open-source AI infrastructure project. Attackers are distributing a fake $CLAW token giveaway, promising a $5,000 prize to lure victims into connecting their wallets. Once a wallet is connected, malicious JavaScript code drains cryptocurrency funds and wipes local browser storage to hinder forensic analysis.
Forged GitHub Repositories and Issues
To build trust, the scammers set up fake GitHub repositories and create issues that directly reference or mention OpenClaw developers. By mimicking real project activity and personalizing outreach, they increase credibility. Developers who engage even briefly with these fraudulent platforms risk losing access to their funds. Security researchers highlight the growing sophistication of the attack.
Rising Profile Attracts Both Interest and Threats
OpenClaw provides an open-source infrastructure layer for persistent AI agents to handle automated scheduling and communication. Recent governance changes placed it under a foundation framework, accelerating adoption and drawing wider tech attention. This heightened visibility, however, makes it a prime target. Attackers analyze public GitHub activity — such as starred repos and recent discussions — to systematically identify active developers.
Founder Strikes Back: Discord Bans Crypto Talk
Peter Steinberger, OpenClaw founder, responded by imposing a platform-wide ban on cryptocurrency discussions in the Discord community. Members are immediately restricted from referencing tokens or digital assets — an aggressive move to curb scams and preserve trust. The phishing wave coincides with OpenAI's announcement that Steinberger will lead the personal AI agent development program at OpenClaw. Investigators have flagged domains like token-claw[.]xyz and watery-compost[.]today as distribution points. Users who authorized wallet connections are urged to revoke permissions immediately. At least one wallet address has been linked, though no confirmed fund losses have been reported. Despite mounting threats, OpenClaw continues to adapt its community rules and technical safeguards.

