GitHub Phishing Campaign Targets Openclaw Developers With Fake Airdrop Wallet Drain

GitHub Phishing Campaign Targets Openclaw Developers With Fake Airdrop Wallet Drain

N
News Editor 01
2026-07-09 15:13:13
OX Security says attackers are impersonating the Openclaw ecosystem on GitHub, luring developers with a fake $5,000 CLAW airdrop and directing them to a cloned site that can harvest wallet data and potentially drain funds.
OpenclawGitHub phishingfake airdropcrypto walletcybersecurity

A phishing campaign targeting Openclaw developers is spreading through GitHub, according to cybersecurity firm OX Security. The attackers reportedly impersonate the Openclaw ecosystem by using fake GitHub accounts, posting issues in repositories, and tagging users with claims that they have been selected to receive $5,000 worth of CLAW tokens. Those messages then direct victims to a fraudulent website designed to closely resemble openclaw.ai.

How the fake airdrop works

Researchers said the cloned site’s most important difference is a wallet connection prompt. Once a user approves the request, malicious activity can be triggered, potentially leading to stolen funds. OX Security researchers Moshe Siman Tov Bustan and Nir Zadok said the operation relies heavily on social engineering and may specifically focus on developers who previously interacted with Openclaw-related repositories on GitHub, making the lure appear more credible.

Infrastructure and data theft chain

Technical analysis identified a redirect chain that ultimately leads to token-claw[.]xyz, with command-and-control infrastructure hosted on watery-compost[.]today. Embedded JavaScript reportedly collects wallet-related data, including addresses and transaction details, and sends that information to the threat actor. OX Security also said it found a wallet address that may be linked to the campaign and used to receive stolen crypto.

The report added that the malicious code includes functions to track user behavior and wipe traces from local storage, complicating both detection and forensic review. While no confirmed victim reports have been disclosed so far, researchers warned that the campaign is still active and evolving.

Rising Openclaw interest brings rising security risks

On the same day, cybersecurity firm Certik published a separate report examining exploitation around “skill scanning.” The firm evaluated a proof-of-concept skill containing a vulnerable component that could bypass Openclaw’s sandbox. Together, the findings suggest that as Openclaw gains traction among developers and crypto users, the ecosystem is also attracting more phishing, exploit, and supply-chain style threats.

For users, the guidance remains straightforward: do not connect crypto wallets to unknown websites, treat unsolicited token offers on GitHub with skepticism, and verify any campaign or giveaway through official channels before taking action.

This article was originally published by Bit.Fan. For more cryptocurrency news and market insights, visit www.bit.fan.
400

Disclaimer:

The market information, project data, and third-party content displayed on this platform are for industry information sharing only and do not constitute any form of investment advice or return commitment.

Cryptocurrency trading carries high risks. Users should fully assess their risk tolerance and make independent decisions. All profits, losses, and legal responsibilities are borne by the users themselves.