OpenClaw’s rapid rise has drawn the attention of attackers, with a phishing campaign now targeting people who starred the open-source AI agent project on GitHub. Security firm OX Security said in a March 18 alert that the attackers are pushing fake messages promising $5,000 worth of “CLAW” tokens, then directing victims to a spoofed website designed to steal assets from connected Web3 wallets.
GitHub notifications used as the first hook
According to OX Security, the attackers used the GitHub API to identify users who had starred OpenClaw, then opened discussions in malicious repositories and tagged dozens of developers at a time. The notifications were delivered through GitHub’s official email system, which made the messages look credible and increased the chance that even experienced users would click through.
The bait was simple: recipients were told they had been selected to claim a token reward tied to OpenClaw. That link led them away from the real project site and into the phishing flow.
Fake website copies the real OpenClaw page
OX Security said the campaign used domains such as token-claw[.]xyz, with pages that closely mirrored the official OpenClaw site at openclaw.ai. The key addition was a wallet connection prompt. Once a user clicked “Connect your wallet,” the malicious backend was triggered.
The report said the wallet drainer supported common options including MetaMask and WalletConnect. An obfuscated script named eleven.js communicated with the C2 server watery-compost[.]today. After a victim approved the request, the attacker could quickly move assets out of the wallet.
Founder says any token promotion is a scam
OpenClaw founder Peter Steinberger responded on X with a direct warning, saying that any email or website claiming to offer OpenClaw-related tokens was “absolutely a scam.” He added that OpenClaw is a non-profit project and would never run that kind of promotion.
Other threats have also surfaced around OpenClaw
The phishing campaign is not the only security issue tied to the project. Earlier this month, researchers also found fake installers promoted through Bing AI search results, with those packages carrying the Vidar info-stealer. A malicious npm package named @openclaw-ai/openclawai was also identified and said to deploy the GhostLoader remote access trojan.
Researchers also flagged risks in ClawHub’s skill marketplace, where as many as 12% of plugins were found to contain AMOS stealer malware. OpenClaw is now ranked ninth among GitHub repositories worldwide, and security researchers are urging developers not to test unknown AI plugins on machines holding corporate credentials or large digital asset balances, and not to approve blind-signature requests.

