Markets
BTC$83,722+0.79%ETH$2,538+1.17%SOL$111.25+0.87%XRP$1.41+0.39%BNB$754.56+0.47%DOGE$0.0868+1.06%ADA$0.2523+0.72%TRX$0.3303−0.18%LINK$13.36+2.48%AVAX$10.95+5.45%SUI$1.13+1.19%HYPE$86.51+1.29%
USD · 24h
Monday, October 12, 2026Crypto markets, policy & blockchain
Digital Coin Journal
Security

OpenClaw developers hit by GitHub phishing campaign promising fake “CLAW” airdrops

OpenClaw developers were targeted by a phishing campaign using fake GitHub rewards and cloned sites to steal wallet credentials.

Developer at desk with a GitHub phishing alert and a fake clone site prompting wallet connect.

OpenClaw’s developer community was hit by a coordinated phishing campaign in mid-March 2026, prompting the project’s creator to issue a public warning on March 19. The attackers posed as OpenClaw across GitHub and cloned websites, using fake token-reward messages to lure developers into connecting wallets and exposing their assets.

The campaign relied on a familiar but effective trick: convincing contributors that they had received a $CLAW token grant that did not exist. According to cybersecurity researchers and statements from Peter Steinberger, the operation used GitHub notifications and copycat versions of openclaw.ai to make the scam appear legitimate.

How the phishing campaign worked

Attackers created fake GitHub accounts and repositories, then used issues and discussion threads to tag contributors and stargazers directly. Those messages told targets they had won token rewards, often described as $5,000 or “5001” CLAW tokens, and pushed them toward fraudulent domains such as token-claw[.]xyz.

The cloned sites were designed to look convincing enough to trigger a rushed wallet connection. Once victims landed on the fake pages, they were met with a prominent “Connect Wallet” prompt that turned a developer-facing notification into a wallet-drain setup.

Researchers said the malicious pages ran obfuscated JavaScript that harvested wallet addresses, balances and transaction history after a connection was made. One analysis pointed to hidden code in files such as eleven.js, and also described a so-called “nuke” function that wiped browser local storage to make forensic review harder.

At least one suspected wallet address was identified as a destination for stolen funds, although no confirmed victims had been publicly established when researchers published their findings. Even without confirmed losses, the technical structure of the campaign made clear that the goal was direct asset theft rather than spam or impersonation alone.

OpenClaw and security researchers moved quickly

Peter Steinberger responded publicly on March 19 by warning that any crypto outreach or token offering claiming to be connected to OpenClaw was fraudulent. That statement was reinforced by OX Security, which published a detailed report on March 18 and urged developers to treat unsolicited GitHub tags and reward messages as hostile by default.

The incident did not emerge in isolation, but as part of a broader pattern of abuse surrounding OpenClaw after its rapid rise earlier in 2026. That pattern has already included fake npm packages, exposed instances, supply-chain tampering attempts and unauthorized memecoins launched under the project’s name.

The broader lesson is that developer ecosystems have become a high-value attack surface for wallet phishing and social engineering. For teams and contributors, the immediate priority is simple: verify every URL, distrust unsolicited token messages, revoke wallet approvals after any suspicious interaction, and treat public developer platforms as part of the threat model rather than as neutral infrastructure.

Tyler Anderson

Hi there! I'm Tyler Anderson from Sweden, and I'm a Web3 Reporter. My main focus is exploring the evolution of Web3, from DAO governance to the real utility of decentralized protocols.

More from Tyler Anderson →

This article is for information only and is not investment advice. We report under our Editorial Policy; to flag an error, see our Corrections Policy.