OpenClaw developers targeted in crypto phishing scam

Phishing targets OpenClaw developers via fake GitHub accounts and a cloned site, promising $5,000 in $CLAW tokens to lure victims into connecting wallets. No confirmed victims yet.

A coordinated phishing campaign has targeted developers linked to the OpenClaw AI project, exploiting its growing popularity. Attackers created fake GitHub accounts and opened issue threads in repositories they controlled, tagging developers with claims of winning $5,000 in non-existent $CLAW tokens. Victims were directed to a cloned OpenClaw website, visually similar to the official portal. There, a "Connect your wallet" button initiated the theft of crypto assets. The phishing sites used obfuscated JavaScript, including a file named "eleven.js," and a "nuke" function to erase evidence of wallet theft, complicating forensic analysis. The campaign also leveraged GitHub’s star feature to identify and target users, and sometimes appeared as legitimate extensions or tools. Security firms report no confirmed victims so far, but warn the infrastructure for wallet draining is fully operational. OpenClaw’s team has denied any token issuance and urged caution.

Related Tokens

Related News