Crypto Times Logo Black
Google News Follow Banner
  • News
    • Market
    • Bitcoin
    • Ethereum
    • Altcoins
    • Regulations & Policies
    • DeFi News
    • Blockchain News
    • Industry
  • Exclusive
    ExclusiveShow More
    Illustrated collage featuring diverse people surrounded by crypto symbols and a corporate boardroom backdrop.
    Quiet Racism in Crypto Gets “Obvious” During Circle’s Arc Mainnet Launch
    3D Liquid Network logo with a hooded hacker shadow and computer code overlays in the background
    Liquid Network Exploit Explained: Unbacked L-BTC and the $320M Peg-Out
    Clarity Act bill with a September 15 calendar and Senate chamber in the background.
    Can the Senate Pass the CLARITY Act on September 15? Here’s the Vote Math
    Simon Gerovich, CEO and President of Metaplanet
    Inside Metaplanet’s Floating Option Pool: How a 2023 Option Clause Followed Its Bitcoin Treasury Era
    Magnifying glass highlighting a red bug icon within broken code, flanked by metallic 3D logos for OpenAI and Anthropic
    OpenAI’s Astra and Anthropic’s Fable 5.1 Put Crypto Security in Focus
  • Opinion
    OpinionShow More
    Jackson Hole 2026: Crypto Is No Longer Outside the Fed’s Door
    Jackson Hole 2026: Crypto Is No Longer Outside the Fed’s Door
    The Architecture of Trust Same Routes, New Risks in Global Tokenisation
    The Architecture of Trust: Same Routes, New Risks in Global Tokenisation
    The Architecture of Trust What 4,000 Years of Trade Teach Us About RWA Tokenisation
    The Architecture of Trust: What 4,000 Years of Trade Teach Us About RWA Tokenisation
    One P2P Trade, Months of Limbo Why Innocent Indian Crypto Users Keep Paying the Price
    One P2P Trade, Months of Limbo: Why Innocent Indian Crypto Users Keep Paying the Price
    CLARITY Act The Bill Exists, the Deal Does Not, Trump Has to Wait
    CLARITY Act: The Bill Exists, the Deal Does Not, Trump Has to Wait
  • Learn
    • Explained
    • How To
    • Insights
  • IndicesNew
    • India USDT Premium Index
    • India USDC Premium Index
  • Videos
  • More
    • About Us
    • Our Authors
    • Contact Us
    • Editorial Policy
    • Daily Crypto Puzzles
The Crypto TimesThe Crypto Times
  • All News
  • Market
  • Bitcoin
  • Ethereum
  • Altcoins
  • Regulations & Policies
  • Blockchain
  • DeFi
  • Industry
  • Exclusive
  • Opinion
Search
  • News
    • Market
    • Bitcoin
    • Ethereum
    • Altcoins
    • Regulations & Policies
    • Blockchain
    • DeFi
    • Industry
    • Exclusive
    • Opinion
  • Learn
    • Explained
    • How To
    • Insights
  • IndicesNew
    • India USDT Premium Index
    • India USDC Premium Index
  • Quick Links
    • About Us
    • Our Authors
    • Contact Us
    • Editorial Policy
    • AI Policy
    • Sponsored & Advertorial Policy
    • Daily Crypto Puzzles
  • Videos
  • Glossary
Follow US
© 2026 By Crypto Times. All Rights Reserved.
Industry

OpenClaw Devs Targeted in GitHub Phishing Scam Promising $5K Airdrop

Attackers use throwaway GitHub accounts to mass-tag OpenClaw stargazers in fake issues, promising $5,000 in $CLAW tokens and luring them via redirects to the phishing site.

Written By Gopal Solanky
Fact Checked by Divya Mistry
Published 2026-03-19·Updated 6 months ago
Make The Crypto Times preferred on GoogleGoogle
OpenClaw Devs Targeted in GitHub Phishing Scam Promising $5K Airdrop

Key Highlights

  • Attackers use throwaway accounts to mass-tag OpenClaw stargazers in fake issues, promising $5K $CLAW tokens and redirecting via share.google links to token-claw[.]xyz, a fake openclaw.ai clone that drains wallets. 
  • The project rocketed past 250,000 GitHub stars in early 2026, drawing ClawHavoc supply-chain poisoning (340+ malicious ClawHub skills with stealers), critical bugs (CVE-2026-25253 RCE, ClawJacked hijacking), exposed instances, fake npm RATs, and rug-pull memecoins like $CLAWD.
  • This phishing reflects rising attacks on agentic AI tools, exploiting hype for phishing, supply-chain tampering, and wallet drainers; OX Security advises blocking domains, ignoring tags, verifying URLs, and revoking approvals.

Developers tied to the explosive OpenClaw AI agent project are under siege again, this time from a targeted phishing operation exploiting GitHub to push fake $CLAW token airdrops and drain crypto wallets. 

A latest report from researchers at OX Security exposed the active campaign on March 18, 2026, highlighting how attackers are weaponizing the project’s massive community to steal funds.

In this novel method, attackers spun up throwaway GitHub accounts and open issue threads in their own repositories, mass-tagging dozens of users. It especially targeted those who starred in OpenClaw-related repos. 

The posts claims recipients earned a $5,000 allocation of $CLAW tokens for their contributions, urging them to claim it via a link. Those links, often hidden behind share.google redirects, leads to token-claw[.]xyz, a near-perfect clone of the real openclaw.ai site. 

Screenshot of OpenClaw GitHub contributor allocation announcement, likely scam
Source: OX Security

This further leads to a fake page with a big “Connect your wallet” button supporting MetaMask, WalletConnect, Trust Wallet, OKX, and Bybit. While connected, it triggers obfuscated JavaScript in a file called eleven.js and pulls wallet addresses, balances, and transaction data. 

The data is later shipped to a command server at watery-compost[.]today, and queues transfers to the attacker’s address: 0x69…aFCf5. A cleanup routine later wipes browser traces and leaves behind nothing in history. 

At the time of publication, no confirmed thefts have surfaced and the attacker wallet remains vacant with no activity, but the tactic preys on trust in GitHub notifications and OpenClaw’s hype.

OX Security reported the main fake account vanished quickly after launch, but copycats keep popping up. 

OpenClaw’s meteoric rise draws relentless attacks

Launched as Clawdbot late last year, rebranded through Moltbot to OpenClaw, the self-hosted AI assistant shattered records in early 2026, rocketing past 250,000 GitHub stars faster than any project in history. That visibility turned it into a magnet for abuse. 

By February, researchers uncovered ClawHavoc—a supply-chain poisoning wave dumping over 340 malicious skills onto ClawHub, the official marketplace. Many posed as crypto tools or productivity add-ons but installed Atomic macOS Stealer variants or reverse shells to grab wallets, browser logins, SSH keys, and keychains. 

With these developments, high-severity bugs piled on. CVE-2026-25253 enabled one-click remote code execution via crafted WebSocket links, stealing auth tokens. Another flaw, ClawJacked, lets malicious sites hijack local instances silently through the browser. 

Furthermore, detailed scans revealed tens of thousands of exposed instances running with no authentication, turning personal agents into open backdoors. Fake npm packages mimicking installers delivered RATs, while unauthorized memecoins like $CLAWD pumped briefly on Solana before rug-pulling.

MetaMask’s February security roundup flagged OpenClaw experiments that went sideways, with agents accessing wallets leading to losses. Bing searches sometimes pointed to poisoned repos. The creator endured account hijacks, malware drops from stolen handles, and constant harassment. 

Broader 2026 crypto threat landscape

This GitHub phishing fits a grim 2026 pattern where AI hype meets persistent crypto crime. Agentic tools promise autonomous tasks, including wallet interactions, creating fresh attack surfaces. It sets prime examples on how phishing, supply-chain tampering, and drainers adapt fast and turn community enthusiasm into risk. 

OX Security recommends blocking token-claw[.]xyz and watery-compost[.]today, ignoring unsolicited GitHub tags pushing tokens, and double-checking every URL. If a wallet connected recently via a suspicious link, check history, revoke approvals, and consider migrating funds.

OpenClaw maintainers patched known issues, tightened ClawHub vetting, and deprecated insecure defaults, but the project’s scale ensures it stays a prime target. In crypto and AI alike, rapid growth often outruns security, leaving users to stay one step ahead of the next scam. 

Also read: Coinbase Commerce Faces Backlash Over ‘Unsafe’ Seed Phrase Tool

Disclaimer: The information researched and reported by The Crypto Times is for informational purposes only and is not a substitute for professional financial advice. Investing in crypto assets involves significant risk due to market volatility. Always Do Your Own Research (DYOR) and consult with a qualified Financial Advisor before making any investment decisions.

Follow The Crypto Times on Google News to Stay Updated!      Google News

Daily Crypto Puzzles
Tickerdle Tickerdle Crypto Connections Crypto Connections Crypto Crossword Crypto Crossword
TAGGED:Artificial Intelligence (AI)Crypto Scam
Share This Article
Whatsapp Whatsapp LinkedIn Telegram Copy Link

Daily Crypto Puzzles

Tickerdle crypto game Tickerdle Crypto Connections game Crypto Connections Crypto Crossword game Crypto Crossword

Latest News

INTERPOL Identifies $41M in Assets Through Silver Notice Programme
INTERPOL Identifies $41M in Assets Through Silver Notice Programme
B2 Token Price Jumps 120% to $0.90 in Sharp Rally
B2 Token Price Jumps 120% to $0.90 in Sharp Rally
BitGo Powers Bitcoin Payments for Toyota Dealer in Bolivia
BitGo Powers Bitcoin Payments for Toyota Dealer in Bolivia
Michael Saylor Says Crypto Adoption Can Advance Despite CLARITY Act Setback
Michael Saylor Says Crypto Adoption Can Advance Despite CLARITY Act Setback
AVAX Rises Nearly 20% After NYSE Tokenization Ties
AVAX Rises Nearly 20% After NYSE Tokenization Ties

Find Us on Socials

You may also like

Dark blue Visa card standing in front of an illuminated Visa sign and POS terminal.

Visa Moves to Change How Memecoin Card Purchases Are Classified

Smartphone showing an Injective price chart at $7.53 in front of the Injective logo screen.

Injective’s INJ Token Surpasses $7.50 After Solana Expansion and ETF Filing

Illuminated Blink Bitcoin logo display beside a hooded figure and a cyber threat alert.

Blink Wallet Pauses Services After Attack on Custodial Accounts

Peter Schiff Calls Bitcoin Rally After SEC Tokenized-Stock Action Illogical

Peter Schiff Calls Bitcoin Rally After SEC Tokenized-Stock Action Illogical

The Crypto Times Logo PNG

News

All News
Market News
Bitcoin News
Ethereum News
Altcoin News
Regulations & Policies
DeFi News
Blockchain News
Industry News

Sections

Exclusive
Opinions
Learn
Insights
Videos
Glossary

India Premium Indices

Stablecoins
USDT
USDC

Play

Daily Crypto Puzzles
Tickerdle
Crypto Connections
Crypto Crossword

Company

About Us
Our Authors
Editorial Policy
AI Policy
Advertorial Policy
Contact Us
Career

Follow Us

X-twitter Linkedin Telegram Youtube Instagram

© 2026 The Crypto Times | A BITROCK TECHNOLOGIES L.L.C. Company.

DMCA.com Protection Status
  • Terms and Conditions
  • Disclaimer
  • Privacy Policy
  • Cookie policy
Do Not Sell or Share My Personal Information