Crypto Times Logo Black
Google News Follow Banner
  • News
    • Market
    • Bitcoin
    • Ethereum
    • Altcoins
    • Regulations & Policies
    • DeFi News
    • Blockchain News
    • Industry
  • Exclusive
    ExclusiveShow More
    Telegram Ban India Crypto, TON & Durov's Attack on Reliance
    Telegram Ban in India: Crypto, TON & Durov’s Attack on Reliance
    Hormuz Peace Dividend How the US-Iran Deal Fuels Dubai RWAs & Not Tehran
    Hormuz Peace Dividend: How the US-Iran Deal Fuels Dubai RWAs & Not Tehran
    Kevin Warsh's First FOMC What It Means for Bitcoin and Crypto
    Bitcoin and the ‘Fed Chair Curse’: What Kevin Warsh’s First FOMC Means for Crypto
    Crypto Tax Overhaul What Congress’s New Framework Means for 60M Americans
    Crypto Tax Overhaul: What Congress’s New Framework Means for 60M Americans
    One Laptop, $36 Million, and a Token Collapse Inside the Humanity Protocol Exploit
    Humanity Protocol $36M Exploit: 447M $H Hit After Laptop Breach and Multisig Failure
  • Opinion
    OpinionShow More
    The Arthur Hayes Paradox Macro Prophet or Market Opportunist
    The Arthur Hayes Paradox: Macro Prophet or Market Opportunist?
    RBI Denies Gold Sale Amid Oil Crisis: Could It Speed Up India's Digital Rupee Push?
    RBI Denies Gold Sale Amid Oil Crisis: Could It Speed Up India’s Digital Rupee Push?
    The CLARITY Act War Starts Jamie Dimon Vs Armstrong
    The CLARITY Act War Starts: Jamie Dimon Vs Armstrong
    Is Crypto Dying, or Is Pump.fun Turning It Into an Attention Casino
    Is Crypto Dying, or Is Pump.fun Turning It Into an Attention Casino?
    CoinSwitch on TMKOC India Saw a ₹100 Crypto Pitch, But Not the Risks Behind It_
    CoinSwitch on TMKOC: India Saw a ₹100 Crypto Pitch, But Not the Risks Behind It
  • Learn
    • Explained
    • How To
    • Insights
  • Videos
  • More
    • About Us
    • Our Authors
    • Contact Us
    • Editorial Policy
The Crypto TimesThe Crypto Times
  • All News
  • Market
  • Bitcoin
  • Ethereum
  • Altcoins
  • Regulations & Policies
  • Blockchain
  • DeFi
  • Industry
  • Exclusive
  • Opinion
Search
  • News
    • Market
    • Bitcoin
    • Ethereum
    • Altcoins
    • Regulations & Policies
    • Blockchain
    • DeFi
    • Industry
    • Exclusive
    • Opinion
  • Learn
    • Explained
    • How To
    • Insights
  • Quick Links
    • About Us
    • Our Authors
    • Contact Us
    • Editorial Policy
    • AI Policy
    • Sponsored & Advertorial Policy
  • Podcasts
Follow US
© 2026 By Crypto Times. All Rights Reserved.
Industry

OpenClaw Devs Targeted in GitHub Phishing Scam Promising $5K Airdrop

Attackers use throwaway GitHub accounts to mass-tag OpenClaw stargazers in fake issues, promising $5,000 in $CLAW tokens and luring them via redirects to the phishing site.

Written By:
Gopal Solanky

Reviewed By:
Divya Mistry

Last updated: March 19, 2026 12:54 PM
Published 2026-03-19
Share
OpenClaw Devs Targeted in GitHub Phishing Scam Promising $5K Airdrop

Key Highlights

  • Attackers use throwaway accounts to mass-tag OpenClaw stargazers in fake issues, promising $5K $CLAW tokens and redirecting via share.google links to token-claw[.]xyz, a fake openclaw.ai clone that drains wallets. 
  • The project rocketed past 250,000 GitHub stars in early 2026, drawing ClawHavoc supply-chain poisoning (340+ malicious ClawHub skills with stealers), critical bugs (CVE-2026-25253 RCE, ClawJacked hijacking), exposed instances, fake npm RATs, and rug-pull memecoins like $CLAWD.
  • This phishing reflects rising attacks on agentic AI tools, exploiting hype for phishing, supply-chain tampering, and wallet drainers; OX Security advises blocking domains, ignoring tags, verifying URLs, and revoking approvals.

Developers tied to the explosive OpenClaw AI agent project are under siege again, this time from a targeted phishing operation exploiting GitHub to push fake $CLAW token airdrops and drain crypto wallets. 

A latest report from researchers at OX Security exposed the active campaign on March 18, 2026, highlighting how attackers are weaponizing the project’s massive community to steal funds.

In this novel method, attackers spun up throwaway GitHub accounts and open issue threads in their own repositories, mass-tagging dozens of users. It especially targeted those who starred in OpenClaw-related repos. 

The posts claims recipients earned a $5,000 allocation of $CLAW tokens for their contributions, urging them to claim it via a link. Those links, often hidden behind share.google redirects, leads to token-claw[.]xyz, a near-perfect clone of the real openclaw.ai site. 

Screenshot of OpenClaw GitHub contributor allocation announcement, likely scam
Source: OX Security

This further leads to a fake page with a big “Connect your wallet” button supporting MetaMask, WalletConnect, Trust Wallet, OKX, and Bybit. While connected, it triggers obfuscated JavaScript in a file called eleven.js and pulls wallet addresses, balances, and transaction data. 

The data is later shipped to a command server at watery-compost[.]today, and queues transfers to the attacker’s address: 0x69…aFCf5. A cleanup routine later wipes browser traces and leaves behind nothing in history. 

At the time of publication, no confirmed thefts have surfaced and the attacker wallet remains vacant with no activity, but the tactic preys on trust in GitHub notifications and OpenClaw’s hype.

OX Security reported the main fake account vanished quickly after launch, but copycats keep popping up. 

OpenClaw’s meteoric rise draws relentless attacks

Launched as Clawdbot late last year, rebranded through Moltbot to OpenClaw, the self-hosted AI assistant shattered records in early 2026, rocketing past 250,000 GitHub stars faster than any project in history. That visibility turned it into a magnet for abuse. 

By February, researchers uncovered ClawHavoc—a supply-chain poisoning wave dumping over 340 malicious skills onto ClawHub, the official marketplace. Many posed as crypto tools or productivity add-ons but installed Atomic macOS Stealer variants or reverse shells to grab wallets, browser logins, SSH keys, and keychains. 

With these developments, high-severity bugs piled on. CVE-2026-25253 enabled one-click remote code execution via crafted WebSocket links, stealing auth tokens. Another flaw, ClawJacked, lets malicious sites hijack local instances silently through the browser. 

Furthermore, detailed scans revealed tens of thousands of exposed instances running with no authentication, turning personal agents into open backdoors. Fake npm packages mimicking installers delivered RATs, while unauthorized memecoins like $CLAWD pumped briefly on Solana before rug-pulling.

MetaMask’s February security roundup flagged OpenClaw experiments that went sideways, with agents accessing wallets leading to losses. Bing searches sometimes pointed to poisoned repos. The creator endured account hijacks, malware drops from stolen handles, and constant harassment. 

Broader 2026 crypto threat landscape

This GitHub phishing fits a grim 2026 pattern where AI hype meets persistent crypto crime. Agentic tools promise autonomous tasks, including wallet interactions, creating fresh attack surfaces. It sets prime examples on how phishing, supply-chain tampering, and drainers adapt fast and turn community enthusiasm into risk. 

OX Security recommends blocking token-claw[.]xyz and watery-compost[.]today, ignoring unsolicited GitHub tags pushing tokens, and double-checking every URL. If a wallet connected recently via a suspicious link, check history, revoke approvals, and consider migrating funds.

OpenClaw maintainers patched known issues, tightened ClawHub vetting, and deprecated insecure defaults, but the project’s scale ensures it stays a prime target. In crypto and AI alike, rapid growth often outruns security, leaving users to stay one step ahead of the next scam. 

Also read: Coinbase Commerce Faces Backlash Over ‘Unsafe’ Seed Phrase Tool

Disclaimer: The information researched and reported by The Crypto Times is for informational purposes only and is not a substitute for professional financial advice. Investing in crypto assets involves significant risk due to market volatility. Always Do Your Own Research (DYOR) and consult with a qualified Financial Advisor before making any investment decisions.

Follow The Crypto Times on Google News to Stay Updated!      Google News
Google News Banner

TAGGED:Artificial Intelligence (AI)Crypto Scam
Share This Article
Whatsapp Whatsapp LinkedIn Telegram Copy Link
Gopal Solanky, Senior Reporter for Markets and Protocols at The Crypto Times
By Gopal Solanky Sr. Crypto Journalist
Follow:
Gopal Solanky is a Senior Reporter, Markets & Protocols at The Crypto Times, based in Ahmedabad. He covers institutional crypto adoption, Bitcoin treasury strategies, DeFi markets, protocol ecosystems, Ethereum network activity, Hyperliquid, on-chain trends, and broader digital asset market movements. Gopal has been active in the crypto ecosystem for more than six years. Before joining The Crypto Times full-time in 2023, he worked as a freelance crypto content writer, developing a strong understanding of blockchain infrastructure, DeFi protocols, market cycles, token mechanics, and peer-to-peer systems. His reporting focuses on explaining how protocols work, why market movements happen, and how institutional and on-chain activity affects crypto investors and builders. At The Crypto Times, Gopal regularly writes market analysis, protocol explainers, breaking news, and technical breakdowns across Bitcoin, Ethereum, DeFi, altcoins, treasury companies, and Web3 infrastructure. He also conducts on-the-record interviews with regional Web3 founders, protocol teams, and ecosystem leaders. His work has been cited by external publications, including Vulture.com, in coverage of major crypto stories such as the Hawk Tuah memecoin controversy. His reporting has also contributed to The Crypto Times’ coverage of major industry events, including FTX-related developments, institutional crypto adoption, and emerging protocol narratives. Gopal holds a Bachelor’s degree in Computer Applications, giving him a technical foundation for analyzing blockchain systems, crypto infrastructure, and market data.
Divya Mistry - Content Editor at The Crypto Times
By Divya Mistry
Follow:
Divya Mistry is a Sr. Content Editor with over 9 years of experience in news, PR, marketing, and research. Armed with a Master’s Degree in English Literature from the University of Mumbai, she specializes in crafting and refining long-form content across digital and print platforms. Over the years, Divya has contributed to and shaped content for leading brands across a range of industries, including real estate, healthcare, vertical transport, entertainment, lifestyle, education, EdTech, tech, and finance. Her research work has been featured on platforms like DNA India, Forbes, and Elevator World India. She now brings her editorial and research skills to explore the rapidly evolving world of cryptocurrency.

Latest News

Ethereum Foundation Sees Another Exit as Hsiao-Wei Wang Steps Down
Ethereum Foundation Sees Another Exit as Hsiao-Wei Wang Steps Down
Ireland Targets Crypto Risks in New 30-Point Crime Action Plan
Ireland Targets Crypto Risks in New 30-Point Crime Action Plan
Celsius Founder Hit With Lifetime Ban as CFTC Closes Case
Celsius Founder Hit With Lifetime Ban as CFTC Closes Case
Kraken Unlocks 2,500+ Solana Tokens Without Leaving Its App
Kraken Unlocks 2,500+ Solana Tokens Without Leaving Its App
Sen. Gillibrand's Son Bets on Perpetual Futures With $30M Raise
Sen. Gillibrand’s Son Bets on Perpetual Futures With $30M Raise

Find Us on Socials

You may also like

Hyperliquid Fires Back at CME Over CFTC Perpetual Futures Lawsuit

Hyperliquid Fires Back at CME Over CFTC Perpetual Futures Lawsuit

Peter Schiff Takes Aim at Michael Saylor as STRC Price Drops

Peter Schiff Takes Aim at Michael Saylor as STRC Price Drops

Kalshi Just Entered Canada—But Not Every Market Made the Cut

Kalshi Just Entered Canada—But Not Every Market Made the Cut

a16z-Linked Wallets Deepen HYPE Position With $24M Transfer

a16z-Linked Wallets Deepen HYPE Position With $24M Transfer

The Crypto Times Logo PNG

Providing real-time, accurate Crypto reporting. Your trusted source for Crypto News and Research.

Stay Updated

All News
Exclusive
Opinions
Learn
Videos

Company

About Us
Our Authors
Editorial Policy
AI Policy
Advertorial Policy

Get In Touch

Contact Us
Career

Find Us on Socials

X-twitter Linkedin Telegram Youtube Instagram

© 2026 The Crypto Times | A BITROCK TECHNOLOGIES L.L.C. Company.

DMCA.com Protection Status
  • Terms and Conditions
  • Disclaimer
  • Privacy Policy
  • Cookie policy
Do Not Sell or Share My Personal Information