Close Menu
Cryptosphere Update
  • Crypto News
  • Economy
  • Crypto Markets
  • World News
  • Technology
  • Breaking Views
What's Hot

States ask DHS to explain noncitizen voter claims

July 30, 2026

Kentucky Governor Mitch McConnell to certify whether he can serve in the Senate or “resign” from the Senate

July 28, 2026

A father shot his wife and six children to death, then set his Michigan home on fire and committed suicide, authorities say.

July 28, 2026
Facebook X (Twitter) Instagram
Trending
  • States ask DHS to explain noncitizen voter claims
  • Kentucky Governor Mitch McConnell to certify whether he can serve in the Senate or “resign” from the Senate
  • A father shot his wife and six children to death, then set his Michigan home on fire and committed suicide, authorities say.
  • Coinbase Chief Policy Officer Praises Draft Clarity Act
  • Bitcoin flips volatile in US trading session, soars towards $66,000
  • Singapore tightens monetary policy with unexpected measures as inflation risks reignite due to rising oil prices
  • At least 2 killed, 5 injured in Seattle shooting
  • Only 7% of major tokens are above their launch price
Facebook X (Twitter) Instagram
Cryptosphere Update
  • Crypto News
  • Economy
  • Crypto Markets
  • World News
  • Technology
  • Breaking Views
Crypto Heatmap
Cryptosphere Update
Home » GitHub phishing scam uses OpenClaw branding to lure developers into wallet breach: Report
Crypto News

GitHub phishing scam uses OpenClaw branding to lure developers into wallet breach: Report

Vickie HelmBy Vickie HelmMarch 19, 2026No Comments3 Mins Read
Facebook Twitter Pinterest LinkedIn Tumblr Email
Github phishing scam uses openclaw branding to lure developers into
Share
Facebook Twitter LinkedIn Pinterest Email

Cryptocurrency scammers are capitalizing on the popularity of OpenClaw to target developers through a new GitHub phishing campaign aimed at draining cryptocurrency wallets.

summary

Attackers are impersonating OpenClaw on GitHub, creating fake accounts and tagging developers with messages offering them $5,000 in $CLAW tokens. Victims are directed to a cloned website where a malicious wallet connection prompt is used to cause wallet exfiltration. OX Security says the campaign uses obfuscated code and targeted tactics, but no confirmed victims have been reported so far.

A report published by the platform OX Security details an active phishing campaign targeting OpenClaw through a coordinated effort on GitHub. In this campaign, attackers created fake accounts, opened issue threads in attacker-controlled repositories, and tagged dozens of developers.

One such post details how a developer was approached with a message claiming to have been selected for an OpenClaw assignment, told that he had won $5,000 worth of $CLAW tokens, and was then redirected to a fake website that closely resembled openclaw.ai.

The website gives victims the option to connect their wallet through a malicious “Connect your wallet” prompt, which ultimately leads to wallet exfiltration.

The campaign surfaced as OpenClaw became a more high-profile project, especially after OpenAI CEO Sam Altman announced that OpenClaw creator Peter Steinberger would lead efforts on a personal AI agent. OpenClaw has since transitioned to an open source project run by the Foundation.

OX Security researchers said attackers may be leveraging GitHub’s star feature to identify users who have starred OpenClaw-related repositories, making them appear more targeted and trustworthy.

Fraudsters have been observed using files named “eleven.js” to embed wallet-stealing code within obfuscated JavaScript. Once triggered, scammers use built-in “nuclear” features that erase their traces from your browser’s local storage to avoid detection and continue tracking your activity.

The malware tracks user actions through commands such as PromptTx, Approved, and Declined and sends encoded data, including wallet addresses and transaction values, to a command and control server.

Researchers have identified at least one wallet address believed to be linked to the attackers that was used to receive the stolen funds. So far, no victims have been identified.

OX Security is urging users to block token-claw(.)xyz and watery-compost(.) starting today, and to avoid connecting their cryptocurrency wallets to newly surfaced or unverified sites.

Meanwhile, OpenClaw creator Peter Steinberger has enforced a strict anti-crypto policy. Mentioning cryptocurrencies throughout the project’s Discord server may lead to removal.

The decision stems from a scam that surfaced during the rebrand, in which the attackers promoted a Solana-based token called $CLAWD, and its market capitalization soared to around $16 million, only to fall more than 90% after Steinberger denied involvement.

branding breach developers GitHub lure OpenClaw Phishing report scam Wallet
Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
vickiehelminc
Vickie Helm

Related Posts

Coinbase Chief Policy Officer Praises Draft Clarity Act

July 27, 2026

Bitcoin flips volatile in US trading session, soars towards $66,000

July 27, 2026

Only 7% of major tokens are above their launch price

July 25, 2026

BitMEX faces proposed class action lawsuit seeking return of 622BTC

July 25, 2026
Add A Comment

Comments are closed.

Popular Posts

The Future of Digital Prosperity: How AI and Web3 Are Shaping the Creator Economy 2.0

October 14, 2024

Bitcoin flips volatile in US trading session, soars towards $66,000

July 27, 2026

BitMEX faces proposed class action lawsuit seeking return of 622BTC

July 25, 2026

LINK has become the most undervalued asset in cryptocurrencies

July 24, 2026
Latest Posts

States ask DHS to explain noncitizen voter claims

July 30, 2026

Kentucky Governor Mitch McConnell to certify whether he can serve in the Senate or “resign” from the Senate

July 28, 2026

A father shot his wife and six children to death, then set his Michigan home on fire and committed suicide, authorities say.

July 28, 2026

Subscribe to Updates

Subscribe to our newsletter and stay updated with the latest news and exclusive offers.

About
About

At Cryptosphere Update, we are dedicated to bringing you in-depth coverage of the rapidly evolving crypto landscape, from market trends and emerging blockchain projects to regulatory developments and expert analysis. Our mission is to keep you informed and ahead of the curve in the ever-changing world of digital assets.

Facebook X (Twitter) Instagram Pinterest YouTube
Don't Miss

States ask DHS to explain noncitizen voter claims

July 30, 2026

Kentucky Governor Mitch McConnell to certify whether he can serve in the Senate or “resign” from the Senate

July 28, 2026

A father shot his wife and six children to death, then set his Michigan home on fire and committed suicide, authorities say.

July 28, 2026
Newsletter

Subscribe to Updates

Get the latest creative news from FooBar about art, design and business.

© 2026 Cryptosphere Update. All Rights Reserved.
  • About Us
  • Contact Us
  • Privacy Policy
  • Terms and Conditions
  • Disclaimer

Type above and press Enter to search. Press Esc to cancel.