- A recent phishing attack has emerged targeting OpenClaw developers, raising concerns about the potential loss of crypto assets.
- The attackers leveraged GitHub, creating fake accounts and repositories to lure developers with promises of $5000 in CLAW tokens.
- Users are redirected to a counterfeit website mimicking OpenClaw’s official site to steal cryptocurrency.
- Key tactics include using deceptive domains, redirecting through third-party services, and supporting popular wallets like MetaMask and Trust Wallet.
- As of now, no confirmed cases of financial loss have been reported, but the risk level remains high.
The Rise of Phishing Threats in Cryptocurrency
The recent phishing attack on OpenClaw developers highlights an alarming trend in the cryptocurrency space. As digital currencies gain popularity, so do the efforts of malicious actors seeking to exploit vulnerabilities. In this latest incident, attackers impersonated the OpenClaw project on GitHub, employing sophisticated techniques to deceive developers into surrendering access to their crypto wallets.
Anatomy of the Phishing Attack
The attackers crafted fake GitHub accounts and initiated discussions within controlled repositories. They mass-tagged developers with enticing messages promising $5000 worth of CLAW tokens for their contributions. This approach aimed to build credibility and lure unsuspecting targets into clicking malicious links.
Once users clicked these links, they were redirected to a fraudulent site that closely mirrored openclaw.ai. The site contained a wallet connection button which, once used, put user assets at risk of being stolen.
Tactics and Techniques
Several key features define this attack:
- Deceptive Domains: The attackers used domains like token-claw[.]xyz that closely resemble legitimate sites.
- Redirection Strategies: They employed third-party services such as linkshare for seamless redirection.
- User Data Collection: Information such as wallet addresses and transaction amounts was harvested.
- C2 Server Communication: Malicious code concealed within eleven.js could initiate unauthorized transactions and send data to a C2 server at watery-compost[.]today.
User Protection Recommendations
To mitigate risks, experts recommend adhering to basic cybersecurity practices:
- Avoid connecting crypto wallets to unfamiliar or new websites.
- Skeptically view token giveaways from unknown GitHub accounts.
- Block suspicious domains like token-claw[.]xyz proactively.
- Regularly check and revoke dubious wallet permissions.
Additionally, it’s advised that users be wary if they’ve interacted with any OpenClaw repositories recently as attackers might be targeting them specifically using GitHub’s “star” feature.
The Context: OpenClaw’s Security Challenges
This phishing campaign is not an isolated incident but part of a broader series of security challenges faced by OpenClaw:
- January 2026: Researchers discovered exposed Clawdbot servers lacking authentication safeguards—posing risks for chat leaks and API key exposure.
- Compromised Accounts: Hackers manipulated account control to launch a scam token named CLAWD that briefly reached $16 million in market cap before collapsing within a day.
