← OpenClaw Developer GitHub Phishing Campaign1 decision on this page
Audit log
Every state-changing event for OpenClaw Developer GitHub Phishing Campaign: moderation decisions on community submissions, plus corrections and updates from the news pipeline. URL-based decisions are designed to carry three independent witnesses — the original source, an Internet Archive snapshot, and a Solana memo signed by our publicly-disclosed publisher key. Archive coverage is still being backfilled, so each decision below reports its own snapshot status rather than assuming one exists.
- #1publishby system:backfill2026-09-21 23:11:41ZScore: ? → ? (no score change)anchoranchored
- chain
- ●mainnet-betaslot 449,199,589
- sig
3HDjaKvqZEUt…s2E6cFq9explorer ↗- hash
7yzTX25kngjM…8KwhbMGHsha256 → base58
verifying row…full verify ↗canonical bytes (13118 B) ▸
{"actor":"system:backfill","investigation_id":"5819a798-1891-4bb7-9593-0df35c8dc80c","kind":"publish","page_slug":"openclaw-developer-github-phishing-campaign","published_at":"2026-09-21T23:11:40.842Z","sequence_num":1,"snapshot":{"content_type":"investigation","entity_name":"OpenClaw Developer GitHub Phishing Campaign","sections":[{"content":"Security firm OX Security disclosed that a threat actor created fake GitHub accounts and opened issues in attacker-controlled repositories, tagging dozens of developers with messages stating they had been selected to receive approximately $5,000 worth of 'CLAW' tokens for their contributions to open-source projects. Researchers assessed that the attackers may have used GitHub's star feature to identify and target users who had previously starred OpenClaw-related repositories, lending the outreach a veneer of relevance. The tagged links routed through a Google redirect to a phishing domain, token-claw[.]xyz, built as a near-identical clone of the legitimate openclaw.ai website, with one addition: a 'Connect your wallet' button not present on the real site.","heading":"The Phishing Mechanism: Fake CLAW Token Airdrops","severity":"high","sources":[{"credibility":2,"name":"OpenClaw Developers Targeted in Crypto-Wallet Phishing Attack (OX Security)","type":"research","url":"https://www.ox.security/blog/openclaw-github-phishing-crypto-wallet-attack/"},{"credibility":1,"name":"OpenClaw GitHub phishing scam uses fake $5,000 token airdrops gain wallet access (CoinDesk)","type":"news_article","url":"https://www.coindesk.com/tech/2026/03/19/openclaw-developers-targeted-in-github-phishing-scam-offering-fake-token-airdrops"},{"credibility":2,"name":"OpenClaw Developers Lured in GitHub Phishing Campaign Targeting Crypto Wallets (Decrypt)","type":"news_article","url":"https://decrypt.co/361646/openclaw-developers-lured-github-phishing-campaign"}]},{"content":"According to OX Security's technical breakdown, once a victim connected a wallet on the cloned site, heavily obfuscated JavaScript contained in a file named eleven.js activated drainer functionality supporting MetaMask, WalletConnect, Trust Wallet, OKX Wallet and Bybit Wallet. The script tracked connected wallet addresses, transaction values and usernames, and communicated with a command-and-control server at watery-compost[.]today using commands such as PromtTx, Approved and Declined to prompt and monitor malicious approval transactions in real time. Researchers also identified a built-in 'nuke' function designed to wipe wallet-theft data from the browser's local storage, apparently to frustrate forensic analysis after the fact. OX Security attributed a specific Ethereum address, 0x6981E9EA7023a8407E4B08ad97f186A5CBDaFCf5, to the threat actor and published a list of related indicators of compromise for blocking.","heading":"Technical Infrastructure of the Wallet Drainer","severity":"high","sources":[{"credibility":2,"name":"OpenClaw Developers Targeted in Crypto-Wallet Phishing Attack (OX Security)","type":"research","url":"https://www.ox.security/blog/openclaw-github-phishing-crypto-wallet-attack/"},{"credibility":2,"name":"GitHub phishers use fake OpenClaw tokens to drain crypto wallets (CSO Online)","type":"news_article","url":"https://www.csoonline.com/article/4150456/github-phishers-use-fake-openclaw-tokens-to-drain-crypto-wallets.html"}]},{"content":"The attacker-controlled GitHub accounts used to post the fake airdrop messages were reportedly created only about a week before the campaign launched and were deleted within hours of going live, a pattern researchers said was intended to evade detection and takedown. At the time OX Security published its findings, the firm stated it had assessed that no users had yet been affected by the drainer. Separately, a Hacker News discussion thread that surfaced around the same period collected reports from more than ten GitHub users who said they had received the same or similar fraudulent airdrop message tagging them by username; several noted that the sending accounts were newly created. No court filing, regulatory action, or on-chain analysis reviewed for this report documents a confirmed dollar figure lost to this specific CLAW-token drainer, and the Hacker News reports should be treated as low-confidence, self-reported, unverified community accounts rather than confirmed losses.","heading":"Scale, Evasion, and Reported Victim Impact","severity":"medium","sources":[{"credibility":2,"name":"OpenClaw Developers Targeted in Crypto-Wallet Phishing Attack (OX Security)","type":"research","url":"https://www.ox.security/blog/openclaw-github-phishing-crypto-wallet-attack/"},{"credibility":3,"name":"Likely Crypto Airdrop Scam Targeting GitHub Contributors (OpenClaw / $Claw) (Hacker News)","type":"community_report","url":"https://news.ycombinator.com/item?id=47425248"}]},{"content":"OpenClaw founder Peter Steinberger publicly warned that any crypto-themed outreach invoking the OpenClaw name should be treated as fraudulent, stating the project will never issue a token. Coverage noted this CLAW-token drainer campaign followed an earlier incident in which a counterfeit 'CLAWD' token unaffiliated with the project briefly reached an approximate $16 million market capitalization before collapsing, which reportedly led Steinberger to ban cryptocurrency discussion from the project's official Discord server. Steinberger was also quoted describing the volume and sophistication of the harassment and scripted abuse directed at contributors during this period. These reports frame the GitHub CLAW-token phishing campaign as one instance within a broader, recurring pattern of bad actors trading on OpenClaw's rapid rise in popularity (it became one of GitHub's most-starred repositories in 2026) to run crypto-themed scams unaffiliated with the legitimate project.","heading":"OpenClaw Project's Response and Broader Crypto-Impersonation Pattern","severity":"medium","sources":[{"credibility":1,"name":"OpenClaw GitHub phishing scam uses fake $5,000 token airdrops gain wallet access (CoinDesk)","type":"news_article","url":"https://www.coindesk.com/tech/2026/03/19/openclaw-developers-targeted-in-github-phishing-scam-offering-fake-token-airdrops"},{"credibility":2,"name":"OpenClaw Creator Warns of Crypto Phishing Wave: 'We Would Never Do That' (BeInCrypto)","type":"news_article","url":"https://beincrypto.com/openclaw-creator-warns-of-crypto-phishing-wave/"}]},{"content":"An existing AVOID.NET page on this topic (slug: openclaw-github-phishing) was reportedly last updated July 25, 2026. This investigation searched specifically for evidence that the CLAW-token GitHub phishing/wallet-drainer campaign described above expanded, resurfaced, or produced newly confirmed victims after that date, through the September 2026 research date. No court filing, regulatory advisory, security-vendor writeup, or mainstream news report was found documenting a distinct new wave of this specific CLAW-token airdrop drainer, new confirmed victims, new phishing domains, or new tactics tied to it since the original March 2026 disclosure. Separately, OpenClaw's broader security ecosystem generated substantial unrelated advisory volume in mid-2026 (a joylarkin/openclaw-security-news tracker shows headlines through at least July 20, 2026 covering the project's underlying software vulnerabilities, and researchers in July 2026 described a new, unrelated technique exploiting AI model hallucinations to plant malicious packages), but none of this later material specifically extends or confirms the CLAW-token GitHub airdrop drainer campaign as still active. The claim that the campaign 'continues to generate new victims' should therefore be treated as unverified pending further evidence; it is plausible given the templated, low-cost nature of this style of attack and the project's continued popularity, but it is not independently confirmed by the sources located.","heading":"Assessment of Claims That the Campaign Is Ongoing","severity":"low","sources":[{"credibility":2,"name":"joylarkin/openclaw-security-news (GitHub tracker)","type":"community_report","url":"https://github.com/joylarkin/openclaw-security-news"}]}],"sources_used":[{"credibility":2,"name":"OpenClaw Developers Targeted in Crypto-Wallet Phishing Attack (OX Security)","type":"research","url":"https://www.ox.security/blog/openclaw-github-phishing-crypto-wallet-attack/"},{"credibility":1,"name":"OpenClaw GitHub phishing scam uses fake $5,000 token airdrops gain wallet access (CoinDesk)","type":"news_article","url":"https://www.coindesk.com/tech/2026/03/19/openclaw-developers-targeted-in-github-phishing-scam-offering-fake-token-airdrops"},{"credibility":2,"name":"GitHub phishers use fake OpenClaw tokens to drain crypto wallets (CSO Online)","type":"news_article","url":"https://www.csoonline.com/article/4150456/github-phishers-use-fake-openclaw-tokens-to-drain-crypto-wallets.html"},{"credibility":2,"name":"OpenClaw Developers Lured in GitHub Phishing Campaign Targeting Crypto Wallets (Decrypt)","type":"news_article","url":"https://decrypt.co/361646/openclaw-developers-lured-github-phishing-campaign"},{"credibility":2,"name":"OpenClaw's rise draws phishing campaign targeting developers' crypto wallets (The Block)","type":"news_article","url":"https://www.theblock.co/post/394290/openclaw-phishing-crypto-wallets"},{"credibility":2,"name":"Fake OpenClaw Token Giveaway Targets GitHub Devs with Wallet-Draining Scam (Hackread)","type":"news_article","url":"https://hackread.com/fake-openclaw-token-github-devs-wallet-drainer-scam/"},{"credibility":2,"name":"OpenClaw Creator Warns of Crypto Phishing Wave: 'We Would Never Do That' (BeInCrypto)","type":"news_article","url":"https://beincrypto.com/openclaw-creator-warns-of-crypto-phishing-wave/"},{"credibility":3,"name":"Likely Crypto Airdrop Scam Targeting GitHub Contributors (OpenClaw / $Claw) (Hacker News)","type":"community_report","url":"https://news.ycombinator.com/item?id=47425248"},{"credibility":2,"name":"joylarkin/openclaw-security-news (GitHub tracker)","type":"community_report","url":"https://github.com/joylarkin/openclaw-security-news"},{"credibility":2,"name":"GitHub phishing scam uses OpenClaw branding to lure developers into wallet drain: report (crypto.news)","type":"news_article","url":"https://crypto.news/github-phishing-scam-uses-openclaw-branding-to-lure-developers-into-wallet-drain-report/"}],"summary":"Beginning in March 2026, a phishing syndicate impersonated the open-source AI agent project OpenClaw on GitHub, tagging developers in issue threads with claims they had won roughly $5,000 in a fabricated 'CLAW' token, and directing them to a cloned OpenClaw website that used obfuscated JavaScript to drain connected MetaMask, WalletConnect, Trust Wallet, OKX and Bybit wallets. OpenClaw has no token and its founder, Peter Steinberger, has repeatedly and publicly stated the project will never issue one. Security researchers who identified the campaign found no confirmed financial losses at the time of disclosure, and this investigation found no verifiable reporting of a distinct new wave, new victims, or expanded tactics after the campaign's initial March 2026 disclosure through the September 2026 research date, despite the scam's continued relevance as a template that developers are warned to watch for.","timeline":[{"date":"2026-03","event":"A threat actor creates short-lived fake GitHub accounts and opens issues in attacker-controlled repositories, tagging developers with claims of a $5,000 CLAW token award and linking to a cloned OpenClaw phishing site; OX Security identifies and discloses the campaign.","source":"OX Security blog","source_url":"https://www.ox.security/blog/openclaw-github-phishing-crypto-wallet-attack/"},{"date":"2026-03-19","date_evidence":"URL published at coindesk.com/tech/2026/03/19/openclaw-developers-targeted-in-github-phishing-scam-offering-fake-token-airdrops","event":"CoinDesk reports on the OpenClaw GitHub phishing campaign and the fake $5,000 CLAW token airdrops.","source":"CoinDesk","source_url":"https://www.coindesk.com/tech/2026/03/19/openclaw-developers-targeted-in-github-phishing-scam-offering-fake-token-airdrops"},{"date":"2026-03","event":"CSO Online, Decrypt, The Block and other outlets publish follow-up coverage detailing the eleven.js drainer script, the watery-compost[.]today command-and-control domain, and the multi-wallet targeting (MetaMask, WalletConnect, Trust Wallet, OKX, Bybit).","source":"CSO Online","source_url":"https://www.csoonline.com/article/4150456/github-phishers-use-fake-openclaw-tokens-to-drain-crypto-wallets.html"},{"date":"2026-07","event":"An existing AVOID.NET investigation page covering this campaign (slug: openclaw-github-phishing) is reported as last updated around this time; this later investigation found no independently verifiable reporting of a new wave or confirmed new victims after this point.","source":"AVOID.NET internal record (scout system note)","source_url":"https://www.avoid.net/openclaw-github-phishing"}]},"v":1}Verify offline (run on your own machine)python -m src.verify_decision 880763f6-d9b9-41d2-bb1a-8959b595a884
How verification works. The “Row integrity” check above is computed in your browser — your machine recomputes the SHA-256 of the canonical bytes and compares against the stored hash. No avoid.net server can fake that check. The “full verify” link goes one level deeper: your browser fetches the on-chain transaction from a Solana RPC node and confirms the same hash is in the memo. If you don’t want to trust either avoid.net or the public RPC, run the CLI verifier on your own machine —
python -m src.verify_decision <event_id>.