OpenClaw Developer GitHub Phishing Campaign
Auto-generated score, not yet verified against the scoring model. Under review — treat as indicative, not a verdict.
anchored·3HDjaK…cFq9Summary
Beginning in March 2026, a phishing syndicate impersonated the open-source AI agent project OpenClaw on GitHub, tagging developers in issue threads with claims they had won roughly $5,000 in a fabricated 'CLAW' token, and directing them to a cloned OpenClaw website that used obfuscated JavaScript to drain connected MetaMask, WalletConnect, Trust Wallet, OKX and Bybit wallets. OpenClaw has no token and its founder, Peter Steinberger, has repeatedly and publicly stated the project will never issue one. Security researchers who identified the campaign found no confirmed financial losses at the time of disclosure, and this investigation found no verifiable reporting of a distinct new wave, new victims, or expanded tactics after the campaign's initial March 2026 disclosure through the September 2026 research date, despite the scam's continued relevance as a template that developers are warned to watch for.
Connected Entities
1 entityNo connected entities recorded yet — this investigation is not currently linked to any other page in the index.
Timeline(4 events)
March 2026
A threat actor creates short-lived fake GitHub accounts and opens issues in attacker-controlled repositories, tagging developers with claims of a $5,000 CLAW token award and linking to a cloned OpenClaw phishing site; OX Security identifies and discloses the campaign.
OX Security blog19 March 2026
CoinDesk reports on the OpenClaw GitHub phishing campaign and the fake $5,000 CLAW token airdrops.
CoinDeskMarch 2026
CSO Online, Decrypt, The Block and other outlets publish follow-up coverage detailing the eleven.js drainer script, the watery-compost[.]today command-and-control domain, and the multi-wallet targeting (MetaMask, WalletConnect, Trust Wallet, OKX, Bybit).
CSO OnlineJuly 2026
An existing AVOID.NET investigation page covering this campaign (slug: openclaw-github-phishing) is reported as last updated around this time; this later investigation found no independently verifiable reporting of a new wave or confirmed new victims after this point.
AVOID.NET internal record (scout system note)Decision Log
- hash: 7yzTX25kngjM3mGTheoPUyCFyHH2o7FGssrM8KwhbMGH
This investigation is cryptographically anchored to the Solana blockchain (1 event). 9 of 10 cited source URLs have an Internet Archive snapshot.
model: claude-code-investigator
generated: 9/21/2026, 11:10:59 PM
last updated: 9/22/2026, 12:54:46 AM
1 viewavoid.net — verified advice for a post-truth world