Skip to main content
AVOID.NET

OpenClaw Developer GitHub Phishing Campaign

avoid.net/openclaw-developer-github-phishing-campaign2/100·72% conf.
[AI-DRAFTED · AWAITING VERIFICATION]

Auto-generated score, not yet verified against the scoring model. Under review — treat as indicative, not a verdict.

anchored·3HDjaK…cFq9

Summary

Beginning in March 2026, a phishing syndicate impersonated the open-source AI agent project OpenClaw on GitHub, tagging developers in issue threads with claims they had won roughly $5,000 in a fabricated 'CLAW' token, and directing them to a cloned OpenClaw website that used obfuscated JavaScript to drain connected MetaMask, WalletConnect, Trust Wallet, OKX and Bybit wallets. OpenClaw has no token and its founder, Peter Steinberger, has repeatedly and publicly stated the project will never issue one. Security researchers who identified the campaign found no confirmed financial losses at the time of disclosure, and this investigation found no verifiable reporting of a distinct new wave, new victims, or expanded tactics after the campaign's initial March 2026 disclosure through the September 2026 research date, despite the scam's continued relevance as a template that developers are warned to watch for.

Connected Entities

1 entity

No connected entities recorded yet — this investigation is not currently linked to any other page in the index.

Have evidence about OpenClaw Developer GitHub Phishing Campaign?

Timeline(4 events)

March 2026

A threat actor creates short-lived fake GitHub accounts and opens issues in attacker-controlled repositories, tagging developers with claims of a $5,000 CLAW token award and linking to a cloned OpenClaw phishing site; OX Security identifies and discloses the campaign.

OX Security blog

19 March 2026

CoinDesk reports on the OpenClaw GitHub phishing campaign and the fake $5,000 CLAW token airdrops.

CoinDesk

March 2026

CSO Online, Decrypt, The Block and other outlets publish follow-up coverage detailing the eleven.js drainer script, the watery-compost[.]today command-and-control domain, and the multi-wallet targeting (MetaMask, WalletConnect, Trust Wallet, OKX, Bybit).

CSO Online

July 2026

An existing AVOID.NET investigation page covering this campaign (slug: openclaw-github-phishing) is reported as last updated around this time; this later investigation found no independently verifiable reporting of a new wave or confirmed new victims after this point.

AVOID.NET internal record (scout system note)
Provenance & Audit Trail

Decision Log

This investigation is cryptographically anchored to the Solana blockchain (1 event). 9 of 10 cited source URLs have an Internet Archive snapshot.

model: claude-code-investigator

generated: 9/21/2026, 11:10:59 PM

last updated: 9/22/2026, 12:54:46 AM

1 view

avoid.net — verified advice for a post-truth world