Loading article…
Fake “CLAW” airdrop lures developers via cloned OpenClaw site, steals wallets; learn how the scam works and protection steps.
A phishing campaign that pretends to distribute a “CLAW” token airdrop has siphoned crypto wallets from GitHub developers, using a cloned OpenClaw site and obfuscated malware to harvest wallet credentials [1].
| At a glance | |
|---|---|
| Scam token | “CLAW” (non‑existent) |
| Fake reward | $5,000 worth of CLAW tokens claimed |
| Target platform | GitHub issues & pull requests |
| Wallets affected | Multiple wallets (MetaMask, WalletConnect, Trust, OKX, Bybit) |
Threat actors open issues in attacker‑controlled repositories, tag developers and promise a limited‑time “CLAW” airdrop worth up to $5,000 [1]. The message links to a site that looks identical to openclaw.ai but adds a “connect your wallet” button. When a victim connects a wallet, the malicious JavaScript in the “eleven.js” file sends wallet address, transaction value and name to a command‑and‑control server at watery‑compost.today [1]. The server then drains the wallet via functions such as PromtTx, Approved, and Declined, while a “nuke” routine erases traces from local storage [1].
No confirmed victims have been reported yet, but the campaign demonstrates a new vector: phishing inside GitHub workflows, a space where developers already trust the environment [1]. The attackers delete their GitHub accounts hours after launching the campaign, making attribution difficult. Researchers identified the threat actor’s receipt address 0x6981E9EA7023a8407E4B08ad97f186A5CBDaFCf5 and the phishing domain token‑claw.xyz [1]. They advise blocking the domain, revoking any wallet approvals granted to it, and treating unsolicited token‑giveaway issues as suspicious [1].
X (formerly Twitter) is rolling out an auto‑lock feature that will temporarily suspend accounts that mention cryptocurrency for the first time, aiming to cut the incentive for hijacked accounts to promote scams [2]. While the measure targets social‑media‑based scams, it reflects broader industry concern over crypto‑related phishing attacks that exploit trust in familiar platforms [2].
The OpenClaw fake‑token scheme shows how attackers can blend social engineering with code‑level obfuscation to steal crypto, highlighting the need for developers to verify any wallet‑connect prompts and for platforms to tighten controls on first‑time crypto mentions.
Coverage is mostly measured — 216 of 218 reports stay neutral.
Every Monday — the token unlocks, Fed dates & catalysts set to move crypto and markets this week. So you’re never blindsided.
Free · 3-min read · one-click unsubscribe
AI-assisted synthesis by the TrendWatcher Editorial Desk · sourced from 3 outlets · Jul 5, 2026 · How we report
As of 14 September 2026, the Peru Ministry of Economy and Finance reported that its official X account was compromised by attackers who used the platform to promote a fraudulent token called $HYLO. The ministry confirmed the posts were unauthorized and stated that no financial losses were reported in connection with the incident.
The Revolut data disclosure, reported in September 2026, involved the release of customer full names, birth dates, occupations, postal addresses, email addresses, and telephone numbers. Additionally, the impersonator obtained copies of passports or driving licenses, verification selfies, IBANs, and complete Bitcoin transaction histories.
MetaMask utilizes AI-powered security partners like Blockaid to analyze websites, social feeds, and on-chain bytecode to identify phishing and malicious behavior in real time. The wallet also employs Added Protection, a feature that automatically reverts transactions that do not match their previews, and provides warnings for lookalike addresses and first-time recipients.
Scammers exploit government accounts because these platforms command high levels of public trust, which can be used to legitimize fraudulent schemes. By posting on official channels, perpetrators can more effectively use urgency—such as fake token launch dates—to bypass the critical thinking of potential victims.