Loading article…
Fake “CLAW” airdrop lures developers via cloned OpenClaw site, steals wallets; learn how the scam works and protection steps.
A phishing campaign that pretends to distribute a “CLAW” token airdrop has siphoned crypto wallets from GitHub developers, using a cloned OpenClaw site and obfuscated malware to harvest wallet credentials [1].
| At a glance | |
|---|---|
| Scam token | “CLAW” (non‑existent) |
| Fake reward | $5,000 worth of CLAW tokens claimed |
| Target platform | GitHub issues & pull requests |
| Wallets affected | Multiple wallets (MetaMask, WalletConnect, Trust, OKX, Bybit) |
Threat actors open issues in attacker‑controlled repositories, tag developers and promise a limited‑time “CLAW” airdrop worth up to $5,000 [1]. The message links to a site that looks identical to openclaw.ai but adds a “connect your wallet” button. When a victim connects a wallet, the malicious JavaScript in the “eleven.js” file sends wallet address, transaction value and name to a command‑and‑control server at watery‑compost.today [1]. The server then drains the wallet via functions such as PromtTx, Approved, and Declined, while a “nuke” routine erases traces from local storage [1].
No confirmed victims have been reported yet, but the campaign demonstrates a new vector: phishing inside GitHub workflows, a space where developers already trust the environment [1]. The attackers delete their GitHub accounts hours after launching the campaign, making attribution difficult. Researchers identified the threat actor’s receipt address 0x6981E9EA7023a8407E4B08ad97f186A5CBDaFCf5 and the phishing domain token‑claw.xyz [1]. They advise blocking the domain, revoking any wallet approvals granted to it, and treating unsolicited token‑giveaway issues as suspicious [1].
X (formerly Twitter) is rolling out an auto‑lock feature that will temporarily suspend accounts that mention cryptocurrency for the first time, aiming to cut the incentive for hijacked accounts to promote scams [2]. While the measure targets social‑media‑based scams, it reflects broader industry concern over crypto‑related phishing attacks that exploit trust in familiar platforms [2].
The OpenClaw fake‑token scheme shows how attackers can blend social engineering with code‑level obfuscation to steal crypto, highlighting the need for developers to verify any wallet‑connect prompts and for platforms to tighten controls on first‑time crypto mentions.
Coverage is mostly measured — 122 of 124 reports stay neutral.
Every Monday — the token unlocks, Fed dates & catalysts set to move crypto and markets this week. So you’re never blindsided.
Free · 3-min read · one-click unsubscribe
AI-assisted synthesis by the TrendWatcher Editorial Desk · sourced from 3 outlets · Jul 5, 2026 · How we report
It is a fraud where scammers pose as recruiters offering easy online tasks and require victims to use cryptocurrency to receive or unlock payments.
Crypto allows rapid, irreversible transfers that are hard for victims to recover once sent to a scammer's wallet.
Red flags include unexpected job texts, vague task descriptions, requests for crypto deposits, and promises that more money is earned by adding funds.
Stop sending money, document all details, report the incident to the FBI's Internet Crime Complaint Center and the FTC, and contact the crypto exchange used.
Legitimate employers typically do not require upfront crypto deposits to access earnings, and any such request should be treated as suspicious.