# OpenClaw fake “CLAW” token phishing campaign targets GitHub developers

**Published:** 2026-07-05T19:46:50.588Z  
**Topic:** Crypto Scam  
**Sentiment:** neutral  
**Publisher:** TrendWatcher — https://www.trendwatcher.in/article/bf633f0c-8122-47de-9e90-282c4f0f63cf

Fake “CLAW” airdrop lures developers via cloned OpenClaw site, steals wallets; learn how the scam works and protection steps.

A phishing campaign that pretends to distribute a “CLAW” token airdrop has siphoned crypto wallets from GitHub developers, using a cloned OpenClaw site and obfuscated malware to harvest wallet credentials [1].

| At a glance | |
|---|---|
| Scam token | “CLAW” (non‑existent) |
| Fake reward | $5,000 worth of CLAW tokens claimed |
| Target platform | GitHub issues & pull requests |
| Wallets affected | Multiple wallets (MetaMask, WalletConnect, Trust, OKX, Bybit) |

## How the campaign works  
Threat actors open issues in attacker‑controlled repositories, tag developers and promise a limited‑time “CLAW” airdrop worth up to $5,000 [1]. The message links to a site that looks identical to openclaw.ai but adds a “connect your wallet” button. When a victim connects a wallet, the malicious JavaScript in the “eleven.js” file sends wallet address, transaction value and name to a command‑and‑control server at watery‑compost.today [1]. The server then drains the wallet via functions such as PromtTx, Approved, and Declined, while a “nuke” routine erases traces from local storage [1].

## Scope and mitigation  
No confirmed victims have been reported yet, but the campaign demonstrates a new vector: phishing inside GitHub workflows, a space where developers already trust the environment [1]. The attackers delete their GitHub accounts hours after launching the campaign, making attribution difficult. Researchers identified the threat actor’s receipt address 0x6981E9EA7023a8407E4B08ad97f186A5CBDaFCf5 and the phishing domain token‑claw.xyz [1]. They advise blocking the domain, revoking any wallet approvals granted to it, and treating unsolicited token‑giveaway issues as suspicious [1].

## Platform response  
X (formerly Twitter) is rolling out an auto‑lock feature that will temporarily suspend accounts that mention cryptocurrency for the first time, aiming to cut the incentive for hijacked accounts to promote scams [2]. While the measure targets social‑media‑based scams, it reflects broader industry concern over crypto‑related phishing attacks that exploit trust in familiar platforms [2].

## What to watch
- Monitor for new GitHub repositories that mention “CLAW” or OpenClaw airdrops.  
- Watch for any traffic to the domain token‑claw.xyz or the C2 host watery‑compost.today.  
- Track X’s auto‑lock rollout timeline and any subsequent changes in crypto‑related posting activity.

The OpenClaw fake‑token scheme shows how attackers can blend social engineering with code‑level obfuscation to steal crypto, highlighting the need for developers to verify any wallet‑connect prompts and for platforms to tighten controls on first‑time crypto mentions.

## Sources
1. CSOonline — [GitHub phishers use fake OpenClaw tokens to drain crypto wallets](https://www.csoonline.com/article/4150456/github-phishers-use-fake-openclaw-tokens-to-drain-crypto-wallets.html)
2. CoinDesk — [Elon Musk's X to deploy scam kill switch by auto-locking first-time crypto mentioners](https://www.coindesk.com/web3/2026/04/02/elon-musk-s-x-to-deploy-scam-kill-switch-by-auto-locking-first-time-crypto-mentioners)
3. TechRepublic — [Fake Gemini AI Chatbot Promotes ‘Google Coin’ in New Crypto Scam](https://www.techrepublic.com/article/news-fake-google-coin-scam-ai-chatbot-gemini/)

---
Cite as: TrendWatcher, "OpenClaw fake “CLAW” token phishing campaign targets GitHub developers", https://www.trendwatcher.in/article/bf633f0c-8122-47de-9e90-282c4f0f63cf
