Charts
DataOn-chain
VIP
Market Cap
API
Rankings
CoinOSNew
CoinClaw🦞
Language
  • 简体中文
  • 繁体中文
  • English
Leader in global market data applications, committed to providing valuable information more efficiently.

Features

  • Real-time Data
  • Special Features
  • AI Grid

Services

  • News
  • Open Data(API)
  • Institutional Services

Downloads

  • Desktop
  • Android
  • iOS

Contact Us

  • Chat Room
  • Business Email
  • Official Email
  • Official Verification

Join Community

  • Telegram
  • Twitter
  • Discord

© Copyright 2013-2026. All rights reserved.

简体繁體English
|Legacy

OpenClaw Developers Lured in GitHub Phishing Campaign Targeting Crypto Wallets

CN
Decrypt
Follow
4 hours ago
AI summarizes in 5 seconds.

OpenClaw’s viral rise has drawn an ugly new side effect: crypto scammers are now using the AI agent project’s name to target developers in a phishing campaign aimed at draining their wallets. 


Security platform OX Security published a report on Wednesday detailing an active phishing campaign targeting OpenClaw in which threat actors create fake GitHub accounts, open issue threads in attacker-controlled repositories, and tag dozens of developers. 


The scam claims recipients have won $5,000 worth of $CLAW tokens and directs them to a site nearly identical to openclaw.ai, with one addition: a "Connect your wallet" button designed to initiate wallet theft, according to the report.





The phishing campaign surfaced weeks after OpenAI CEO Sam Altman announced OpenClaw creator Peter Steinberger would lead its push into personal AI agents, with OpenClaw transitioning to a foundation-run open-source project. 


That mainstream profile and the framework's association with one of the most prominent names in AI make its developer community an increasingly attractive target.


Threat actors post GitHub issues telling developers, “Appreciate your contributions on GitHub. We analyzed profiles and chose developers to get OpenClaw allocation.” It then directs victims to a fake site supporting several major crypto wallets.


OX Security assessed that the attackers may be using GitHub's star feature to identify users who have starred OpenClaw-related repositories, making the lure appear more targeted and credible.


The platform’s analysis found the wallet-stealing code buried inside a heavily obfuscated JavaScript file called "eleven.js."


After deobfuscating the malware, researchers identified a built-in "nuke" function that wipes all wallet-stealing data from the browser's local storage to frustrate forensic analysis. 


The malware tracks user actions via commands such as PromptTx, Approved, and Declined, relaying encoded data, including wallet addresses, transaction values, and names, back to a C2 server.


Researchers identified one crypto wallet address they believe belongs to the threat actor, 0x6981E9EA7023a8407E4B08ad97f186A5CBDaFCf5, used to receive stolen funds. 


The accounts were created last week and deleted within hours of launch, with no confirmed victims so far, according to OX Security.


Decrypt has reached out to Peter Steinberger and OX Security for comments.


OpenClaw's crypto magnet problem


OpenClaw, a self-hosted AI agent framework that lets users run persistent bots connected to messaging apps, email, calendars, and shell commands, hit 323,000 GitHub stars following its acquisition by OpenAI last month. 


That visibility quickly attracted bad actors, with OpenClaw creator Peter Steinberger saying crypto spam flooded OpenClaw’s Discord almost “every half hour,” forcing bans and ultimately a blanket prohibition after what he described to Decrypt as “nonstop coin promotion.”


Unlike chat-based AI tools, OpenClaw agents persist, wake on a schedule, store memory locally, and execute multi-step tasks autonomously.


OX Security recommends blocking token-claw[.]xyz and watery-compost[.]today across all environments, avoiding connecting crypto wallets to newly surfaced or unverified sites, and treating any GitHub issue promoting token giveaways or airdrops as suspicious, particularly from unknown accounts. 


Users who recently connected a wallet should revoke approvals immediately, the platform warned. 


免责声明:本文章仅代表作者个人观点,不代表本平台的立场和观点。本文章仅供信息分享,不构成对任何人的任何投资建议。用户与作者之间的任何争议,与本平台无关。如网页中刊载的文章或图片涉及侵权,请提供相关的权利证明和身份证明发送邮件到support@aicoin.com,本平台相关工作人员将会进行核查。

躺赚BNB,超级AI管家
广告
|
|
APP
Windows
Mac
Share To

X

Telegram

Facebook

Reddit

CopyLink

|
|
APP
Windows
Mac
Share To

X

Telegram

Facebook

Reddit

CopyLink

Selected Articles by Decrypt

3 hours ago
Nasdaq Wins SEC Approval to Trade Tokenized Securities in Pilot Program
6 hours ago
Why Bitcoin Is Falling Despite $1.1 Billion in ETF Inflows
9 hours ago
Coalition Urges OpenAI to Scrap AI Ballot Measure Over Child Safety Concerns
View More

Table of Contents

|
|
APP
Windows
Mac
Share To

X

Telegram

Facebook

Reddit

CopyLink

Related Articles

avatar
avatarbitcoin.com
1 hour ago
Breez SDK Integrates Passkey Login to Eliminate Traditional Seed Phrase Barriers
avatar
avatarcoindesk
2 hours ago
Bitcoin OGs dump over $100 million in BTC after hawkish Fed dents rate cut hopes
avatar
avatarcoindesk
2 hours ago
Forget market hours: Leading ETP firm just opened 24/7 liquidity for tokenized stocks, gold and money market funds
avatar
avatarDecrypt
3 hours ago
Nasdaq Wins SEC Approval to Trade Tokenized Securities in Pilot Program
avatar
avatarbitcoin.com
3 hours ago
SBI VC Trade Launches Japan’s First Licensed USDC Lending Service
APP
Windows
Mac

X

Telegram

Facebook

Reddit

CopyLink