OpenClaw Developers Targeted in GitHub Phishing Campaign
Analysis based on 11 articles · First reported Mar 19, 2026 · Last updated Mar 21, 2026
The phishing campaign targeting OpenClaw developers could lead to a decrease in trust in open-source AI projects and cryptocurrency platforms, potentially affecting the broader crypto market sentiment. Cybersecurity firms like OX Security may see increased demand for their services as awareness of such threats grows.
Malicious cyber actors are exploiting the popularity of the open-source AI agent project OpenClaw with a phishing campaign. They create fake Microsoft===GitHub accounts and issue threads, tagging developers with fraudulent offers of $5,000 in 'CLAW' tokens. Victims are directed to a malicious website, an almost identical clone of OpenClaw's official site, featuring a 'Connect your wallet' button designed to initiate wallet theft. Cybersecurity firm OX Security reported on this campaign, identifying malicious domains and a 'nuke' function in the malware to erase forensic data. OpenClaw creator Peter Steinberger has warned users about these scams and enforced a strict anti-crypto policy due to previous related incidents, including a fake CLAWD token scam on Solana. No confirmed victims have been reported yet, but the wallet-draining infrastructure is operational.
Set up alerts, explore entity relationships, search across thousands of events, and build custom intelligence feeds.
Open Dashboard