OpenClaw Phishing Wave Targets Crypto Wallets

OpenClaw Phishing Wave Targets Crypto Wallets
March 19, 2026
~6 min read

The hype around OpenClaw has created exactly the kind of environment scammers love: a viral open-source project, a fast-growing developer community, and a flood of new users who are eager to try anything that looks early, exclusive, or official. In recent days, that excitement has spilled into a coordinated wave of phishing attacks aimed at crypto wallets, with attackers abusing the OpenClaw name to push fake airdrops, wallet-draining websites, and malicious installers. 

What makes this story more important than a routine phishing headline is the way the scam is being delivered. This is not only about random spam emails or fake token websites. Security researchers say attackers are using GitHub itself as a distribution channel, tagging developers in fake issue threads, impersonating OpenClaw branding, and luring victims with promises of free $CLAW tokens. Once users connect a wallet, the site can drain funds; in other cases, fake installers have delivered infostealer malware capable of stealing browser data, credentials, and crypto wallet information. 

Why OpenClaw became such an attractive lure

OpenClaw’s popularity helps explain why attackers moved so fast. Threat-intelligence reporting says the open-source AI agent project went viral in early 2026, drawing enormous developer attention and rapid growth on GitHub. That kind of visibility gives criminals a ready-made audience: technical users who already trust open-source platforms and are used to clicking into repositories, documentation, and community discussions. 

Malwarebytes described OpenClaw as a self-hosted AI agent with broad permissions and heavy interest from developers, which made it especially attractive for impersonation attacks. In other words, the brand had two features scammers value most: credibility and momentum. When a project is suddenly everywhere, fake versions can blend in more easily because users expect to see new pages, new forks, and new community activity popping up all the time. 

That dynamic is common across crypto and Web3. MetaMask’s February 2026 security report, citing Scam Sniffer, said signature-phishing attacks jumped 207% in January and drained $6.27 million from 4,700 wallets, showing how quickly scammers adapt when new narratives appear. OpenClaw just gave them a fresh one. 

How the phishing campaign works

The current OpenClaw-themed wallet attack appears to follow a fairly simple but effective pattern.

According to a GitHub security issue filed on the official OpenClaw repository on March 18, scammers created a fake repository and discussion thread that claimed to be distributing 5,000 $CLAW tokens to selected GitHub developers. The post listed dozens of usernames, used official-sounding language, and sent users to an external link where they were told to connect their wallets and join a whitelist for the supposed token distribution. The issue flagged several red flags, including the newly created repository, zero project association, and the external wallet-connection page. 

OX Security, which analyzed the campaign the same day, said the attackers created fake GitHub accounts, opened issue threads in attacker-controlled repositories, and tagged developers directly to maximize credibility and reach. The linked website was described as an almost identical clone of the real OpenClaw site, except for one crucial addition: a “Connect your wallet” prompt intended to start the theft process. OX said the phishing page supported multiple major wallets, including WalletConnect, MetaMask, Trust Wallet, OKX Wallet, and Bybit Wallet. 

That detail matters because it shows the attack was not built for one narrow user segment. It was designed to catch a broad range of crypto users, especially developers who might assume a token claim page is legitimate if it appears connected to an AI project they already know.

The recent wallet-drainer campaign is only the latest example. Earlier in March, Malwarebytes warned about fake OpenClaw installers appearing in GitHub repositories and even surfacing in Bing search results. According to that report, attackers used bogus installer repos to deliver Vidar, a known information stealer, and in some cases GhostSocks, which can turn the victim’s machine into a proxy node. Malwarebytes noted that Vidar can steal browser credentials, crypto wallets, and application data, making the threat much broader than a one-time token scam. 

That means the OpenClaw hype cycle has already produced at least two major attack patterns. One is the classic Web3 phishing model: promise tokens, get the victim to connect a wallet, then drain funds or abuse approvals. The other is a malware-delivery model: disguise malicious software as an OpenClaw installer and steal credentials and wallet data from the system itself. 

For crypto users, that overlap is especially dangerous. Many people still think wallet theft only happens when they reveal a seed phrase. In reality, malware, signature phishing, and malicious approval requests are often enough to compromise funds without ever asking for a recovery phrase directly. MetaMask’s report specifically warned that signature phishing tricks users into signing what looks like a harmless off-chain message but can authorize unlimited token or NFT transfers. 

Why developers are the real target

One of the more interesting parts of this campaign is the audience selection. OX Security said the attackers may be using GitHub stars and other visible signals to identify people already connected to OpenClaw-related repositories. That makes the scam feel more personal and more convincing than generic spam. 

Developers are a high-value target for three reasons. First, many of them are active in crypto and Web3, so wallet connection prompts are not automatically suspicious. Second, they are comfortable with GitHub, package managers, and test builds, which lowers their skepticism around new repos and downloads. Third, they often have access to far more than a typical retail wallet user: SSH keys, browser secrets, cloud credentials, API tokens, and private repos. Malwarebytes explicitly noted that the fake installer campaign could steal browser credentials and wallet data, not just crypto balances. 

That makes the attack more than a crypto story. It is also a software supply-chain and identity-compromise story.

What users should do now

The most practical takeaway is blunt: there is no legitimate reason to connect a wallet to claim an “OpenClaw allocation” from a random GitHub issue or cloned website. The official GitHub warning described the current “$CLAW” giveaway as phishing, and OX Security advised users to treat GitHub issues promoting token giveaways or airdrops as suspicious, especially when they come from unknown accounts. 

A few habits matter more than ever:

  • Do not trust GitHub notifications just because they come through GitHub’s infrastructure. The platform can still be used to amplify attacker-controlled content. 
  • Do not download OpenClaw installers from random GitHub repos or search-engine results. Malwarebytes said fake installer repositories were used to deliver infostealer malware instead of the real software. 
  • Do not connect a wallet to an unfamiliar page just because it looks polished or uses real project branding. OX Security found that the phishing site cloned the real OpenClaw appearance closely enough to fool users at a glance. 

And if you already interacted with a suspicious OpenClaw-themed site, review recent wallet connections and revoke approvals where possible. OX Security specifically recommended that step for users who may have touched the campaign. 

The bigger lesson behind the OpenClaw scam

The OpenClaw phishing wave is really a lesson in how fast online hype turns into attack surface. A project does not need to launch a token for scammers to invent one. It does not need to endorse crypto for criminals to use its brand in wallet-drainer campaigns. Once a name becomes recognizable, it becomes exploitable. 

That is why this story matters beyond OpenClaw itself. The next viral AI project, dev tool, or open-source assistant will likely face the same problem. In crypto, attackers do not wait for legitimacy. They front-run attention. And when wallets, developer tools, and social trust all overlap in the same ecosystem, that combination can get expensive very quickly. 

Follow us:

Coinxes.io

Twitter/X

Telegram

0.0
(0 ratings)
Click on a star to rate it

You send:

You send:

Network

Network

Floating rate

You receive:

You receive:

Network

Network

This service is not available to persons located in, resident in, incorporated in, established in, or acting from the EU/EEA.

Reliable service for exchanging cryptocurrencies 24/7

CoinXes is a convenient and secure platform for instant cryptocurrency conversion. We offer up-to-date rates, low fees and transparent exchange conditions. Support works 24/7.