GitHub phishing activities targeting OpenClaw developers exploit fake airdrops to steal cryptocurrency wallet funds
According to market news, the security platform OX Security has disclosed that the developers of the AI agent project OpenClaw are becoming targets of cryptocurrency phishing activities.
Attackers create fake GitHub accounts, initiate topics in repositories controlled by them, and @ dozens of developers, claiming they have won a $5000 CLAW token reward, leading them to a clone website that is almost identical to openclaw.ai. This phishing site includes a "Connect Wallet" button, aimed at stealing the assets of connected wallets. Malicious code is hidden in deeply obfuscated JavaScript files, featuring a "nuke" function that clears browser local storage data to hinder forensic analysis, and encodes information such as wallet addresses and transaction values to send back to the C2 server. Researchers identified a suspected cryptocurrency wallet address used to receive stolen funds. The related accounts were created last week and deleted within hours, with no confirmed victims at this time. OpenClaw has become a target for scammers due to its high visibility, and its Discord community has previously encountered a large amount of cryptocurrency spam. Earlier reports indicated that OpenClaw's founder warned to be cautious of cryptocurrency scam emails sent in the name of OpenClaw.
You may also like

Hawkish Signal in Tightening Mode | Rewire News Brief

x402 and AI Agents: An Emerging Data Economy

Illustration: Despite 6 consecutive interest rate cuts, the interest rate outlook is trending upward

SpaceX is playing hardball with Nasdaq at the negotiation table, while Hyperliquid has already flipped the table.

Bloomberg: Once Blacklisted by the U.S., Bitmain Finds a New Powerful Backer

Three Charts Explain Why S&P Authorized Its Brand to trade.xyz

After the SEC and CFTC Join Forces, What Can the Crypto Market Look Forward To?

Revisiting RWA: Nearly 50,000 people's first on-chain transaction was not Bitcoin, but stock indices and crude oil

Morning Report | Kraken freezes IPO plans due to difficult market conditions; Polymarket acquires DeFi infrastructure Brahma; World launches AgentKit integrated with Coinbase

Bitmain, mired in controversy, has found its strongest backing in the United States

Full text of the Federal Reserve's decision: Maintain interest rates unchanged and expect one rate cut within the year, with Governor Mulan casting a dissenting vote

Guarding billions in assets, yet unable to sustain itself: Tally bids a dignified farewell after five years

SEC’s Stance on Crypto Assets: Most Not Considered Securities
Key Takeaways: The SEC’s new interpretation categorizes most crypto assets as non-securities under federal law. This move aims…

South Korea’s New Crypto Seizure Guidelines After Asset Mismanagement Incidents
Key Takeaways: South Korea’s National Police Agency (KNPA) has drafted guidelines for crypto seizure, with a focus on…

Institutional Confidence in Crypto’s 2026 Growth Trajectory
Key Takeaways: A significant 73% of institutional investors plan to increase their crypto holdings by 2026. Exchange-traded products…

Ethereum Reduces Bridge Times by 98% with Fast Confirmation Rule
Key Takeaways: Ethereum introduces the Fast Confirmation Rule (FCR) aiming to cut bridge times from L1 to L2…

Crypto Firms Advocate DeFi Education in US Colleges
Key Takeaways: Twenty-one crypto organizations have called on US colleges to integrate decentralized finance (DeFi) into their curricula…

RedotPay Reorganizes Amidst Funding Tries and IPO Goals
Key Takeaways: RedotPay is facing leadership changes and concerns over its connections with mainland China while eyeing a…