COINTURK NEWSCOINTURK NEWSCOINTURK NEWS
  • Crypto Tracker App
  • Bitcoin
  • Altcoin
  • Ethereum
  • Advertise
  • Contact
  • TURTURTUR
  • ESESES
Search
© 2024 COINTURK NEWS. All Rights Reserved.
Reading: Cybercriminals Target Crypto Developers with Fake Openclaw Campaign on Github
Share
Font ResizerAa
COINTURK NEWSCOINTURK NEWS
Font ResizerAa
Search
  • Crypto Tracker App
  • Bitcoin
  • Altcoin
  • Ethereum
  • Advertise
  • Contact
  • TURTURTUR
  • ESESES
Follow US
© 2025 >> COINTURK NEWS
Powered by LK SOFTWARE
COINTURK NEWS > Cryptocurrency Security > Cybercriminals Target Crypto Developers with Fake Openclaw Campaign on Github
Cryptocurrency Security

Cybercriminals Target Crypto Developers with Fake Openclaw Campaign on Github

In Brief

  • Attackers impersonate Openclaw to target crypto developers through fake Github accounts.

  • Phishing links drain assets after victims connect wallets to a counterfeit website.

  • Experts urge caution with token offers and warn of ongoing exploitation attempts.

Fatih Uçar
Fatih Uçar 4 weeks ago
Share
SHARE

A new phishing campaign is putting crypto developers at risk by exploiting the popularity of Openclaw, a platform favored by open-source contributors. Cybersecurity firm OX Security has sounded the alarm, warning that threat actors are impersonating the Openclaw ecosystem through fake Github accounts, directly targeting users who are active in open-source projects. The campaign’s focus on engaged developers—and its sophisticated mimicry—has raised concerns across the industry.

Contents
Phishing Attack Promises Fake Tokens to Lure TargetsWallet Connection Leaves User Assets VulnerableInfrastructure and Malicious Code Exposed

Phishing Attack Promises Fake Tokens to Lure Targets

Attackers operate by opening “issue” threads on Github repositories, tagging users and falsely claiming they have won $5,000 worth of a so-called CLAW token. The deceptive messages contain links directing victims to a counterfeit website designed to closely mirror the real openclaw.ai portal. When users are prompted on this fraudulent page to connect their cryptocurrency wallets and comply, a series of malicious transactions are unleashed.

Wallet Connection Leaves User Assets Vulnerable

Technical analysis conducted by OX Security researchers Moshe Siman Tov Bustan and Nir Zadok revealed that once developers connect their wallets as instructed, their assets can be swiftly drained. The campaign employs social engineering tactics designed to personalize the interaction, making it appear especially credible to those who have previously interacted with Openclaw-related repositories. This individualized targeting increases the likelihood of success for the attackers.

Infrastructure and Malicious Code Exposed

Digging deeper, technical experts uncovered a complex attack infrastructure. Victims are redirected to the token-claw[.]xyz domain, while a command-and-control server is set up at watery-compost[.]today to manage the campaign. Malicious JavaScript embedded in the site harvests sensitive data such as wallet addresses and transaction details and transmits them back to the attackers.

Researchers identified a cryptocurrency wallet address likely associated with the attacker. They also noted that the malicious code tracks user actions and wipes local storage, making it significantly harder for investigators to trace the operation.

Although there have been no confirmed victims thus far, reports suggest the phishing campaign remains active. Security experts strongly caution people not to connect their cryptocurrency wallets to unfamiliar websites and to be skeptical of unsolicited token offers on Github, no matter how enticing they seem.

Meanwhile, a separate report by Certik drew attention to “skill scanning” vulnerabilities within the Openclaw ecosystem. Analyzed sample applications showed that these flaws could bypass established security layers, making exploitation feasible, Certik explained in its report.

Openclaw has recently surged in popularity among developers for its AI-powered agent systems. As the community around such platforms rapidly grows, their increasing appeal also marks them as prime targets for sophisticated cyber attacks.

You can follow our news on Telegram, Facebook & Coinmarketcap & X
Disclaimer: The information contained in this article does not constitute investment advice. Investors should be aware that cryptocurrencies carry high volatility and therefore risk, and should conduct their own research.

You Might Also Like

AAVE plunges 10% after $200M Kelp DAO DeFi hack

Kelp DAO suffers $292M rsETH exploit, Aave freezes markets

Rhea Finance hit by $7.6M hack through fake token pools

Hyperbridge hack losses soar to $2.5 million after update

CowSwap hit by hack after BTC surge, COW drops to $0.21

Fatih Uçar 21 March, 2026 - 10:51 pm 21 March, 2026 - 10:51 pm
Share This Article
Facebook Twitter
Share
Previous Article Bitcoin Miners’ Position Index Hits Rare Low As Market Awaits Signals
Next Article Ethereum Holds Steady as Buyers Offset ETF Outflows and Market Volatility
Leave a comment

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

This site uses Akismet to reduce spam. Learn how your comment data is processed.

Stay Connected

8.1k Like
21.1k Follow
1.1k Follow

Latest News

Over $5.4 billion exits Aave after major DeFi hack
DeFi News Ethereum (ETH)
Solana dominance holds at 2% as long positions rise
Solana (SOL)
Bitcoin eyes $80,000 as upside signals and liquidity align
Bitcoin (BTC)
//

COINTURK was launched in March 2014 by a group of technology enthusiasts who believe that Bitcoin will be as important as the internet in the world of the future thanks to the amazing technology underlying it.

CRYPTOCURRENCY LIVE PRICES

  • Bitcoin (BTC) Live Price
  • Ethereum (ETH) Live Price
  • Ripple (XRP) Live Price
  • Solana (SOL) Live Price
  • Dogecoin (DOGE) Live Price
  • Cardano (ADA) Live Price
  • Chainlink (LINK) Live Price

OUR PARTNERS

  • COINMARKETCAP
  • COINGECKO
  • BITCOINHABER
  • BH NEWS
  • 21MILYON
  • NEWSLINKER

OUR COMPANY

  • About Us
  • Cookie Policy
  • Advertising
  • Contact
COINTURK NEWSCOINTURK NEWS
Follow US
COINTURK NEWS
Powered by LK SOFTWARE
Welcome Back!

Sign in to your account

Lost your password?