logo

Fake OpenClaw Token Giveaway Targets GitHub Devs with Wallet-Draining Scam

ID: 1f5f7135-372b-5fcb-9f42-44d23778db7f

STIX ID: report--1f5f7135-372b-5fcb-9f42-44d23778db7f

Feed Name: HackRead

Threat Score
60/100

Date Published: 2026-03-25

Date Updated: 2026-04-22

Author: Deeba Ahmed

...
...

A targeted GitHub-based phishing campaign impersonates the OpenClaw project offering $5,000 in CLAW tokens to tagged developers; the malicious link (token-claw.xyz) is a cloned site that prompts wallet connections (MetaMask, Trust Wallet, OKX, Bybit) enabling attackers to drain funds. Researchers found a malicious JavaScript file ('eleven.js') with a 'nuke' function to erase browser evidence and identified a recipient wallet address; there are no confirmed victims yet, and recommended mitigations include revoking wallet permissions and blocking the domain.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.