Cybercriminals Exploit Openclaw Popularity in Sophisticated Github Phishing Campaign
Cryptocurrency developers are being targeted by a deceptive phishing campaign masquerading as Openclaw, a platform favored by open-source contributors. Cybersecurity firm OX Security warns that threat actors are impersonating the Openclaw ecosystem through fake Github accounts, specifically targeting active open-source developers.
The attackers lure victims by creating 'issue' threads on Github, tagging users with false promises of $5,000 worth of CLAW tokens. These messages direct targets to a counterfeit website mimicking openclaw.ai, where users are prompted to connect their cryptocurrency wallets. Once connected, malicious transactions drain their assets.
Researchers Moshe Siman Tov Bustan and Nir Zadok of OX Security confirmed the campaign's technical sophistication, emphasizing its focus on social engineering rather than code vulnerabilities. The industry-wide alert underscores growing risks to crypto developers engaged in collaborative platforms.