The post OpenClaw Developers Targeted in Crypto-Wallet Phishing Attack appeared on BitcoinEthereumNews.com. Attackers target OpenClaw developers via GitHub issuesThe post OpenClaw Developers Targeted in Crypto-Wallet Phishing Attack appeared on BitcoinEthereumNews.com. Attackers target OpenClaw developers via GitHub issues

OpenClaw Developers Targeted in Crypto-Wallet Phishing Attack

2026/03/20 02:43
Okuma süresi: 3 dk
Bu içerikle ilgili geri bildirim veya endişeleriniz için lütfen [email protected] üzerinden bizimle iletişime geçin.
  • Attackers target OpenClaw developers via GitHub issues and phishing emails. 
  • Malicious site clones the official interface and triggers wallet connection to execute fund draining.
  • Obfuscated malware tracks wallet data and sends it to a remote server before executing the drain.

A new phishing campaign is targeting developers linked to the OpenClaw project, using fake token airdrops to trick users into connecting crypto wallets. The attack spreads through GitHub and cloned websites, with the goal of draining funds once access is granted.

Security firm OX Security identified the campaign, noting that attackers are actively impersonating the OpenClaw ecosystem to reach developers directly.

GitHub Used As Primary Attack Vector

The attackers are not relying on random spam but are targeting developers where they are most active. Fake GitHub accounts are created, and issue threads are opened in attacker-controlled repositories.

Dozens of developers are tagged in each post to maximize reach. The message is simple: recipients have been selected to receive $5,000 worth of CLAW tokens.

The targeting appears deliberate as attackers may be scraping users who interacted with OpenClaw-related repositories, making the messages look relevant and credible.

At the same time, phishing emails are being sent through GitHub notification systems. These emails mirror the same pitch and use names like “ClawFunding” and “ClawReward” to appear legitimate.

Fake Site Clones OpenClaw Interface

The attackers redirected users through links, including Google link shorteners, to a phishing domain that closely mimics the official OpenClaw site. The interface looks identical, except for one key addition: a wallet connection prompt. Once the wallet is connected, the attack begins.

The phishing page supports multiple wallets, including MetaMask, Trust Wallet, OKX Wallet, Bybit Wallet, and WalletConnect, increasing the chances of user interaction.

The core of the attack sits inside an obfuscated JavaScript file. This code handles wallet interaction, tracks user actions, and sends data to a remote server.

Captured data includes wallet addresses, transaction values, and user identifiers. The system uses command signals such as transaction prompts and approval tracking to monitor behavior in real time.

A command-and-control server is used to receive the data and execute the drain. A dedicated wallet address has been identified as the main destination for stolen funds.

The malware also includes a cleanup function that removes traces from the browser after execution, making detection and forensic analysis harder.

At this stage, there are no confirmed reports of funds lost. However, the structure of the attack is fully operational. 

The campaign was launched using newly created GitHub accounts, which were deleted shortly after activity began. This suggests a short lifecycle strategy designed to avoid detection.

Related: Solana and Base Compete as AI Agents Go Fully Onchain With OpenClaw

Disclaimer: The information presented in this article is for informational and educational purposes only. The article does not constitute financial advice or advice of any kind. Coin Edition is not responsible for any losses incurred as a result of the utilization of content, products, or services mentioned. Readers are advised to exercise caution before taking any action related to the company.

Source: https://coinedition.com/openclaw-developers-targeted-in-crypto-wallet-phishing-attack/

Piyasa Fırsatı
Folks Finance Logosu
Folks Finance Fiyatı(FOLKS)
$0.964
$0.964$0.964
-0.51%
USD
Folks Finance (FOLKS) Canlı Fiyat Grafiği
Sorumluluk Reddi: Bu sitede yeniden yayınlanan makaleler, halka açık platformlardan alınmıştır ve yalnızca bilgilendirme amaçlıdır. MEXC'nin görüşlerini yansıtmayabilir. Tüm hakları telif sahiplerine aittir. Herhangi bir içeriğin üçüncü taraf haklarını ihlal ettiğini düşünüyorsanız, kaldırılması için lütfen [email protected] ile iletişime geçin. MEXC, içeriğin doğruluğu, eksiksizliği veya güncelliği konusunda hiçbir garanti vermez ve sağlanan bilgilere dayalı olarak alınan herhangi bir eylemden sorumlu değildir. İçerik, finansal, yasal veya diğer profesyonel tavsiye niteliğinde değildir ve MEXC tarafından bir tavsiye veya onay olarak değerlendirilmemelidir.

Ayrıca Şunları da Beğenebilirsiniz

The Channel Factories We’ve Been Waiting For

The Channel Factories We’ve Been Waiting For

The post The Channel Factories We’ve Been Waiting For appeared on BitcoinEthereumNews.com. Visions of future technology are often prescient about the broad strokes while flubbing the details. The tablets in “2001: A Space Odyssey” do indeed look like iPads, but you never see the astronauts paying for subscriptions or wasting hours on Candy Crush.  Channel factories are one vision that arose early in the history of the Lightning Network to address some challenges that Lightning has faced from the beginning. Despite having grown to become Bitcoin’s most successful layer-2 scaling solution, with instant and low-fee payments, Lightning’s scale is limited by its reliance on payment channels. Although Lightning shifts most transactions off-chain, each payment channel still requires an on-chain transaction to open and (usually) another to close. As adoption grows, pressure on the blockchain grows with it. The need for a more scalable approach to managing channels is clear. Channel factories were supposed to meet this need, but where are they? In 2025, subnetworks are emerging that revive the impetus of channel factories with some new details that vastly increase their potential. They are natively interoperable with Lightning and achieve greater scale by allowing a group of participants to open a shared multisig UTXO and create multiple bilateral channels, which reduces the number of on-chain transactions and improves capital efficiency. Achieving greater scale by reducing complexity, Ark and Spark perform the same function as traditional channel factories with new designs and additional capabilities based on shared UTXOs.  Channel Factories 101 Channel factories have been around since the inception of Lightning. A factory is a multiparty contract where multiple users (not just two, as in a Dryja-Poon channel) cooperatively lock funds in a single multisig UTXO. They can open, close and update channels off-chain without updating the blockchain for each operation. Only when participants leave or the factory dissolves is an on-chain transaction…
Paylaş
BitcoinEthereumNews2025/09/18 00:09
Gold continues to hit new highs. How to invest in gold in the crypto market?

Gold continues to hit new highs. How to invest in gold in the crypto market?

As Bitcoin encounters a "value winter", real-world gold is recasting the iron curtain of value on the blockchain.
Paylaş
PANews2025/04/14 17:12
XRP Multi-Year Accumulation Signals Potential 1000% Breakout

XRP Multi-Year Accumulation Signals Potential 1000% Breakout

The post XRP Multi-Year Accumulation Signals Potential 1000% Breakout appeared on BitcoinEthereumNews.com. XRP Builds Multi-Year Base as Whales Accumulate and Volume
Paylaş
BitcoinEthereumNews2026/03/21 00:04