DriversRecommendedOutdated drivers can make a good PC feel brokenScan driver issues before chasing fixes manually.Scan NowOctober DealsAmazon USOctober deal check: compare before you payAmazon US: current deals, useful picks and tech finds.Check DealsSlow PC?RecommendedPC slow today? Run a repair scan before it gets worseResolve common Windows issues and optimize system performance.Scan Now×
Skip to content
The Finance Base
The Money Desk · Blog
Re:

GitHub Phishers Used a Fake OpenClaw Airdrop to Target Crypto Wallets

A fake $5,000 CLAW airdrop promoted through GitHub led to a counterfeit OpenClaw site with wallet-stealing code. Here’s what the report established and what to do if you interacted with it.
From TheFinanceBase Team5 min to read
Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

In March 2026, attackers used GitHub issues, discussions and user mentions to promote a supposed $5,000 allocation of “CLAW” tokens. The links led to a counterfeit OpenClaw site that asked visitors to connect a crypto wallet. Researchers found obfuscated code designed to support wallet theft, but the initial report did not identify confirmed victims or losses. The dollar figure was the attackers’ claim, not a verified value.

How the GitHub campaign worked

According to CSO Online’s March 26, 2026 report, citing OX Security, the campaign used GitHub as a way to reach people interested in OpenClaw. Attackers used accounts and repositories to post messages, open issues or discussions, and tag users. The messages claimed recipients had been selected for a limited-time CLAW token allocation.

  1. A GitHub message or mention drew a developer or OpenClaw user’s attention to the supposed giveaway.
  2. The link led to a site at token-claw[.]xyz, which imitated OpenClaw’s website.
  3. The imitation added a prompt to connect a crypto wallet.
  4. Obfuscated JavaScript reportedly attempted to collect wallet and transaction information and facilitate unauthorized transfers.

The reported campaign used GitHub for delivery and social engineering; that does not mean GitHub itself was the mechanism that moved funds. A broader pattern of attackers using trusted developer platforms to distribute phishing material is described by Proofpoint.

Was the CLAW airdrop official?

The reported lure was an unauthorized or fake crypto-token offer, not a software login credential. CSO reported that OpenClaw developer Peter Steinberger had said the project would never issue tokens and that claims otherwise were scams. OpenClaw’s own project lore also records fake developer profiles and unauthorized token activity. Those earlier or parallel incidents provide context, but they are distinct from this specific GitHub campaign.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
#1 Best Overall
Sale
Ledger Nano X - Classic Crypto Wallet with Bluetooth
  • Effortlessly build your crypto portfolio via the all in one Ledger Wallet app: buy, sell, send, receive, swap, stake and more across popular blockchains. 15,000+ coins & tokens in a single dashboard. Keep a close eye on the market. Compare service providers. Track performance. Get timely alerts. Build your portfolio with confidence.
  • Effortlessly build your crypto portfolio via the all in one Ledger Wallet app: buy, sell, send, receive, swap, stake and more across popular blockchains. 15,000+ coins & tokens in a single dashboard. Keep a close eye on the market. Compare service providers. Track performance. Get timely alerts. Build your portfolio with confidence.
  • Enjoy Bluetooth connectivity, iOS access, and hours of battery use with this mobile-first, secure backup signer. Freedom you can depend on.
  • Genuine Check: confirm your signer is authentic during setup with the Ledger Wallet app.
  • Protect your signer: keep it in mint condition at all times with a bespoke Pod or Case to avoid scratches and everyday wear and tear.

The word “token” can mean different things here. OpenClaw documentation also refers to legitimate software credentials, such as API, gateway and ClawHub authentication tokens. Those are not cryptocurrency or airdrop assets; see the project’s ClawHub authentication documentation and environment-variable reference.

Do not treat a familiar logo, GitHub mention, token ticker, or polished page as proof that an offer is official. Verify announcements through the project’s official channels and check the domain character by character. Navigate using a saved bookmark or an address you enter yourself rather than a link in an unsolicited message. HTTPS protects a connection to a site; it does not establish that the site belongs to OpenClaw.

Rank #2
TANGEM Crypto Wallet Pack of 2 – Trusted Cold Storage Hardware Wallet
  • Proven security at scale: Over 9 years and millions of cards issued with no known remote hacks, while military‑grade EAL6+ security keeps your private keys locked inside the chip. Your cryptocurrencies stay strongly protected from online attackers.
  • Tap once to manage your entire crypto wallet across 90 blockchains - no USB cables or Bluetooth, no batteries, no setup. Access 14,100+ coins & tokens, DeFi, NFTs, and staking instantly from your phone
  • Smart backup: Use your second Tangem Wallet as your Backup keys with end‑to‑end encryption; no more papers, pictures. If one card is lost, the remaining can still restore full access, with an optional seed phrase available for advanced users.
  • Engineered to last up to 25 years: Waterproof (IP69K), shockproof and tested for extreme temperatures from −25°C to 50°C. A durable cold wallet with long‑term protection and independently audited security.
  • Trusted by 6 million users worldwide - buy, sell, swap, stake, and spend cryptocurrency directly. The secure offline storage wallet designed for how people actually use crypto wallets

What researchers reported about the wallet-draining code

CSO’s account of OX Security’s analysis described obfuscated code in a JavaScript file named eleven.js. The code reportedly collected wallet addresses, transaction values and names, and communicated with watery-compost[.]today. Reported command names included PromtTx, Approved and Declined. Researchers also described a “nuke” function intended to remove wallet-stealing information from browser local storage and hinder investigation.

The report named WalletConnect, MetaMask, Trust Wallet, OKX Wallet and Bybit Wallet as supported or targeted wallet interfaces. That does not mean those providers were breached. The reported risk was that a user could be deceived into connecting a wallet and authorizing a harmful request.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Rank #3
Ledger Nano S Plus - Classic Crypto Wallet
  • All your digital assets in one place. You can manage thousands of crypto including Bitcoin, Ethereum, Solana, Tether and more.
  • Defend your identity against hackers: secure your online accounts with passwordless, hardware backed, 2FA logins for all your favorite apps and websites.
  • Connectivity: USB-C cable connection only. No Bluetooth.Compatible with the Ledger Wallet crypto app, both desktop (Windows, macOS, Linux) and mobile (Android only). Not compatible with iOS.
  • Protect your digital assets with the industry's best security: keep your private keys offline in your private signer, battle-tested by the Donjon's white hat hackers, CC EAL 6+ certified Secure Element, constantly updated Ledger OS.
  • Effortlessly build your crypto portfolio via the all in one Ledger Wallet app: buy, sell, send, receive, swap, stake and more across popular blockchains. 15,000+ coins & tokens in a single dashboard. Keep a close eye on the market. Compare service providers. Track performance. Get timely alerts. Build your portfolio with confidence.

The analysis also identified this recipient address in the code: 0x6981E9EA7023a8407E4B08ad97f186A5CBDaFCf5. Security teams can treat the address and defanged domains as indicators to investigate, not as proof by themselves that a particular person lost funds. The report said multiple accounts were created and deleted within hours; that short-lived activity does not establish that every account or domain was taken down or is now inactive.

What “draining a wallet” means—and what it does not

A wallet interaction can expose different levels of control. Connecting a wallet may reveal its public address or establish a website-wallet session; that alone is not the same as authorizing a transfer. Signing a message, approving token spending, and signing an on-chain transaction are also different actions, and their risks depend on exactly what the wallet request says. An approval can let a spender move specified tokens, sometimes up to an unlimited amount; a transaction can directly authorize an on-chain action.

Rank #4
Trezor Safe 5 Crypto Hardware Wallet with Color Touchscreen
  • UNPARALLELED SECURITY: Protect your assets with Trezor Safe 5's NDA-free EAL 6+ Secure Element, offering robust defense and complete transparency.
  • EFFORTLESS NAVIGATION: Experience seamless crypto management with the vibrant color touchscreen, designed for intuitive and user-friendly interactions.
  • ENHANCED USER EXPERIENCE: Enjoy tactile confirmation with Trezor Touch Haptic Engine, making each interaction precise and engaging.
  • SUPPORTS 1000s OF COINS & TOKENS: Securely handle thousands of assets, including Bitcoin, Ethereum, and more, all in one wallet.
  • EASY ASSET MANAGEMENT: Monitor and transact seamlessly with Trezor Suite, our user-friendly desktop and mobile app

The cited report describes wallet-stealing functionality, but does not establish precisely which request every visitor saw, that a seed phrase was collected, or that funds were successfully transferred. Merely visiting the page or having a public wallet address exposed does not automatically empty a wallet. Conversely, a hardware wallet does not make a malicious transaction safe if its owner approves it.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

What to do if you encountered the message or site

Choose the response based on what you actually did. Disconnecting a site, revoking an allowance and moving funds address different risks; revoking an allowance does not reverse a completed transfer.

What’s actually slowing this PC down?

Pick the symptom - the matching free tool is one click away.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Best Value
Trezor Safe 7 Crypto Hardware Wallet with Bluetooth for Android/iOS/Desktop
  • Dual-chip architecture for maximum protection: The next-gen, fully auditable TROPIC01 chip works alongside a certified EAL6+ Secure Element—completely NDA-free—to deliver radically transparent, industry-leading defense against physical attacks.
  • Quantum-ready security: Get protection against future threats with the first-ever hardware wallet designed with quantum-ready architecture.
  • See every detail with confidence: Our largest high-resolution color touchscreen makes it easy to navigate your assets, review transactions and manage your coins with clarity.
  • Wireless freedom with encrypted Bluetooth control: Manage, buy, swap and stake securely using Trezor Suite on desktop or mobile. Qi2-compatible wireless charging keeps your Trezor powered up. No cables required—security meets convenience.
  • Works seamlessly with Android, iOS and desktop: Connect wirelessly or via USB-C to your phone or computer. Manage your crypto anywhere with our companion Trezor Suite app.
Your action Risk and response
Read the GitHub message but did not click Do not follow the link. Report the account, issue, discussion or repository to GitHub and delete the notification.
Clicked the link but did not connect or sign Close the page. Do not download files or install extensions it requested. Check browser downloads and extensions, and run your usual device-security checks. A click alone does not show that funds were exposed.
Connected a wallet, but did not approve or sign anything Disconnect the site in the wallet, review recent wallet activity and watch for unexpected requests or transactions. A connection and an approval are not the same thing.
Approved token spending Use a trusted wallet interface or reputable approval-review tool to inspect and revoke suspicious allowances. Review each network you used: token approvals are generally chain-specific. Revocation cannot recover assets already transferred.
Signed a transaction you do not recognize Inspect the transaction and move remaining assets to a fresh wallet if you believe the transaction exposed broader control. Preserve relevant details and seek help through a trusted wallet or security provider, not unsolicited recovery offers.
Entered a seed phrase or private key Treat that wallet as compromised. Create a new wallet with a trusted application or hardware wallet, transfer remaining assets if possible, and never reuse the exposed secret. A wallet connection or allowance revocation is not an adequate substitute.

If you also entered GitHub credentials or installed a browser extension, handle that as a separate account or device-security incident: change the affected credentials, review active sessions and OAuth applications, and investigate the extension. Do not trust anyone who contacts you through GitHub or social media promising to recover funds.

What organizations and project administrators can do

  • Block the reported domains, token-claw[.]xyz and watery-compost[.]today, in appropriate security controls, and preserve relevant DNS, proxy and browser telemetry.
  • Search GitHub notifications and available audit records for messages containing terms such as “CLAW,” “allocation,” “airdrop” and “OpenClaw.” Report abusive accounts, issues, discussions and repositories to GitHub.
  • Train developers to treat issues, pull requests, discussions and mentions as possible phishing delivery channels, including when a message appears in a familiar project community.
  • Keep valuable holdings separate from wallets used for experiments or routine development. Require transaction simulation or human review for high-value actions, and prohibit connecting production wallets to unapproved websites.
  • If investigating the page, preserve its HTML, JavaScript, screenshots, timestamps and headers without visiting it from a production environment or connecting a wallet.

What the report establishes about impact

The March 26, 2026 report attributed the technical findings to OX Security and said its analysis had not identified affected users at the time. It did not establish a victim count, total losses or successful transfers. That makes “wallet drainer” a description of the campaign’s reported capability and objective—not confirmation that the reported campaign had already drained victims’ funds. Domain and account status can change, so the publication-time report should not be read as a current status check.

Quick Recap

SaleBestseller No. 1
Ledger Nano X - Classic Crypto Wallet with Bluetooth
Ledger Nano X - Classic Crypto Wallet with Bluetooth
Genuine Check: confirm your signer is authentic during setup with the Ledger Wallet app.
$79.00

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

Leave a Reply

Your email address will not be published. Required fields are marked *

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

More post from the Money Desk

  1. The Money DeskBlogTheFinanceBase09 OCT 267 minMortgage Escrow FAQs: Taxes, Insurance, Shortages, and Refunds
  2. The Money DeskBlogTheFinanceBase09 OCT 265 minHow Mortgage Escrow Accounts Work and What Homeowners Pay For
  3. The Money DeskBlogTheFinanceBase09 OCT 265 minHow to Read a Stock Chart, Volume and Market-Cap Data
Recommended PC Tool
Recommended PC Tool
Crashes, No Sound, or Screen Glitches?Free driver scan
PC Slower Than It Used to Be?Free scan - under a minute

Two free Windows tools

One Free Minute Could Fix That PC

Before you go - each of these free tools takes about a minute and tackles what quietly slows a Windows PC down.

Special offer. View Outbyte info, uninstall instructions, EULA, and Privacy Policy.