In March 2026, attackers used GitHub issues, discussions and user mentions to promote a supposed $5,000 allocation of “CLAW” tokens. The links led to a counterfeit OpenClaw site that asked visitors to connect a crypto wallet. Researchers found obfuscated code designed to support wallet theft, but the initial report did not identify confirmed victims or losses. The dollar figure was the attackers’ claim, not a verified value.
How the GitHub campaign worked
According to CSO Online’s March 26, 2026 report, citing OX Security, the campaign used GitHub as a way to reach people interested in OpenClaw. Attackers used accounts and repositories to post messages, open issues or discussions, and tag users. The messages claimed recipients had been selected for a limited-time CLAW token allocation.
- A GitHub message or mention drew a developer or OpenClaw user’s attention to the supposed giveaway.
- The link led to a site at
token-claw[.]xyz, which imitated OpenClaw’s website. - The imitation added a prompt to connect a crypto wallet.
- Obfuscated JavaScript reportedly attempted to collect wallet and transaction information and facilitate unauthorized transfers.
The reported campaign used GitHub for delivery and social engineering; that does not mean GitHub itself was the mechanism that moved funds. A broader pattern of attackers using trusted developer platforms to distribute phishing material is described by Proofpoint.
Was the CLAW airdrop official?
The reported lure was an unauthorized or fake crypto-token offer, not a software login credential. CSO reported that OpenClaw developer Peter Steinberger had said the project would never issue tokens and that claims otherwise were scams. OpenClaw’s own project lore also records fake developer profiles and unauthorized token activity. Those earlier or parallel incidents provide context, but they are distinct from this specific GitHub campaign.
Do these 3 things before closing this tab:
1Repair Windows errors before they cause bigger problems2Scan for outdated or missing drivers - takes under a minute3Clear out junk files and repair common Windows errors#1 Best Overall
- Effortlessly build your crypto portfolio via the all in one Ledger Wallet app: buy, sell, send, receive, swap, stake and more across popular blockchains. 15,000+ coins & tokens in a single dashboard. Keep a close eye on the market. Compare service providers. Track performance. Get timely alerts. Build your portfolio with confidence.
- Effortlessly build your crypto portfolio via the all in one Ledger Wallet app: buy, sell, send, receive, swap, stake and more across popular blockchains. 15,000+ coins & tokens in a single dashboard. Keep a close eye on the market. Compare service providers. Track performance. Get timely alerts. Build your portfolio with confidence.
- Enjoy Bluetooth connectivity, iOS access, and hours of battery use with this mobile-first, secure backup signer. Freedom you can depend on.
- Genuine Check: confirm your signer is authentic during setup with the Ledger Wallet app.
- Protect your signer: keep it in mint condition at all times with a bespoke Pod or Case to avoid scratches and everyday wear and tear.
The word “token” can mean different things here. OpenClaw documentation also refers to legitimate software credentials, such as API, gateway and ClawHub authentication tokens. Those are not cryptocurrency or airdrop assets; see the project’s ClawHub authentication documentation and environment-variable reference.
Do not treat a familiar logo, GitHub mention, token ticker, or polished page as proof that an offer is official. Verify announcements through the project’s official channels and check the domain character by character. Navigate using a saved bookmark or an address you enter yourself rather than a link in an unsolicited message. HTTPS protects a connection to a site; it does not establish that the site belongs to OpenClaw.
Rank #2
- Proven security at scale: Over 9 years and millions of cards issued with no known remote hacks, while military‑grade EAL6+ security keeps your private keys locked inside the chip. Your cryptocurrencies stay strongly protected from online attackers.
- Tap once to manage your entire crypto wallet across 90 blockchains - no USB cables or Bluetooth, no batteries, no setup. Access 14,100+ coins & tokens, DeFi, NFTs, and staking instantly from your phone
- Smart backup: Use your second Tangem Wallet as your Backup keys with end‑to‑end encryption; no more papers, pictures. If one card is lost, the remaining can still restore full access, with an optional seed phrase available for advanced users.
- Engineered to last up to 25 years: Waterproof (IP69K), shockproof and tested for extreme temperatures from −25°C to 50°C. A durable cold wallet with long‑term protection and independently audited security.
- Trusted by 6 million users worldwide - buy, sell, swap, stake, and spend cryptocurrency directly. The secure offline storage wallet designed for how people actually use crypto wallets
What researchers reported about the wallet-draining code
CSO’s account of OX Security’s analysis described obfuscated code in a JavaScript file named eleven.js. The code reportedly collected wallet addresses, transaction values and names, and communicated with watery-compost[.]today. Reported command names included PromtTx, Approved and Declined. Researchers also described a “nuke” function intended to remove wallet-stealing information from browser local storage and hinder investigation.
The report named WalletConnect, MetaMask, Trust Wallet, OKX Wallet and Bybit Wallet as supported or targeted wallet interfaces. That does not mean those providers were breached. The reported risk was that a user could be deceived into connecting a wallet and authorizing a harmful request.
Rank #3
- All your digital assets in one place. You can manage thousands of crypto including Bitcoin, Ethereum, Solana, Tether and more.
- Defend your identity against hackers: secure your online accounts with passwordless, hardware backed, 2FA logins for all your favorite apps and websites.
- Connectivity: USB-C cable connection only. No Bluetooth.Compatible with the Ledger Wallet crypto app, both desktop (Windows, macOS, Linux) and mobile (Android only). Not compatible with iOS.
- Protect your digital assets with the industry's best security: keep your private keys offline in your private signer, battle-tested by the Donjon's white hat hackers, CC EAL 6+ certified Secure Element, constantly updated Ledger OS.
- Effortlessly build your crypto portfolio via the all in one Ledger Wallet app: buy, sell, send, receive, swap, stake and more across popular blockchains. 15,000+ coins & tokens in a single dashboard. Keep a close eye on the market. Compare service providers. Track performance. Get timely alerts. Build your portfolio with confidence.
The analysis also identified this recipient address in the code: 0x6981E9EA7023a8407E4B08ad97f186A5CBDaFCf5. Security teams can treat the address and defanged domains as indicators to investigate, not as proof by themselves that a particular person lost funds. The report said multiple accounts were created and deleted within hours; that short-lived activity does not establish that every account or domain was taken down or is now inactive.
What “draining a wallet” means—and what it does not
A wallet interaction can expose different levels of control. Connecting a wallet may reveal its public address or establish a website-wallet session; that alone is not the same as authorizing a transfer. Signing a message, approving token spending, and signing an on-chain transaction are also different actions, and their risks depend on exactly what the wallet request says. An approval can let a spender move specified tokens, sometimes up to an unlimited amount; a transaction can directly authorize an on-chain action.
Rank #4
- UNPARALLELED SECURITY: Protect your assets with Trezor Safe 5's NDA-free EAL 6+ Secure Element, offering robust defense and complete transparency.
- EFFORTLESS NAVIGATION: Experience seamless crypto management with the vibrant color touchscreen, designed for intuitive and user-friendly interactions.
- ENHANCED USER EXPERIENCE: Enjoy tactile confirmation with Trezor Touch Haptic Engine, making each interaction precise and engaging.
- SUPPORTS 1000s OF COINS & TOKENS: Securely handle thousands of assets, including Bitcoin, Ethereum, and more, all in one wallet.
- EASY ASSET MANAGEMENT: Monitor and transact seamlessly with Trezor Suite, our user-friendly desktop and mobile app
The cited report describes wallet-stealing functionality, but does not establish precisely which request every visitor saw, that a seed phrase was collected, or that funds were successfully transferred. Merely visiting the page or having a public wallet address exposed does not automatically empty a wallet. Conversely, a hardware wallet does not make a malicious transaction safe if its owner approves it.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.What to do if you encountered the message or site
Choose the response based on what you actually did. Disconnecting a site, revoking an allowance and moving funds address different risks; revoking an allowance does not reverse a completed transfer.
What’s actually slowing this PC down?
Pick the symptom - the matching free tool is one click away.
Best Value
- Dual-chip architecture for maximum protection: The next-gen, fully auditable TROPIC01 chip works alongside a certified EAL6+ Secure Element—completely NDA-free—to deliver radically transparent, industry-leading defense against physical attacks.
- Quantum-ready security: Get protection against future threats with the first-ever hardware wallet designed with quantum-ready architecture.
- See every detail with confidence: Our largest high-resolution color touchscreen makes it easy to navigate your assets, review transactions and manage your coins with clarity.
- Wireless freedom with encrypted Bluetooth control: Manage, buy, swap and stake securely using Trezor Suite on desktop or mobile. Qi2-compatible wireless charging keeps your Trezor powered up. No cables required—security meets convenience.
- Works seamlessly with Android, iOS and desktop: Connect wirelessly or via USB-C to your phone or computer. Manage your crypto anywhere with our companion Trezor Suite app.
| Your action | Risk and response |
|---|---|
| Read the GitHub message but did not click | Do not follow the link. Report the account, issue, discussion or repository to GitHub and delete the notification. |
| Clicked the link but did not connect or sign | Close the page. Do not download files or install extensions it requested. Check browser downloads and extensions, and run your usual device-security checks. A click alone does not show that funds were exposed. |
| Connected a wallet, but did not approve or sign anything | Disconnect the site in the wallet, review recent wallet activity and watch for unexpected requests or transactions. A connection and an approval are not the same thing. |
| Approved token spending | Use a trusted wallet interface or reputable approval-review tool to inspect and revoke suspicious allowances. Review each network you used: token approvals are generally chain-specific. Revocation cannot recover assets already transferred. |
| Signed a transaction you do not recognize | Inspect the transaction and move remaining assets to a fresh wallet if you believe the transaction exposed broader control. Preserve relevant details and seek help through a trusted wallet or security provider, not unsolicited recovery offers. |
| Entered a seed phrase or private key | Treat that wallet as compromised. Create a new wallet with a trusted application or hardware wallet, transfer remaining assets if possible, and never reuse the exposed secret. A wallet connection or allowance revocation is not an adequate substitute. |
If you also entered GitHub credentials or installed a browser extension, handle that as a separate account or device-security incident: change the affected credentials, review active sessions and OAuth applications, and investigate the extension. Do not trust anyone who contacts you through GitHub or social media promising to recover funds.
What organizations and project administrators can do
- Block the reported domains,
token-claw[.]xyzandwatery-compost[.]today, in appropriate security controls, and preserve relevant DNS, proxy and browser telemetry. - Search GitHub notifications and available audit records for messages containing terms such as “CLAW,” “allocation,” “airdrop” and “OpenClaw.” Report abusive accounts, issues, discussions and repositories to GitHub.
- Train developers to treat issues, pull requests, discussions and mentions as possible phishing delivery channels, including when a message appears in a familiar project community.
- Keep valuable holdings separate from wallets used for experiments or routine development. Require transaction simulation or human review for high-value actions, and prohibit connecting production wallets to unapproved websites.
- If investigating the page, preserve its HTML, JavaScript, screenshots, timestamps and headers without visiting it from a production environment or connecting a wallet.
What the report establishes about impact
The March 26, 2026 report attributed the technical findings to OX Security and said its analysis had not identified affected users at the time. It did not establish a victim count, total losses or successful transfers. That makes “wallet drainer” a description of the campaign’s reported capability and objective—not confirmation that the reported campaign had already drained victims’ funds. Domain and account status can change, so the publication-time report should not be read as a current status check.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.




