OpenClaw developers on GitHub, a platform for collaboration and version control, are being targeted in a phishing campaign using fake token giveaways to lure victims into connecting crypto wallets that can then be drained.
The attackers created bogus GitHub accounts and tagged developers in issue threads, claiming they had been selected to receive roughly $5,000 worth of CLAW tokens, Tel Aviv-based cybersecurity company OX Security said in a blog post on Wednesday.
The attackers' posts link to a near-identical clone of the OpenClaw website, but with a key addition: a prompt to connect a crypto wallet. Once a wallet is connected, malicious code can trigger transactions or approvals that allow attackers to siphon funds. The phishing page supports major wallets including MetaMask, WalletConnect and Trust Wallet, widening the potential impact, OX said.
coindesk.com