Thursday, March 19, 2026
Digital Pulse
No Result
View All Result
  • Home
  • Bitcoin
  • Crypto Updates
    • Crypto Updates
    • Altcoin
    • Ethereum
    • Crypto Exchanges
  • Blockchain
  • NFT
  • DeFi
  • Web3
  • Metaverse
  • Analysis
  • Regulations
  • Scam Alert
Crypto Marketcap
  • Home
  • Bitcoin
  • Crypto Updates
    • Crypto Updates
    • Altcoin
    • Ethereum
    • Crypto Exchanges
  • Blockchain
  • NFT
  • DeFi
  • Web3
  • Metaverse
  • Analysis
  • Regulations
  • Scam Alert
No Result
View All Result
Digital Pulse
No Result
View All Result
Home Bitcoin

OpenClaw Developers Hit by GitHub Phishing Attack

Digital Pulse by Digital Pulse
March 19, 2026
in Bitcoin
0
OpenClaw Developers Hit by GitHub Phishing Attack
2.4M
VIEWS
Share on FacebookShare on Twitter


Scammers are focusing on contributors to the viral AI mission OpenClaw with a complicated phishing marketing campaign aimed toward draining crypto wallets.

By exploiting GitHub’s trusted notification system, attackers lure builders with a faux $5,000 token airdrop that leads on to a wallet-draining script.

🚨Pretend $5K airdrop targets OpenClaw devs

Scammers used faux GitHub tags to lure customers to a cloned web site with a hidden pockets join.

Accounts vanished inside hours. No confirmed victims but.

Keep alert⚠️ pic.twitter.com/ZYpmckDJ1j

— Bitinning (@bitinning) March 19, 2026

There aren’t any good contract exploits concerned right here. Simply social engineering, leveraging the hype round AI brokers, and unsuspecting customers falling for the lure.

It comes because the broader crypto market suffered a hunch in a single day, with the entire market cap falling 4% to $2.5 trillion, with 24-hour buying and selling quantity sitting at simply over $125Bn.

OpenClaw has suffered a massive setback with a GitHub attack that has spooked the market and reminded the market how important OpSec is

(SOURCE: CoinGecko)

The Lure: Pretend Contributions and Hidden Scripts

In accordance with a report by OX Safety, risk actors create fraudulent GitHub accounts and open situation threads in repositories they management. They then tag dozens of genuine OpenClaw builders in these threads.

The message is flattering. It claims, “Recognize your contributions on GitHub. We analyzed profiles and selected builders to get OpenClaw allocation.” The scammers promise $5,000 price of $CLAW tokens and direct targets to an internet site that eerily mimics the official openclaw.ai area.

As soon as on the location, customers are prompted to “Join your pockets” to assert the funds. That is the lure. The location executes a connection immediate designed to empty belongings, powered by a closely obfuscated JavaScript file hidden within the web site’s code named “eleven.js.”

OX Safety researcher Moshe Siman Tov Bustan famous that the marketing campaign intently resembles earlier assaults focusing on the Solana ecosystem on GitHub.

DISCOVER: The Subsequent 1000x Crypto Gem Earlier than It Lists on Exchanges

Why OpenClaw and Why Now?

Peter Steinberger is becoming a member of OpenAI to drive the subsequent era of non-public brokers. He’s a genius with a number of wonderful concepts about the way forward for very good brokers interacting with one another to do very helpful issues for individuals. We count on it will shortly turn out to be core to our…

— Sam Altman (@sama) February 15, 2026

OpenClaw is at present one of many hottest tech properties. The mission has moved from a developer instrument to a mainstream AI asset, particularly after OpenAI CEO Sam Altman tapped creator Peter Steinberger to steer the corporate’s push into private AI brokers.

That legitimacy makes it harmful. Scammers know that builders are at present paying shut consideration to the mission. Additionally they know that builders are prone to maintain cryptocurrency and are snug utilizing Web3 wallets.

This incident highlights a rising pattern the place respectable instruments are used as vectors for theft. It echoes Vitalik Buterin’s considerations about the intersection of AI and pockets safety. As AI instruments turn out to be central to the crypto workflow, the road between useful automation and malicious extraction blurs.

The attackers even seem like utilizing GitHub’s “star” function to construct their goal lists, making certain they go after customers who’ve actively engaged with OpenClaw repositories.

If you’re a developer or energetic GitHub person, it’s essential to lock down your workflow instantly. The sophistication of those clones means visible inspection is usually not sufficient.

Confirm the URL: By no means click on hyperlinks inside GitHub situation threads from repositories you don’t acknowledge. At all times kind the official area manually.
Verify the Repo Proprietor: Official airdrops will come from the mission’s principal repository, not a random person’s fork. If the repository has few stars or was created lately, it’s a lure.
Use a Burner Pockets: By no means join your principal holding pockets (chilly storage) to any dApp or declare web site. If you’re interacting with a simplified protocol or an airdrop, use a scorching pockets with minimal funds.
Ignore Sudden Tags: If you’re tagged in a thread by a person you don’t know, deal with it as spam immediately. Actual tasks announce allocations on their official X (Twitter) or Discord channels, not through mass-tagging in random points.

DISCOVER: Prime Crypto Presales to Watch Now

Comply with 99Bitcoins on X (Twitter) For the Newest Market Updates and Subscribe on YouTube For Each day Professional Market Evaluation.

Why you’ll be able to belief 99Bitcoins

10+ Years

Established in 2013, 99Bitcoin’s crew members have been crypto consultants since Bitcoin’s Early days.

90hr+

Weekly Analysis

100k+

Month-to-month readers

50+

Professional contributors

2000+

Crypto Initiatives Reviewed

Google News IconGoogle News Icon

Comply with 99Bitcoins in your Google Information Feed

Get the newest updates, tendencies, and insights delivered straight to your fingertips. Subscribe now!

Subscribe now

Alex Ioannou

Alex Ioannou

On-Chain Journalist

Alex is a seasoned cryptocurrency dealer and market analyst with over seven years of energetic expertise within the digital asset house. Since getting into the markets in 2017, Alex has specialised in figuring out rising “meta” tendencies and high-volatility narratives. Notably, Alex…
Learn Extra





Source link

Tags: AttackDevelopersGitHubHitOpenClawPhishing
Previous Post

How HR Can Protect Expertise in the Age of AI

Next Post

Google Transforms Stitch Into AI-Driven Design Canvas For Fast UI Creation And Collaborative Prototyping

Next Post
Google Transforms Stitch Into AI-Driven Design Canvas For Fast UI Creation And Collaborative Prototyping

Google Transforms Stitch Into AI-Driven Design Canvas For Fast UI Creation And Collaborative Prototyping

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Facebook Twitter
Digital Pulse

Blockchain 24hrs delivers the latest cryptocurrency and blockchain technology news, expert analysis, and market trends. Stay informed with round-the-clock updates and insights from the world of digital currencies.

Categories

  • Altcoin
  • Analysis
  • Bitcoin
  • Blockchain
  • Crypto Exchanges
  • Crypto Updates
  • DeFi
  • Ethereum
  • Metaverse
  • NFT
  • Regulations
  • Scam Alert
  • Web3

Latest Updates

  • Tempo’s Payments Infrastructure and Protocol Goes Live
  • Now Live: MetaWinners Community Launches $METAWIN Token Presale
  • PwC Tells Partners: Get “AI-First” or Get Left Behind

Copyright © 2024 Digital Pulse.
Digital Pulse is not responsible for the content of external sites.

Welcome Back!

Login to your account below

Forgotten Password?

Retrieve your password

Please enter your username or email address to reset your password.

Log In
No Result
View All Result
  • Home
  • Bitcoin
  • Crypto Updates
    • Crypto Updates
    • Altcoin
    • Ethereum
    • Crypto Exchanges
  • Blockchain
  • NFT
  • DeFi
  • Web3
  • Metaverse
  • Analysis
  • Regulations
  • Scam Alert

Copyright © 2024 Digital Pulse.
Digital Pulse is not responsible for the content of external sites.