The campaign is easy to understand and worrying in its mechanics: developers linked to OpenClaw were targeted on GitHub with the promise of $5,000 in $CLAW tokens, before being redirected to a fake site designed to make them connect and then drain their crypto wallets. OX Security documented the operation, and the OpenClaw project itself eventually publicly reported the scam.