The clouds hang low over Shanghai today, 8 degrees. It’s that kind of weather where it won’t rain but doesn’t intend to clear up either—perfect for sitting in front of a screen and getting angry enough at certain news to want to go out for a walk.
Alright, let’s talk about something quietly spreading in the open-source community recently.
The script for this scam is written with precision
Someone is impersonating core team members of OpenClaw, actively reaching out to open-source contributors who are submitting PRs (Pull Requests) to the project.
The contact strategy generally has three layers: First, pitching “AI grey market money-making projects,” claiming they can help you use AI tools to generate traffic, take orders, and arbitrage; Second, providing a cryptocurrency wallet address and asking you to “support the team”; Third, implying that if you cooperate, your PR will be prioritized for review and merged faster.
When I first saw this news, I paused for a moment—not out of shock, but because… this script understands human nature too well.
What are people who submit PRs waiting for? They are waiting for a reply from a reviewer. Sometimes they wait for days, sometimes weeks, or even longer. In this waiting period, there is anxiety, anticipation, and a bit of uncertainty about whether what they wrote is correct. The scammers step precisely onto this psychological node, using the words “speed up approval” to pry open that door.
To put it bluntly, this is much more advanced than random phishing emails.
Why this is particularly worth mentioning
It is necessary to explain the background of the OpenClaw project. Those unfamiliar might think this is just an ordinary small project having its popularity exploited. In reality, it is not.
OpenClaw, originally named ClawdBot, was released by Austrian developer Peter Steinberger in November 2025. In January 2026, it exploded on GitHub with astonishing speed, accumulating over 145,000 stars in just a few weeks, and later breaking through 190,000, becoming one of the fastest-growing open-source projects in history. It can integrate with mainstream messaging platforms like WhatsApp, Telegram, Discord, and Slack, allowing AI assistants to directly control your local file system, calendar, emails, browser, and even execute shell commands.
This positioning determines the composition of its community: there are a large number of independent developers, geeks, tech enthusiasts, and beginners learning to contribute to open source.
Precisely because the community is so active and scattered, and because the project has undergone too many renaming storms (ClawdBot → Moltbot → OpenClaw), community members are in a state of mild confusion regarding “who is official and who is a fake.” It is not without reason that scammers chose to strike here.
(Gently rubs temples)
Worse still, this is not the first time OpenClaw has encountered such impersonation events.
A screenshot of OpenClaw risk warnings compiled by security researchers—this page alone was enough to overwhelm ordinary users at the time.
Change the name, and the scam follows right in
On January 27, 2026, Anthropic issued a trademark objection letter to ClawdBot, believing that the name “Clawd” was too similar to their product “Claude,” and demanded a name change. Steinberger changed the name to Moltbot.
This name change was exploited by scammers in barely 10 seconds.
The @clawdbot X account and GitHub handle were instantly cybersquatted and immediately used to promote a fake $CLAWD Solana token. The market cap of this token was once pumped to $16 million.
At the same time, ClawHub (OpenClaw’s skill plugin market) was injected with malicious skills on a large scale. Security firm Koi Security audited all 2,857 skills on the platform and found 341 clearly malicious ones. Bitdefender’s independent scan put the number closer to 900, roughly 20% of the total. Among them, one account named “hightower6eu” uploaded 354 malicious packages alone.
So, this current incident of impersonating team members to peddle grey market projects to PR contributors… is, in a way, the “social engineering version” of this series of attacks. Technical attacks trigger alarms too easily, so they switched methods: talk to people directly, build a rapport, establish trust, and then ask for money.
This method is even harder to detect.
What does trust in the open-source community actually look like?
I’ve talked about this topic with several friends who maintain open-source projects—they universally face a dilemma: the larger and more active the project, the harder it is for the maintenance team to conduct detailed verification of every contributor’s identity.
PR review itself is a loose, dispar
