AI, ML, and networking — applied and examined.
Scammers Are Impersonating the OpenClaw Team: Let’s Talk About the Fragility of Open Source Trust
Scammers Are Impersonating the OpenClaw Team: Let’s Talk About the Fragility of Open Source Trust

Scammers Are Impersonating the OpenClaw Team: Let’s Talk About the Fragility of Open Source Trust

The brand confusion period of OpenClaw became a breeding ground for scammers. This image basically shows how much the project was tossed around.

In March, Shanghai’s broken clouds have churned the sky into a gloomy grey. It’s just over ten degrees Celsius—the kind of weather where you’re wrong whether you dress warm or light. I had just made a cup of hot cocoa and sat down when I scrolled past a message that nearly made me spit my drink out.

Someone is impersonating the OpenClaw team, sending private messages to open-source contributors who have submitted PRs. They are peddling some “AI grey market money-making opportunities,” attaching crypto donation addresses, and even promising to help “fast-track PR approval.”

I stared blankly for about three seconds after reading it, then let out a deep sigh. It wasn’t shock; it was that exhausted feeling of “well, here it is.”

This Is Much Darker Than You Think

First, let’s talk about why this scam chose OpenClaw.

To be honest, most people hadn’t heard of the OpenClaw project six months ago. Its predecessor was called Clawdbot, an open-source autonomous AI agent created by Austrian developer Peter Steinberger. Released last November, it suddenly exploded in late January of this year—GitHub stars rushed to 149k within a week. Then Anthropic sent a legal notice due to trademark issues (the name was too similar to Claude). Steinberger changed the name to Moltbot, and later to OpenClaw.

The problem occurred in the gap between the name changes. Between Steinberger releasing the old GitHub and X account usernames and registering the new ones, there was reportedly only a ten-second window. Automated squatting bots snatched up all the old accounts. Scammers then used these accounts to push a fake Solana token called $CLAWD. The market cap once hit $16 million, but after Steinberger publicly denied involvement, it crashed by over 90%, falling from about $8 million to less than $800k.

Steinberger posted at the time, essentially saying: “To all the crypto people, stop harassing me. I will never launch a coin. Any coin issued in my name is a scam. You are hurting the project.”

Later, OpenClaw’s Discord implemented a strict rule: banning all cryptocurrency discussions. Someone merely mentioned Bitcoin in a technical context and was banned immediately.

Peter Steinberger, the creator of OpenClaw, looks like the type to quietly write code in a café, but ended up dragged into a multi-million dollar farce.

So you see, someone impersonating the OpenClaw team to DM PR contributors isn’t a fresh tactic at all; it’s a continuation and mutation of that previous large-scale scam. The only difference is that the targeting has become more precise—instead of casting a wide net on social media, they are pinpointing the people actively contributing code to the project.

Why Target PR Contributors specifically?

(Stirring the cocoa in the cup) This angle of entry is actually worth thinking about.

What is the mindset of a developer who has just submitted a PR to OpenClaw? Waiting to be reviewed, waiting to be merged, feeling a subtle sense of belonging and anticipation that “I am contributing to this project.” At this moment, if someone approaches you in the name of the “official team” saying they can help you speed up the PR approval—this bait precisely hits the point contributors care about most.

Then they bundle it with an “AI grey market money-making project” and attach a crypto donation address. The whole chain becomes: first establish trust and goodwill with the promise of accelerating the PR, then convert that into profit via the money-making scheme, and finally harvest the funds via the crypto address.

I’ve chatted with a few friends who maintain open-source projects about this. They say similar DMs have noticeably increased in recent months. It’s not just OpenClaw; other hot AI projects are being targeted too. It’s just that most people don’t talk about it publicly, fearing it might bring negative impact to the project.

Sean Goedecke—an engineer at GitHub—wrote an article earlier this year specifically discussing this trend. Crypto scammers have started systematically targeting open-source AI developers. There’s a platform called Bags that allows anyone to create a token for an open-source developer, “allocating” a portion of the transaction fees to the developer’s Twitter account. Developers have woken up to find their accounts being @mentioned everywhere, with thousands of dollars worth of cryptocurrency inexplicably appearing in a wallet. A developer on Hacker News said: “None of the people messaging me have actually used my open-source project.”

Classic tactic of crypto scams targeting open-source developers—give a taste of sweetness then harvest. Does this image look familiar?

This whole thing is basically… how should I put it? It’s a parasite on the trust mechanism of the open-source community. Open source operates on goodwill and trust between people; maintainers trust contributors’ code, and contributors trust maintainers’ review processes. Scammers just need to disguise themselves as a link in this chain of trust.

It’s an Old Problem, But the Form Changes Every Time

Speaking of the exploitation of trust in the open-source community, we have to mention the xz-utils backdoor incident of 2024. The magnitude of that event is in a completely different league compared to this, but the underlying logic is connected.

A person under the alias Jia Tan spent nearly three years (2021 to 2024) slowly building trust within the xz-utils project—first submitting code contributions, then taking over maintenance duties, handling translations, maintaining CI/CD systems, and finally becoming a co-maintainer of the project. By early 2024, he implanted a backdoor in the version about to be adopted by mainstream distributions like Debian and RedHat. If Andres Freund from Microsoft hadn’t accidentally noticed abnormal CPU consumption during SSH logins, this backdoor could have affected countless servers globally.

Three years. One person spent three years pretending to be a trustworthy open-source contributor just for that one injection.

Of course, the OpenClaw impersonation event we’re discussing now has a much lower technical complexity; plainly speaking, it’s a relatively crude social engineering attack. But it points to the same core issue: In the open-source community, how do you confirm that the person communicating with you is really who they say they are?

GitHub’s identity verification, official project communication channels, maintainer signing keys—there are solutions for these things on a technical level. But the reality is that many projects, especially those that explode in popularity overnight, simply don’t have time to establish this infrastructure. OpenClaw went from obscurity to 140k stars in just a week; at that speed of growth, security and governance inevitably lag behind.

The attack timeline of the xz-utils backdoor incident—three years of patient planning, more chilling than any horror movie.

Jia Tan’s activity timeline from 2021 to 2024. Looking at this image gives me an indescribable sense of unease.

If It Were Me, I Might Have Waered Too

To be blunt—and honest—if I were an average developer who had just submitted a PR to a hot project, and I received a private message that looked very official saying “We noticed your contribution and have an opportunity to chat with you”… I would at least click to check it out.

This is the power of social engineering attacks. It doesn’t require you to be stupid; it just requires you to be a normal person. Normal people feel happy about recognition, curious about opportunities, and have an instinctive trust in “official status.” Scammers aren’t exploiting technical vulnerabilities; they are exploiting human nature.

I sometimes wonder, as AI agent projects become increasingly popular, will the scale and precision of such scams continue to upgrade? Imagine if scammers used AI to automate these DMs? Customizing the script based on each contributor’s PR content, or even mimicking the speaking style of specific maintainers? This is already technically feasible.

Maybe I’m overthinking it. But earlier this year, both Malwarebytes and Bitsight reported that phishing domains appeared during OpenClaw’s name change—moltbot[.]you, clawbot[.]ai, clawdbot[.]you—along with cloned GitHub repositories. In the 2025 npm supply chain attack (Shai-Hulud 2.0), malicious packages implanted with backdoors automatically traversed all projects of a maintainer to mass-infect them. When you look at these things together, the attack surface is indeed expanding.

By the way, today happens to be International Open Data Day. Ironically, openness and trust are exactly what’s being exploited.

The Doughnut Is Finished

The clouds outside seem even more broken than before.

Steinberger announced on February 14th that he is joining OpenAI, and the OpenClaw project will be transferred to an open-source foundation. This might be good for the project’s governance; at least with organized operations, official communication channels will be clearer, and the cost of impersonation will be higher. But honestly, I don’t have a very definitive conclusion. These things are hard to prevent.

The advice I can come up with is actually very simple and boring: If someone contacts you in the name of the project team, verify it first on the project’s official GitHub, Discord, or website. Don’t click on links from unknown sources. Don’t transfer money to any crypto address claiming to be “project official.” Anyone promising to “fast-track PR review” is a scammer—legitimate projects don’t work that way.

These words sound as plain as “remember to lock the door when you leave,” but they are indeed the most effective line of defense right now.

By the way, if you’ve recently submitted a PR to OpenClaw or other popular open-source projects and received similar DMs, leave a comment and let me know? I’m curious to know how wide the actual impact of this really is.


References:

—— Lyra Celest @ Turbulence τ

Leave a Reply

Your email address will not be published. Required fields are marked *