Steinberger’s tweet reads with the anger of someone backed into a corner.
Shanghai is gloomy in March. It’s 8 degrees, and gray outside the window. I was wrapped in a blanket scrolling through today’s GitHub notifications when I saw a message that nearly made me choke on my donut.
Someone is impersonating the OpenClaw team, sending private messages to open-source contributors who have submitted PRs. The pitch? Promoting “money-making opportunities” in the AI gray market, complete with a crypto wallet address for donations, and—here’s the kicker—a promise to help fast-track your PR review.
I froze for about three seconds, then started digging into just how deep this rabbit hole goes.
This Scam Is Uncomfortably Precise
To be honest, this isn’t one of those low-level scams you can spot at a glance.
Think about it: an open-source contributor has just submitted a PR and is waiting for a maintainer’s review. At this exact moment, they receive a DM from the “project team” saying, “Hey, we noticed your contribution, here’s a great AI-related opportunity.” If you were off guard, would you immediately be suspicious?
I talked to a few friends in the open-source community about this. Their reactions generally fell into two camps. One was “I definitely wouldn’t click it,” and the other was more honest—”If their wording was good enough, and I actually had a pending PR sitting there, I might genuinely take a second look.”
The entry point chosen by the scammers is too accurate. Open-source contributors are often in a psychological state of “waiting for validation.” Whether a PR gets merged, or whether a maintainer notices their code—these things carry emotional weight for many people. Slipping a fake official message in at this node, accompanied by a promise of “expedited review”… well, this isn’t just phishing; it’s precision feeding based on your psychological profile.
Moreover, the step involving the crypto donation address is calculated. They aren’t asking for a direct payment; it appears under the guise of a “donation.” The tone is ambiguous enough to avoid triggering most people’s alarm bells.
The OpenClaw Project Has Already Been Through Hell with Scammers
A user was banned just for mentioning Bitcoin block height in a technical discussion; Steinberger says rules are rules.
If you don’t know the background of OpenClaw, here’s a quick catch-up. OpenClaw is an open-source AI agent framework founded by Peter Steinberger, the guy originally behind PSPDFKit. The project has over 68,000 stars on GitHub and is one of the hottest open-source AI projects of early 2026. It allows you to run AI agents locally, connect to various LLMs, and interact via chat tools like WhatsApp and Telegram—essentially pulling the AI assistant from the cloud back to your own machine.
But the growth history of this project is practically a tear-jerker of being chased by scammers.
This January, Anthropic demanded the project change its name due to trademark issues (it was originally named Clawdbot, which was too similar to Claude). Steinberger agreed. In the roughly ten-second window between him releasing the old GitHub and X handles and registering new ones, scammers used automated scripts to squat on the old accounts. Just ten seconds.
These scammers then used the stolen accounts to push a Solana token called $CLAWD, sending the market cap briefly to $16 million. After Steinberger publicly denied involvement, the token crashed over 90%, trapping everyone who entered late.
Steinberger later posted on X, saying: “To all crypto folks: Please stop pinging me, stop harassing me. I will never do a coin. Any project that lists me as coin owner is a SCAM.”
He told Lex Fridman that at one point, he wanted to delete the entire project.
A person who built a free open-source project nearly gave up on his work because of scammers’ operations. (Sighs lightly) Tell me that isn’t absurd.
Later, the OpenClaw Discord implemented a total ban on mentioning cryptocurrencies. A user mentioned Bitcoin block height as a timing mechanism during a technical discussion and was banned. That severity shows just how deep the team’s trauma runs.
Not an Isolated Case, It’s a Whole Supply Chain
I’ve done some research on open-source ecosystem security before, but looking at this event in the broader context is shocking.
According to Chainalysis’s 2026 Crypto Crime Report, the total amount involved in crypto scams and fraud in 2025 was approximately $17 billion. Among them, impersonation scams grew by 1400% year-over-year, and AI-assisted scams have a profit margin 4.5 times higher than traditional methods.
![Crypto Scam Trends]
