Scam Alert: Fake GitHub Airdrop Targets CLAW Token Users

Scam Details
A fake GitHub airdrop scam is targeting users with promises of $CLAW tokens for GitHub contributions. According to the source, the scam operates through the following mechanism:
- Users receive messages claiming they've been "selected" for a $CLAW airdrop based on their GitHub activity
- The scam directs users to connect their wallets through a random Google share link
- This Google link redirects to a shady .xyz website
- The fake GitHub discussion where users get tagged and receive GitHub emails is at:
https://github.com/highwayskinkjump/OpenClawEco-4828884/discussions/7
Security Warning
This is identified as a wallet-draining phishing scam. The source explicitly warns:
- Do NOT connect your wallet to any links from this scam
- Do NOT sign any transactions or approvals
- The use of a Google share link followed by redirection to a .xyz domain is a common phishing tactic
GitHub-based airdrop scams typically work by creating fake repositories or discussions that appear legitimate, then using GitHub's notification system to reach potential victims. Once users connect their wallets through the provided link, the scam site can request permissions that allow attackers to drain funds.
📖 Read the full source: r/openclaw
👀 See Also

Snowflake Cortex Code CLI vulnerability allowed sandbox escape and malware execution
A vulnerability in Snowflake Cortex Code CLI version 1.0.25 and earlier allowed arbitrary command execution without human approval via process substitution bypass, enabling malware installation and sandbox escape through indirect prompt injection.

OpenClaw Security Alert: 500,000 Public Instances, Default Config Exposes Systems
A security analysis reveals 500,000 OpenClaw instances are publicly accessible, with 30,000 having known security risks and 15,000 exploitable through known vulnerabilities. The default installation disables authentication and binds to 0.0.0.0, exposing agent setups to the open internet.

Potential Claude Security Incident: Self-Sent Password Alerts and Suspicious .NET Process
A user reports receiving suspicious password reset alerts that appeared to be sent from their own account after logging into Claude, with emails vanishing minutes later and an unusual .NET process blocking system shutdown.

LLM-Assisted Exploit: Anthropic's Mythos Preview Helped Build First Public macOS Kernel Exploit on Apple M5 in Five Days
Using Anthropic's Mythos Preview, security firm Calif built the first public macOS kernel memory corruption exploit on Apple's M5 silicon in five days—breaking MIE hardware security that took Apple five years to develop.