https://www.paypal.com/us/cgi-bin/?&cmd=_donate-intro-ou...
"To accept donations, put a Donate button on your website. Creating the button is easy. We provide the HTML code, which you simply copy and paste to your site. Donors can then click the button to make donations. See button features you can customize."
How could you use the Donate button? "Let’s say that you are an animal rescue organization needing to raise funds to provide care for animals. You can easily add a donate button to your website and make it safe and convenient for supporters to give to your cause"
There are other similar and/or related scams involving "charities" (both legitimate and fake) but I feel this is the wrong place to discuss them.
The trouble the OP has with "donations" to an open source project tend to be very common with paypal and they often result in a false-positive in the paypal "fraud detection" (risk management) analysis. I know of one example where a prominent OpenBSD developer needed some fast hardware. He does full builds of the entire "ports" tree (i.e. all software ported to OpenBSD), so buying powerful (read: expenseive) hardware was really needed. One person stepped up with a donation/gift of the needed funds, and sent the payment through paypal...
The first thing that happened is the donor got a call from paypal because the donation triggered a false-positive in their "fraud detection" analysis. It might seem like an annoyance, but this is actually a good thing.
The next thing that happened is, the donor got a call from the credit card department of his bank, mainly because he used only a credit card with paypal. Yep, there was another false-positive alert on the fraud detection system of his bank.
During these two false-positives, the paypaly account of the open source developer receiving the funds was locked. In this case, the mistaken lock was resolved very quickly due to the two separate phone calls, but it was still a pain in the ass.
There is hope. The way to get around the paypal "requirement" of an open source project needing to be a vetted and registered 501(3)(c) organization in the US (or equivalent in other countries) is to have the payments classified as a "gift" rather than a "donation" in paypal parlance.
If they get even a whiff of fraud or a scam then they're sure as hell going to investigate, because if it goes wrong and it is fraud who has to pick up the bill? Paypal.
(What is a "fake" charity, anyway? I've worked with some charitable companies that were outright scams, but due to clever phrasing, continue to do business.)
I expect that when such organizations are uncovered, paypal gets a flood of credit card chargebacks (but can't recover the money from the "charity" because by that point the scammers have drained the accounts and moved on).
What is a "fake" charity, anyway?
The canonical example is "disaster relief" organizations which pop up after each major earthquake but just pocket the cash rather than assisting disaster victims.