Threat Intel
Fake xStocks, Pendle, and other sites bait crypto users with rewards votes
We found 70 websites that impersonate legitimate crypto projects that invite visitors to vote on the date of an upcoming rewards distribution. The pages copy the look of the real sites closely, and on most of them the offer is small and believable: Cast a vote, and as an active v
Malwarebytes Labs··7 min read
We found 70 websites that impersonate legitimate crypto projects that invite visitors to vote on the date of an upcoming rewards distribution. The pages copy the look of the real sites closely, and on most of them the offer is small and believable: Cast a vote, and as an active voter you get a 1.25x boost when the rewards are paid out. However, the vote is fake and clicking the Vote now button opens a wallet connection prompt. It’s the first step toward requests that could trick visitors into authorizing access to their tokens. The brands being copied include xStocks from Kraken, Pendle, Zama, Kinetiq, Yield Basis, Firelight, and smaller platforms including Umia, Keeta, and NetNet. None of these pages are affiliated with the projects they imitate. Copies of familiar brands Each site is a close copy of the project it targets, down to the logo, menus, and colors. The Firelight copy even carries a real announcement about the protocol’s deposit cap, suggesting the pages were copied from the live sites rather than rebuilt from scratch. Most use the same wording about voting on the rewards date to earn a boost, though a few vary the pitch. The Pendle copy adds fake dates and a countdown to create urgency, the Keeta copy promises points instead of a boost, and the NetNet copy skips the vote and warns that unclaimed tokens will be burned after 48 hours. Why these brands The choice of targets does not appear to be random. Several of the impersonated projects have held a token launch, airdrop, or public token sale within the past year. Others run points or rewards programs. Their communities are used to hearing about rewards, claims, and allocations, and are primed to act on them. Zama ran a public token auction in January, and its token began trading in February. Kinetiq launched its governance token alongside an airdrop to early users in November 2025. Umia’s token auction ran from August 29 to September 2, only weeks ago. Firelight awards points to early depositors, and Pendle launched on Robinhood Chain on September 4. A message about rewards from one of these projects would not sound strange to someone who follows it. The lure appears designed to appeal to people who already hold the token or have used the protocol, because they’re the ones who might expect a distribution and want a bigger share. What happens when you click vote The Vote button does not lead to a ballot. It opens a Connect Wallet window that is the same regardless of which brand the page imitates. It lists WalletConnect, MetaMask, Trust Wallet, OKX Wallet, Binance Wallet, Bitget Wallet, and Rabby, along with an option to browse more than 28 others. This window resembles the connection prompts people see on legitimate crypto sites, which may make the request seem routine. Connecting a wallet on its own shares the wallet’s address, allowing the site to look up its holdings. At this point, it does not give the site permission to spend your tokens. The damage typically comes from what the site asks for next. In wallet-draining scams, a page may follow the connection with a request to sign a message or approve a transaction, presented as confirming the action the visitor came to take. A malicious approval or signature can give the attacker permission to move tokens out of the wallet without further confirmation. Blockchain transactions generally cannot be reversed, so stolen funds are very difficult to recover. Signs of a single operation Several details suggest a shared operation or phishing kit. All of the domains listed at the end of this article follow the same pattern: sitemu followed by a string of apparently random characters, on the .xyz top-level domain. The same templates are reused across several different brands, with the text appearing almost word for word whether the page is dressed up as Zama, Firelight, or Yield Basis—right down to writing the boost as 1,25x , with a comma in place of the decimal point. The wallet connection window behind the Vote button is identical across the brands as well. Random domain names spare the operator the work of coming up with a convincing lookalike address for each brand, and losing any single site costs them little. They also make the address bar one of the clearest giveaways on these pages. How to protect your wallet Check any claimed vote or rewards distribution through the project’s official channels before connecting your wallet. A familiar logo is easy to copy. Check the address, not the design. These pages closely copy the real thing, so branding alone cannot establish that they are genuine. If the domain is not the one the project officially uses, close the tab. Go to the project directly. If a vote or a reward is genuine, it will be on the project’s official site or announced on its established social accounts. Use a bookmark or type the address yourself rather than following a link from a message, ad, or reply. Read what your wallet asks you to sign. Voting should not require you to approve spending of your tokens. If a signature or transaction request mentions approvals, permits, or transfers, reject it. Wallets that preview the outcome of a transaction can help, but do not approve a request you cannot understand. Be wary of boosts, bonuses, and deadlines. Promises of extra rewards and warnings that unclaimed tokens will be burned can pressure you to act before checking. Keep most of your funds in a separate wallet. Use a wallet with a small balance for unfamiliar sites, and keep long-term holdings in a wallet that you don’t use for those connections. If you already connected, disconnect from the site. If you also signed a message or approved a transaction, use your wallet’s approval-management feature or a trusted token approval checker to review and revoke suspicious permissions. Disconnecting alone does not revoke token approvals. If you suspect your recovery phrase or private key was exposed, move remaining funds to a new wallet created with a new recovery phrase. How Malwarebytes helps Malwarebytes Browser Guard can block known phishing and scam sites before you interact with them. That is useful in campaigns like this one, where the fake page closely resembles the real thing. If you receive a link to a rewards vote, claim page, or airdrop and are unsure about it, Malwarebytes Scam Guard can help assess the link before you connect your wallet. Check the offer through the project’s official channels too. Indicators of compromise sitemufl06qs0r4o[.]xyz sitemui6m6bbj1bd[.]xyz sitemui8go6g99bb[.]xyz sitemuicitd4jrtr[.]xyz sitemuidkr38kji0[.]xyz sitemuidlij5urd0[.]xyz sitemuif3pa5k4eh[.]xyz sitemuife3h91vjj[.]xyz sitemuioeefbyh3i[.]xyz sitemuioi7005ekb[.]xyz sitemuizkhpdbjnv[.]xyz sitemuj1xencnin8[.]xyz sitemuj7lzbasipw[.]xyz sitemujbcz1nas1x[.]xyz sitemujdi54aitrf[.]xyz sitemujejvp4tp0x[.]xyz sitemujffobdhxgj[.]xyz sitemuji07m137aw[.]xyz sitemujoqrmsm0et[.]xyz sitemujrfn7witew[.]xyz sitemujsm7brhwh0[.]xyz sitemujtcvh5q9fj[.]xyz sitemujtd8ingh2b[.]xyz sitemujtdkvy6c7n[.]xyz sitemujufht1ntj4[.]xyz sitemujufs1975v4[.]xyz sitemujug76lkyke[.]xyz sitemujumvtmjaf1[.]xyz sitemujuncdlpnng[.]xyz sitemujuno47vpud[.]xyz sitemujunzgjapds[.]xyz sitemujw19idqe01[.]xyz sitemujw1uspghl1[.]xyz sitemujwcvm5ufu8[.]xyz sitemujxjlv2lmhh[.]xyz sitemuk3jcm1olr8[.]xyz sitemuk3jpe1eph7[.]xyz sitemuk3z1hh2tvn[.]xyz sitemuk3zjrr2ufy[.]xyz sitemuk3zu5776gi[.]xyz sitemuk6zd201nsw[.]xyz sitemuk7f31386dx[.]xyz sitemuk7fi1dcrp4[.]xyz sitemuk7fvnvihra[.]xyz sitemuk7xbyszpzj[.]xyz sitemuk7y434m4om[.]xyz sitemuk7yi5eqn74[.]xyz sitemuk7ys6db9qj[.]xyz sitemuk9ayiwadjz[.]xyz sitemuk9c4oppeco[.]xyz sitemukh5awm67rj[.]xyz sitemukpy2hpmpwv[.]xyz sitemukrod1am6ez[.]xyz sitemukvxv7j5hmv[.]xyz sitemukvy7wudsqb[.]xyz sitemukww7ivnaji[.]xyz sitemukwxih8302f[.]xyz sitemul94tcv4l80[.]xyz sitemul95f18sowo[.]xyz sitemul95pxqgmm8[.]xyz sitemulaay8dbm66[.]xyz sitemulaucnbmnrd[.]xyz sitemulffos1qryn[.]xyz sitemuli8pd7qi9z[.]xyz sitemulpmt6if530[.]xyz sitemulpnff7964j[.]xyz sitemulpo7jkntfz[.]xyz sitemulr9d1dg77r[.]xyz sitemuls00qrsh0k[.]xyz sitemulszq4rm2yn[.]xyz About the author Stefan Dasic Sr. Malware Research Engineer/Web Protection Technical Lead, ThreatLabs Passionate about antivirus solutions, Stefan has been involved in malware testing and AV product QA from an early age. As part of the Malwarebytes team, Stefan is dedicated to protecting customers and ensuring their security.