Skip to content

Executive Summary

Seventy websites impersonate legitimate cryptocurrency projects to solicit votes on rewards distribution dates. These fraudulent pages closely mimic the appearance of real sites, featuring small, believable offers like a 1.25x boost for voting. Clicking the vote button does not lead to a ballot but instead opens a wallet connection prompt that lists various wallet options. Connecting a wallet shares its address with the site, allowing it to look up holdings, though it does not grant permission to spend tokens at that stage. The subsequent requests often attempt to trick visitors into authorizing access or approving transactions, which can result in token draining. The impersonated brands include xStocks from Kraken, Pendle, Zama, Kinetiq, Yield Basis, Firelight, Umia, Keeta, and NetNet.

Facts Only

* Seventy websites impersonate legitimate crypto projects to invite visitors to vote on reward distribution dates.
* The pages copy the look of real sites, including logos, menus, and colors.
* One site copies Firelight, which includes a real announcement about its deposit cap.
* Pages use wording about voting for rewards to earn a boost, though some vary the pitch.
* Clicking 'Vote now' opens a wallet connection prompt listing WalletConnect, MetaMask, Trust Wallet, OKX Wallet, Binance Wallet, Bitget Wallet, and Rabby.
* Connecting a wallet shares the address but does not give permission to spend tokens.
* The operation uses domains following the pattern sitemu followed by random characters on the .xyz TLD.
* Templates are reused across brands, with identical text regarding boosts (e.g., 1,25x).

Full Take

The architecture of this impersonation relies heavily on exploiting established community expectations and social proof. The choice of targets—projects that have recently executed token launches, airdrops, or public sales—is a deliberate strategy to prime potential victims who already anticipate reward distributions. This leverages cognitive momentum: the expectation of receiving rewards creates a psychological vulnerability where verifiable information is filtered through the lens of anticipated gain.
The manipulation shifts from surface-level appearance (copying branding) to functional deception (wallet interaction). The shared wallet connection prompt suggests an automated, template-driven phishing kit. The uniformity in messaging and technical implementation across distinct brands indicates a centralized operation focused on maximizing exposure rather than individual brand loyalty. This points toward a systemic pattern where the specific identities of the imitated projects are secondary to the generalized mechanism of token extraction via wallet authorization prompts.
The core implication is that trust in established crypto ecosystems, specifically the anticipation of rewards, can be weaponized into immediate transactional compliance. The attackers do not need complex social engineering; they rely on the built-in workflow expectations of crypto users, turning a routine action (connecting a wallet) into a high-stakes security risk by piggybacking on existing user workflows. If the goal is to induce actions that lead to token movement, the focus must shift from guarding branding to scrutinizing every request for permission and transaction approval, regardless of how familiar the context seems.
Bridge Questions: How does the reliance on established crypto community narratives affect a user's baseline skepticism? What independent verification methods exist outside of project-specific channels that users can deploy to confirm legitimate reward information? If impersonation relies on identical technical templates, what systemic safeguards are needed within blockchain protocols themselves to verify the origin and context of wallet prompts?

From the original · Malwarebytes Labs

We found 70 websites that impersonate legitimate crypto projects that invite visitors to vote on the date of an upcoming rewards distribution. The pages copy the look of the real sites closely, and on most of them the offer is small and believable: Cast a vote, and as an active voter you get a 1.25x boost when the rewards are paid out.
Read the full story at malwarebytes.com

Sentinel — Human

Confidence

The analysis displays the structure and depth characteristic of human investigative writing, focusing on pattern recognition, mechanism explanation, and actionable security advice rather than purely abstract synthesis.

Signals Detected
low severity: Text demonstrates strong, consistent focus and flows logically from observation (impersonation) to mechanism (wallet connection) to implication (scam), which suggests human-directed structure.
low severity: Sentence structures vary naturally, particularly in the descriptive sections and the detailed concluding advice, avoiding the mechanical rhythm typical of pure LLM output.
medium severity: The specific enumeration of brands, dates (even hypothetical ones), and the list of malicious domains suggests grounded, observational reporting rather than synthetic fabrication.
low severity: The core mechanism described (wallet connection leading to signing transactions) is accurate, and the specific instructions for protection are actionable and context-aware, reducing fabrication risk.
Human Indicators
The text shifts between reporting observable facts (what sites mimic), analyzing behavioral patterns (why targets were chosen), and providing detailed, layered defensive advice, which demonstrates an analytical progression common in investigative journalism.
The inclusion of a specific list of domains and the explicit warnings about irreversible blockchain actions suggest direct engagement with forensic material.
Fake xStocks, Pendle, and other sites bait crypto users with rewards votes | Huntaegis