VYPR
phishingPublished Oct 1, 2026· 1 source

Fake Crypto Sites Mimic Legitimate Projects to Steal User Funds

Cybercriminals are operating a sophisticated phishing campaign using 70 fake websites that impersonate popular cryptocurrency projects, luring users into connecting their wallets and authorizing token theft.

A widespread phishing campaign has been uncovered, involving approximately 70 deceptive websites designed to impersonate legitimate cryptocurrency projects. These sites, including those mimicking popular platforms like xStocks (from Kraken), Pendle, Zama, Kinetiq, and Yield Basis, lure unsuspecting users with the promise of a "rewards boost" for participating in a fake voting process. The campaign leverages the trust users place in these brands to trick them into a multi-stage attack that can lead to the theft of their digital assets.

The fake websites meticulously replicate the appearance of their legitimate counterparts, often copying logos, menus, and color schemes. Some even incorporate real announcements or details about the protocols, suggesting the pages were built from scraped content of the actual sites. The core of the deception involves a "Vote now" button, which, when clicked, prompts the user to connect their cryptocurrency wallet. This initial connection allows the malicious site to gather information about the user's wallet address and holdings.

The choice of impersonated projects is strategic. Many of the targeted platforms have recently conducted token launches, airdrops, or public sales, or they operate reward programs. This means their communities are accustomed to discussions around rewards, claims, and distributions, making the phishing lure more believable. The campaign appears to target existing users or those familiar with these protocols, as they are more likely to expect and act upon notifications about rewards and distributions.

When a user clicks the "Vote now" button, a wallet connection window appears, offering a variety of popular wallet options such as WalletConnect, MetaMask, and Trust Wallet. While connecting a wallet itself doesn't immediately grant spending permissions, it's the first step in a dangerous sequence. The subsequent requests from the malicious site can trick users into approving transactions or signing messages that grant attackers the ability to drain their wallets.

Several indicators point to a single, coordinated operation or the use of a shared phishing kit. The domains used for these fake sites predominantly follow a pattern of "sitemu" followed by random characters on the .xyz top-level domain. The consistent reuse of templates across different brands, identical wallet connection windows, and the specific phrasing of the "1,25x" boost (using a comma as a decimal separator) further strengthen the evidence of a unified campaign.

To protect themselves, cryptocurrency users are advised to verify any claimed vote or rewards distribution through the project's official channels before connecting their wallet. It is crucial to check the website's address carefully, as branding alone can be easily mimicked. Users should be wary of promises of boosts, bonuses, or urgent deadlines, as these are common tactics to pressure quick action.

Furthermore, users should always read what their wallet asks them to sign or approve. Actions like voting should not require token spending approvals. If a request involves permissions, transfers, or approvals, it should be treated with extreme suspicion. Maintaining a separate wallet with a small balance for interacting with unfamiliar sites and revoking suspicious permissions after use are also critical security practices.

If a user has already connected their wallet or approved a transaction on a suspicious site, they should immediately disconnect from the site and use their wallet's approval management features or a trusted token approval checker to revoke any unauthorized permissions. If there's any suspicion that a recovery phrase or private key was compromised, funds should be moved to a new, secure wallet.

Synthesized by Vypr AI