Researchers found dozens of lookalike websites impersonating real crypto projects and promising a small, believable reward boost if users “vote” on a rewards distribution date. The vote is fake; clicking “Vote now” triggers a wallet connection prompt and can lead to malicious approval/signature requests that let attackers steal tokens.
Key findings
- 70 impersonation sites copied legitimate crypto project branding and offered a small, believable incentive to “vote” on a rewards distribution date.
- Clicking “Vote now” opens a standard-looking “Connect Wallet” prompt (WalletConnect/MetaMask/Trust Wallet/etc.), designed to feel routine.
- The likely theft occurs after wallet connection when victims are prompted to approve a transaction or sign a message that grants token access.
- Indicators suggest a shared operation/kit: repeated templates and a consistent domain naming pattern using `sitemu...` on `.xyz`.
Who’s being targeted
- Commonly targeted roles: Finance/Treasury, Executives, Employees who use crypto wallets (personal or corporate), Fraud/Payments teams, Customer/community support for crypto products.
- Affected industries: Cryptocurrency / Web3, Financial services, Retail investors/consumers.
- Attack channels: website.
- Impersonated: A legitimate crypto project (e.g., Pendle, Zama, Firelight, xStocks), NetNet (impersonated).
Awareness takeaways
- Treat “rewards votes/claims” as untrusted until verified in the project’s official channels.
- Teach users to verify the website address (domain) rather than trusting a familiar logo and design.
- Train wallet users to reject signature/approval requests that grant spending permissions for “voting” or “boosts.”
- Highlight urgency and small “bonus boosts” as common manipulation tactics in scams.
Red flags to watch for
- A “vote” unexpectedly requires connecting a wallet
- Random-looking `.xyz` domains (pattern `sitemu` + random characters)
- Urgency tactics like a countdown or burn warning (e.g., “unclaimed tokens will be burned after 48 hours”)
- Threat of loss (“burned after 48 hours”) to rush a decision
- Branding looks real but the domain is not the project’s official site
- Wallet asks to sign/approve something unrelated to the stated action
Read the video transcript
You see a Pendle or NetNet page saying, “Cast a vote and get a 1.25x rewards boost.” Looks legit, right? But on these 70 fake “rewards vote” sites, that Vote button never leads to a ballot. It pops a standard-looking Connect Wallet window, MetaMask, WalletConnect, Trust Wallet, the same no matter which project they copy. The trap is what comes next: a signature or approval that quietly grants token access, while the page screams “unclaimed tokens will be burned after 48 hours” to rush you. Remember: voting or claiming should not require spending approvals. Your move: if any “vote” or “boost” page on a random .xyz asks your wallet to approve spending, stop and close it, then only check rewards from the project’s official site or app.