Fake “Rewards Vote” Sites Drain Crypto Wallets

Malwarebytes · Medium sophistication
Last updated October 1, 2026

Researchers found dozens of lookalike websites impersonating real crypto projects and promising a small, believable reward boost if users “vote” on a rewards distribution date. The vote is fake; clicking “Vote now” triggers a wallet connection prompt and can lead to malicious approval/signature requests that let attackers steal tokens.

Key findings

  • 70 impersonation sites copied legitimate crypto project branding and offered a small, believable incentive to “vote” on a rewards distribution date.
  • Clicking “Vote now” opens a standard-looking “Connect Wallet” prompt (WalletConnect/MetaMask/Trust Wallet/etc.), designed to feel routine.
  • The likely theft occurs after wallet connection when victims are prompted to approve a transaction or sign a message that grants token access.
  • Indicators suggest a shared operation/kit: repeated templates and a consistent domain naming pattern using `sitemu...` on `.xyz`.

Who’s being targeted

  • Commonly targeted roles: Finance/Treasury, Executives, Employees who use crypto wallets (personal or corporate), Fraud/Payments teams, Customer/community support for crypto products.
  • Affected industries: Cryptocurrency / Web3, Financial services, Retail investors/consumers.
  • Attack channels: website.
  • Impersonated: A legitimate crypto project (e.g., Pendle, Zama, Firelight, xStocks), NetNet (impersonated).

Awareness takeaways

  • Treat “rewards votes/claims” as untrusted until verified in the project’s official channels.
  • Teach users to verify the website address (domain) rather than trusting a familiar logo and design.
  • Train wallet users to reject signature/approval requests that grant spending permissions for “voting” or “boosts.”
  • Highlight urgency and small “bonus boosts” as common manipulation tactics in scams.

Red flags to watch for

  • A “vote” unexpectedly requires connecting a wallet
  • Random-looking `.xyz` domains (pattern `sitemu` + random characters)
  • Urgency tactics like a countdown or burn warning (e.g., “unclaimed tokens will be burned after 48 hours”)
  • Threat of loss (“burned after 48 hours”) to rush a decision
  • Branding looks real but the domain is not the project’s official site
  • Wallet asks to sign/approve something unrelated to the stated action
Try Mirage

Mirage safely runs attacks like this one against your own team, so you find out what happens before a real adversary does.

Get a demo
Read the video transcript

You see a Pendle or NetNet page saying, “Cast a vote and get a 1.25x rewards boost.” Looks legit, right? But on these 70 fake “rewards vote” sites, that Vote button never leads to a ballot. It pops a standard-looking Connect Wallet window, MetaMask, WalletConnect, Trust Wallet, the same no matter which project they copy. The trap is what comes next: a signature or approval that quietly grants token access, while the page screams “unclaimed tokens will be burned after 48 hours” to rush you. Remember: voting or claiming should not require spending approvals. Your move: if any “vote” or “boost” page on a random .xyz asks your wallet to approve spending, stop and close it, then only check rewards from the project’s official site or app.

Similar attacks

AI Search Results Turn Into Phishing Traps

AI Search Results Turn Into Phishing Traps

This bulletin describes multiple real-world scams where attackers make fake pages and messages look like routine, trusted experiences (search answers, Google login pop-ups, “giveaways,” and official-sounding calls). Examples include a fake Claude Max giveaway using a convincing fake Google sign-in…

September 24, 2026
Revolut Smishing Uses Fake Identity Check

Revolut Smishing Uses Fake Identity Check

Following a Revolut data breach, scammers sent text messages that appeared to come from the same message thread as legitimate Revolut texts. The texts pushed victims to click a link for a fake identity “liveness check,” request camera access, and then capture passwords, information that could be…

September 21, 2026
Revolut Users Hit With SMS Phish After Breach

Revolut Users Hit With SMS Phish After Breach

Days after Revolut disclosed that customer records were shared with an unauthorized party, some customers reported receiving phishing texts that appeared in the same SMS thread as real Revolut messages. The link led to a fake site that asked for camera access to mimic Revolut’s identity “liveness”…

September 17, 2026
Brevo Breach Fuels Crypto Newsletter Phishing

Brevo Breach Fuels Crypto Newsletter Phishing

Attackers abused access to Brevo (an email marketing platform) to send highly convincing phishing emails from legitimate cryptocurrency company domains to newsletter subscribers. The lures claimed urgent security issues (hardware vulnerability or data breach) and pushed victims to click links,…

September 11, 2026
Fake Tesla Token Presale Kit Steals Crypto

Fake Tesla Token Presale Kit Steals Crypto

Researchers found a turnkey scam kit sold on a cybercrime forum that lets criminals quickly stand up a fake crypto “presale” website styled to look like Tesla. The site uses pressure tactics and a fake investment dashboard to trick people into either handing over their wallet recovery phrase or…

August 12, 2026
Finance Phishing Lures Feed Telegram Data Leaks

Finance Phishing Lures Feed Telegram Data Leaks

A June 2026 financial-sector threat report describes real phishing emails that used business-looking themes (e.g., money transfers, receipts, voicemail) to push victims to malicious links or HTML attachments that mimic login pages. The report also highlights cases where stolen account information…

July 22, 2026