← Back to Feed

Fake xStocks, Pendle, and other sites bait crypto users with rewards votes

October 1, 2026 · Malwarebytes · Severity: MEDIUM

This article reports on 70 fake websites impersonating crypto projects such as xStocks and Pendle, which bait users with fake rewards votes. When victims click to vote, they are prompted to connect their wallets, potentially granting access that leads to token theft. 📌 **Analyst Note:** This social engineering technique exploits trust in reward systems and the familiarity of brand names. Crypto users must verify URLs and never connect wallets to unfamiliar sites; security teams should monitor for brand impersonation and warn users.

We found 70 websites that impersonate legitimate crypto projects that invite visitors to vote on the date of an upcoming rewards distribution.

The pages copy the look of the real sites closely, and on most of them the offer is small and believable: Cast a vote, and as an active voter you get a 1.25x boost when the rewards are paid out.

However, the vote is fake and clicking the Vote now button opens a wallet connection prompt. It’s the first step toward requests that could trick visitors into authorizing access to their tokens.

The brands being copied include xStocks from Kraken, Pendle, Zama, Kinetiq, Yield Basis, Firelight, and smaller platforms including Umia, Keeta, and NetNet. None of these pages are affiliated with the projects they imitate.

Copies of familiar brands

Each site is a close copy of the project it targets, down to the logo, menus, and colors. The Firelight copy even carries a real announcement about the protocol’s deposit cap, suggesting the pages were copied from the live sites rather than rebuilt from scratch.

Most use the same wording about voting on the rewards date to earn a boost, though a few vary the pitch. The Pendle copy adds fake dates and a countdown to create urgency, the Keeta copy promises points instead of a boost, and the NetNet copy skips the vote and warns that unclaimed tokens will be burned after 48 hours.

Why these brands

The choice of targets does not appear to be random. Several of the impersonated projects have held a token launch, airdrop, or public token sale within the past year. Others run points or rewards programs. Their communities are used to hearing about rewards, claims, and allocations, and are primed to act on them.

Zama ran a public token auction in January, and its token began trading in February. Kinetiq launched its governance token alongside an airdrop to early users in November 2025. Umia’s token auction ran from August 29 to September 2, only weeks ago. Firelight awards points to early depositors, and Pendle launched on Robinhood Chain on September 4.

A message about rewards from one of these projects would not sound strange to someone who follows it. The lure appears designed to appeal to people who already hold the token or have used the protocol, because they’re the ones who might expect a distribution and want a bigger share.

What happens when you click vote

The Vote button does not lead to a ballot. It opens a Connect Wallet window that is the same regardless of which brand the page imitates. It lists WalletConnect, MetaMask, Trust Wallet, OKX Wallet, Binance Wallet, Bitget Wallet, and Rabby, along with an option to browse more than 28 others.

This window resembles the connection prompts people see on legitimate crypto sites, which may make the request seem routine.

The Connect Wallet window on the Firelight scam site

Connecting a wallet on its own shares the wallet’s address, allowing the site to look up its holdings. At this point, it does not give the site permission to spend your tokens.

The damage typically comes from what the site asks for next. In wallet-draining scams, a page may follow the connection with a request to sign a message or approve a transaction, presented as confirming the action the visitor came to take. A malicious approval or signature can give the attacker permission to move tokens out of the wallet without further confirmation.

Blockchain transactions generally cannot be reversed, so stolen funds are very difficult to recover.

Signs of a single operation

Several details suggest a shared operation or phishing kit. All of the domains listed at the end of this article follow the same pattern: sitemu followed by a string of apparently random characters, on the .xyz top-level domain.

The same templates are reused across several different brands, with the text appearing almost word for word whether the page is dressed up as Zama, Firelight, or Yield Basis—right down to writing the boost as 1,25x, with a comma in place of the decimal point. The wallet connection window

Key Takeaways

  • Malwarebytes discovered 70 fraudulent websites that closely mimic legitimate crypto projects, using fake rewards votes to lure users into connecting their crypto wallets.
  • The scam offers a small incentive like a 1.25x boost on rewards for voting, tricking victims into authorizing wallet connections that can lead to token theft.
  • Impersonated brands include xStocks from Kraken, Pendle, Zama, and others, with no affiliation, demonstrating a widespread phishing campaign targeting crypto investors.
☕ Buy a Coffee