Fake xStocks, Pendle, and other sites bait crypto users with rewards votes

Fake xStocks, Pendle, and other sites bait crypto users with rewards votes
Researchers found 70 fake websites impersonating crypto projects such as Kraken’s xStocks, Pendle, Zama, Kinetiq, Yield Basis, and Firelight to lure visitors into clicking a bogus rewards vote. The pages lead to wallet connection prompts that can pave the way for malicious approvals or signatures that drain tokens, and they share a common pattern of random sitemu*.xyz domains. #Kraken #Pendle #Zama #Kinetiq #Firelight #YieldBasis #Umia #Keeta #NetNet

Keypoints

  • 70 websites were identified impersonating legitimate crypto projects and promoting fake rewards-vote pages.
  • The pages closely copied real project sites, including logos, menus, colors, and even copied announcements.
  • The main lure was a bogus “Vote now” action promising an activity-based boost for future rewards.
  • Clicking Vote opened a wallet connection prompt, which could be the first step toward token-draining approvals or signatures.
  • Targets included xStocks from Kraken, Pendle, Zama, Kinetiq, Yield Basis, Firelight, Umia, Keeta, and NetNet.
  • The sites appear to be part of a shared phishing operation, using the same templates and randomized sitemu*.xyz domains.
  • Users are advised to verify offers through official channels, inspect wallet requests carefully, and revoke suspicious approvals if needed.

MITRE Techniques

  • [T1566 Phishing – Used fake reward-vote pages to trick visitors into interacting with a malicious site (‘clicking the Vote now button opens a wallet connection prompt’)]
  • [T1199 Trusted Relationship – The pages impersonated well-known crypto projects to exploit users’ trust in familiar brands (‘copy the look of the real sites closely’)]
  • [T1056 Input Capture – The wallet connection flow is designed to collect sensitive wallet interaction details through deceptive prompts (‘opens a wallet connection prompt’)]
  • [T1204 User Execution – The scam depends on the victim clicking the vote button and proceeding with the connection flow (‘clicking the Vote now button’)]
  • [T1071 Web Protocols – The operation uses websites and web-based wallet prompts to deliver the scam (’70 websites that impersonate legitimate crypto projects’)]
  • [T1583 Acquire Infrastructure – The actor registered many lookalike domains to host the campaign (‘all of the domains … follow the same pattern … on the .xyz top-level domain’)]
  • [T1036 Masquerading – Each page disguises itself as a real crypto project using copied branding and content (‘close copy of the project it targets, down to the logo, menus, and colors’)]

Indicators of Compromise

  • [Domain names] fake reward-vote sites – sitemufl06qs0r4o[.]xyz, sitemui6m6bbj1bd[.]xyz, and 68 more sitemu*.xyz domains
  • [Brand names] impersonated crypto projects – Kraken xStocks, Pendle, Zama, and 5 more brands
  • [Wallet connection options] deceptive wallet prompt – WalletConnect, MetaMask, Trust Wallet, and 5 more wallet options


Read more: https://www.malwarebytes.com/blog/threat-intel/2026/10/fake-xstocks-pendle-and-other-sites-bait-crypto-users-with-rewards-votes