Security1 publisher2 min readPublished
Seventy cloned crypto sites use a fake rewards vote to get wallets connected
Malwarebytes found 70 sites cloning Kraken's xStocks, Pendle and other crypto projects to push a fake rewards vote that opens a wallet prompt. The targets, it says, are projects whose users are used to hearing about rewards and allocations.
The Watch · Security desk
Drafted by a language model from the sources cited here and checked against its claim ledger before publication. How we use AISend a correction

What happened
- Most pages pitch a small reward: vote on the distribution date and, as an active voter, collect a 1.25x boost on the payout.
- Besides xStocks and Pendle, the copied brands include Zama, Kinetiq, Yield Basis and Firelight, plus smaller platforms Umia, Keeta and NetNet, none of them affiliated with the pages.
- The Firelight copy carries a real announcement about the protocol's deposit cap, which suggests the pages were lifted from the live sites.
- Page text repeats almost word for word across brands, down to a boost written as "1,25x", and Malwarebytes says that points to one operation or phishing kit.
Compiled by The WatchSomething wrong?How this is made
Why it matters
- constraint Watch lists that flag new domains containing a brand name will not match these addresses, because each one is a random "sitemu" string on .xyz with no brand in it.
- cost The operator loses little when any single site goes down, so taking clones down one page at a time leaves the kit that produces them intact.
- precedent Targets track recent token sales, launches and points programs, so projects announcing an airdrop or sale are the likeliest next brands for the same kit.
The attack runs on two user decisions [13][14]. Connecting a wallet gives the site its address and lets it look up holdings. It does not grant permission to spend tokens [13]. The loss comes at the next prompt: a request to sign a message or approve a transaction, presented as confirming the vote [14]. A malicious signature or approval can let the attacker move tokens without further confirmation, according to Malwarebytes, and blockchain transactions generally cannot be reversed [14][15]. Malwarebytes describes that second step as what drainer pages typically do, without detailing the request each of the 70 clones makes [14].
The infrastructure matches across brands. Every listed domain is "sitemu" followed by apparently random characters, on .xyz [16]. The Connect Wallet window behind the Vote button is the same whichever brand the page imitates [12]. It lists WalletConnect, MetaMask, Trust Wallet, OKX Wallet, Binance Wallet, Bitget Wallet and Rabby, with an option to browse more than 28 others [12]. Malwarebytes notes that it resembles the connection prompts people see on legitimate crypto sites [21]. The company names nine impersonated brands among the 70 sites [1].
Most pages run the same script. A few vary the pitch. The Pendle copy adds fake dates and a countdown, the Keeta copy promises points instead of a boost, and the NetNet copy drops the vote and warns that unclaimed tokens will be burned after 48 hours [7].
Malwarebytes says the choice of brands does not appear random [8]. Zama ran a public token auction in January, and its token began trading in February [9]. Kinetiq launched its governance token with an airdrop to early users in November 2025 [9]. Umia's token auction ran from August 29 to September 2, and Pendle launched on Robinhood Chain on September 4 [10]. Firelight awards points to early depositors [10]. According to the report, the lure is pitched at people who already hold the token or have used the protocol, because they are the ones who might expect a distribution and want a bigger share [11].
Malwarebytes tells users to check any claimed vote or rewards distribution through the project's official channels before connecting a wallet. "A familiar logo is easy to copy," the company wrote [19]. The first item on its list: "Check the address, not the design." [20]
What to watch
- Whether Malwarebytes or the copied projects publish the exact signature or approval the clones request after connection, and whether on-chain losses get tied to the sitemu domains.
- New sitemu-pattern .xyz domains appearing for projects that announce an airdrop or token sale next.
- Whether Kraken, Pendle or the other projects post warnings on their official channels, the check Malwarebytes tells users to rely on.