More than 70 websites copying well-known crypto projects are inviting visitors to vote on the date of an upcoming rewards distribution, with a 1.25x boost promised to active voters. There is no vote. Researchers at Malwarebytes found the sites and say the Vote now button simply opens a wallet connection prompt, the first step toward requests that could trick visitors into authorizing access to their tokens.
The brands being copied include xStocks from Kraken, Pendle, Zama, Kinetiq, Yield Basis and Firelight, along with smaller platforms such as Umia, Keeta and NetNet. None of the pages are affiliated with the projects they imitate.
The targets all had a recent payout story
Malwarebytes says the choice of brands does not appear to be random. Several of the impersonated projects have held a token launch, airdrop or public token sale within the past year, and others run points or rewards programs. Zama ran a public token auction in January, Kinetiq launched its governance token alongside an airdrop in November 2025, and Umia's token auction ran from August 29 to September 2. A community used to hearing about claims and allocations is primed to act on one more.
The copies are close. The Firelight clone even carries a real announcement about the protocol's deposit cap, which suggests the pages were copied from the live sites rather than rebuilt from scratch. The NetNet copy skips the vote entirely and warns that unclaimed tokens will be burned after 48 hours.
One kit behind dozens of brands
Several details point to a shared operation or phishing kit. Every domain Malwarebytes lists follows the same pattern, "sitemu" followed by apparently random characters on the .xyz top-level domain. The same templates are reused across brands almost word for word, right down to writing the boost as "1,25x" with a comma in place of the decimal point. The wallet window behind the Vote button, offering WalletConnect, MetaMask, Trust Wallet, OKX Wallet, Binance Wallet, Bitget Wallet and Rabby, is identical whichever project the page imitates.
Random domain names spare the operator the work of inventing a convincing lookalike address for each brand, and losing any one site costs little. They also make the address bar one of the clearest giveaways.
Connecting is not the theft, signing is
Malwarebytes stresses that connecting a wallet on its own shares the wallet's address, letting the site look up its holdings, but does not give permission to spend. In wallet-draining scams the damage typically comes next, with a request to sign a message or approve a transaction presented as confirming the vote. A malicious approval or signature can let an attacker move tokens without further confirmation, and blockchain transactions generally cannot be reversed.
The researchers' advice is practical. Check any rewards vote through the project's official channels, and judge the domain rather than the design. Voting should never require approving token spending, so reject any request that mentions approvals, permits or transfers. Keep long-term holdings in a different wallet from the one used on unfamiliar sites. Anyone who already connected should disconnect, and anyone who signed something should review and revoke suspicious permissions with an approval manager, because disconnecting alone does not revoke them. If a recovery phrase may have been exposed, move the remaining funds to a new wallet with a new phrase.
Sample indicators
- sitemufl06qs0r4o[.]xyz
- sitemui6m6bbj1bd[.]xyz
- sitemuj7lzbasipw[.]xyz
- sitemuk7fi1dcrp4[.]xyz
- sitemulszq4rm2yn[.]xyz
The full domain list is at the end of the Malwarebytes report. The lure is new but the shape is familiar from earlier campaigns such as fake wallet safety checkers and a fake GTA 6 leak site. The bait changes with whatever the crypto crowd is talking about, while the wallet prompt underneath stays exactly the same.
This briefing is provided by IntelFusions for informational and defensive purposes only. It is based on sources assessed to be reliable at the time of writing, and analytic judgments carry the confidence levels indicated. Indicators of compromise are defanged; re-arm them only in controlled environments. IntelFusions is not affiliated with the organizations named and makes no warranty as to completeness or accuracy.