MABOnChain
Educational content only. Nothing on this site is financial advice.
Home / Scam Alerts / 70 Fake Rewards Vote Sites Target Pendle, xStocks Users
Scam Alerts

70 Fake Rewards Vote Sites Target Pendle, xStocks Users

By MABOnChain Desk · Published · Updated · 2 min read

Abstract illustration for 70 Fake Rewards Vote Sites Target Pendle, xStocks Users

Published October 5, 2026, 04:36 UTC. Based on research Malwarebytes published on October 1, 2026.

Security firm Malwarebytes says it has found 70 websites impersonating crypto projects that ask visitors to "vote" on the date of an upcoming rewards distribution. According to the firm, the vote is fake, and the Vote now button opens a wallet connection prompt. That prompt is the first step toward requests that could trick users into giving the attackers access to their tokens.

Which brands are being copied

Malwarebytes listed xStocks from Kraken, Pendle, Zama, Kinetiq, Yield Basis and Firelight among the brands being copied, along with smaller platforms Umia, Keeta and NetNet. None of the pages is affiliated with the projects it imitates.

The firm said the copies closely match the real sites, down to logos, menus and colours. Most offer a small, believable reward: vote and get a "1.25x boost" when rewards are paid out. Some vary the pitch. The Pendle copy adds fake dates and a countdown, the Keeta copy promises points, and the NetNet copy warns that unclaimed tokens will be burned after 48 hours.

Malwarebytes said the targets appear to have been chosen deliberately. Several held a token launch, airdrop or public sale in the past year, or run points programmes, so their users are used to hearing about claims and allocations.

How the theft works

Connecting a wallet on its own only shares the wallet's address, Malwarebytes noted, and does not give a site permission to spend tokens. The danger comes next: in wallet-draining scams, a page may follow up with a request to sign a message or approve a transaction. A malicious approval or signature can let an attacker move tokens without further confirmation, and blockchain transactions generally cannot be reversed.

Signs of a single operation

The researchers believe one operator or phishing kit is behind the campaign. Every domain they listed follows the same pattern: "sitemu" plus a random-looking string on the .xyz domain. The same template text, including writing the boost as "1,25x" with a comma, appears across different brands, and the wallet window is identical on every site.

How to protect yourself

Malwarebytes recommends checking the address bar rather than the design, and going to a project's official site or established social accounts directly instead of following links. Voting should never require approving token spending, so reject any request that mentions approvals, permits or transfers. If you have already signed something, disconnecting is not enough: review and revoke approvals with your wallet's approval tools. If you think your recovery phrase was exposed, move funds to a new wallet.

For more warning signs, see our explainer on how to spot a crypto scam.

This article is news reporting and is not investment advice.

Sources

Not financial advice. This content is for information and education only. See our disclaimer, editorial policy and disclosures.

MABOnChain Daily Brief

The key crypto and markets stories in one short, plain-language email. Free. Unsubscribe any time.

Loading the signup form…

Prefer chat? Join us on Telegram

Keep reading