We found 70 websites that impersonate legitimate crypto projects that invite visitors to vote on the date of an upcoming rewards distribution.
The pages copy the look of the real sites closely, and on most of them the offer is small and believable: Cast a vote, and as an active voter you get a 1.25x boost when the rewards are paid out.
However, the vote is fake and clicking the Vote now button opens a wallet connection prompt. It’s the first step toward requests that could trick visitors into authorizing access to their tokens.
The brands being copied include xStocks from Kraken, Pendle, Zama, Kinetiq, Yield Basis, Firelight, and smaller platforms including Umia, Keeta, and NetNet. None of these pages are affiliated with the projects they imitate.
Copies of familiar brands
Each site is a close copy of the project it targets, down to the logo, menus, and colors. The Firelight copy even carries a real announcement about the protocol’s deposit cap, suggesting the pages were copied from the live sites rather than rebuilt from scratch.
Most use the same wording about voting on the rewards date to earn a boost, though a few vary the pitch. The Pendle copy adds fake dates and a countdown to create urgency, the Keeta copy promises points instead of a boost, and the NetNet copy skips the vote and warns that unclaimed tokens will be burned after 48 hours.
Why these brands
The choice of targets does not appear to be random. Several of the impersonated projects have held a token launch, airdrop, or public token sale within the past year. Others run points or rewards programs. Their communities are used to hearing about rewards, claims, and allocations, and are primed to act on them.
Zama ran a public token auction in January, and its token began trading in February. Kinetiq launched its governance token alongside an airdrop to early users in November 2025. Umia’s token auction ran from August 29 to September 2, only weeks ago. Firelight awards points to early depositors, and Pendle launched on Robinhood Chain on September 4.
A message about rewards from one of these projects would not sound strange to someone who follows it. The lure appears designed to appeal to people who already hold the token or have used the protocol, because they’re the ones who might expect a distribution and want a bigger share.
What happens when you click vote
The Vote button does not lead to a ballot. It opens a Connect Wallet window that is the same regardless of which brand the page imitates. It lists WalletConnect, MetaMask, Trust Wallet, OKX Wallet, Binance Wallet, Bitget Wallet, and Rabby, along with an option to browse more than 28 others.
This window resembles the connection prompts people see on legitimate crypto sites, which may make the request seem routine.

Connecting a wallet on its own shares the wallet’s address, allowing the site to look up its holdings. At this point, it does not give the site permission to spend your tokens.
The damage typically comes from what the site asks for next. In wallet-draining scams, a page may follow the connection with a request to sign a message or approve a transaction, presented as confirming the action the visitor came to take. A malicious approval or signature can give the attacker permission to move tokens out of the wallet without further confirmation.
Blockchain transactions generally cannot be reversed, so stolen funds are very difficult to recover.
Signs of a single operation
Several details suggest a shared operation or phishing kit. All of the domains listed at the end of this article follow the same pattern: sitemu followed by a string of apparently random characters, on the .xyz top-level domain.
The same templates are reused across several different brands, with the text appearing almost word for word whether the page is dressed up as Zama, Firelight, or Yield Basis—right down to writing the boost as 1,25x, with a comma in place of the decimal point. The wallet connection window behind the Vote button is identical across the brands as well.
Random domain names spare the operator the work of coming up with a convincing lookalike address for each brand, and losing any single site costs them little. They also make the address bar one of the clearest giveaways on these pages.
How to protect your wallet
Check any claimed vote or rewards distribution through the project’s official channels before connecting your wallet. A familiar logo is easy to copy.
- Check the address, not the design. These pages closely copy the real thing, so branding alone cannot establish that they are genuine. If the domain is not the one the project officially uses, close the tab.
- Go to the project directly. If a vote or a reward is genuine, it will be on the project’s official site or announced on its established social accounts. Use a bookmark or type the address yourself rather than following a link from a message, ad, or reply.
- Read what your wallet asks you to sign. Voting should not require you to approve spending of your tokens. If a signature or transaction request mentions approvals, permits, or transfers, reject it. Wallets that preview the outcome of a transaction can help, but do not approve a request you cannot understand.
- Be wary of boosts, bonuses, and deadlines. Promises of extra rewards and warnings that unclaimed tokens will be burned can pressure you to act before checking.
- Keep most of your funds in a separate wallet. Use a wallet with a small balance for unfamiliar sites, and keep long-term holdings in a wallet that you don’t use for those connections.
- If you already connected, disconnect from the site. If you also signed a message or approved a transaction, use your wallet’s approval-management feature or a trusted token approval checker to review and revoke suspicious permissions. Disconnecting alone does not revoke token approvals. If you suspect your recovery phrase or private key was exposed, move remaining funds to a new wallet created with a new recovery phrase.
How Malwarebytes helps
Malwarebytes Browser Guard can block known phishing and scam sites before you interact with them. That is useful in campaigns like this one, where the fake page closely resembles the real thing.
If you receive a link to a rewards vote, claim page, or airdrop and are unsure about it, Malwarebytes Scam Guard can help assess the link before you connect your wallet. Check the offer through the project’s official channels too.
Indicators of compromise
sitemufl06qs0r4o[.]xyzsitemui6m6bbj1bd[.]xyzsitemui8go6g99bb[.]xyzsitemuicitd4jrtr[.]xyzsitemuidkr38kji0[.]xyzsitemuidlij5urd0[.]xyzsitemuif3pa5k4eh[.]xyzsitemuife3h91vjj[.]xyzsitemuioeefbyh3i[.]xyzsitemuioi7005ekb[.]xyzsitemuizkhpdbjnv[.]xyzsitemuj1xencnin8[.]xyzsitemuj7lzbasipw[.]xyzsitemujbcz1nas1x[.]xyzsitemujdi54aitrf[.]xyzsitemujejvp4tp0x[.]xyzsitemujffobdhxgj[.]xyzsitemuji07m137aw[.]xyzsitemujoqrmsm0et[.]xyzsitemujrfn7witew[.]xyzsitemujsm7brhwh0[.]xyzsitemujtcvh5q9fj[.]xyzsitemujtd8ingh2b[.]xyzsitemujtdkvy6c7n[.]xyzsitemujufht1ntj4[.]xyzsitemujufs1975v4[.]xyzsitemujug76lkyke[.]xyzsitemujumvtmjaf1[.]xyzsitemujuncdlpnng[.]xyzsitemujuno47vpud[.]xyzsitemujunzgjapds[.]xyzsitemujw19idqe01[.]xyzsitemujw1uspghl1[.]xyzsitemujwcvm5ufu8[.]xyzsitemujxjlv2lmhh[.]xyzsitemuk3jcm1olr8[.]xyzsitemuk3jpe1eph7[.]xyzsitemuk3z1hh2tvn[.]xyzsitemuk3zjrr2ufy[.]xyzsitemuk3zu5776gi[.]xyzsitemuk6zd201nsw[.]xyzsitemuk7f31386dx[.]xyzsitemuk7fi1dcrp4[.]xyzsitemuk7fvnvihra[.]xyzsitemuk7xbyszpzj[.]xyzsitemuk7y434m4om[.]xyzsitemuk7yi5eqn74[.]xyzsitemuk7ys6db9qj[.]xyzsitemuk9ayiwadjz[.]xyzsitemuk9c4oppeco[.]xyzsitemukh5awm67rj[.]xyzsitemukpy2hpmpwv[.]xyzsitemukrod1am6ez[.]xyzsitemukvxv7j5hmv[.]xyzsitemukvy7wudsqb[.]xyzsitemukww7ivnaji[.]xyzsitemukwxih8302f[.]xyzsitemul94tcv4l80[.]xyzsitemul95f18sowo[.]xyzsitemul95pxqgmm8[.]xyzsitemulaay8dbm66[.]xyzsitemulaucnbmnrd[.]xyzsitemulffos1qryn[.]xyzsitemuli8pd7qi9z[.]xyzsitemulpmt6if530[.]xyzsitemulpnff7964j[.]xyzsitemulpo7jkntfz[.]xyzsitemulr9d1dg77r[.]xyzsitemuls00qrsh0k[.]xyzsitemulszq4rm2yn[.]xyz














