MALWAREBYTES confirms a large-scale phishing operation that imitates well-known crypto projects, including xStocks, Pendle, Zama, Kinetiq, Yield Basis, Firelight and others. In nearly all cases the fake pages invite visitors to vote on the date of a forthcoming rewards distribution and promise a boost for active voters. The “Vote now” button, however, opens a wallet connection prompt instead, which can lead to requests that trick users into authorising access to their tokens.
The sites copy the real brands very closely—down to logos, menus and colours—and several even reference real announcements to appear credible. A key pattern is that the same basic page template and the same Connect Wallet window are used across multiple brands, with minor wording changes.
When a user clicks vote, the Connect Wallet prompt appears and lists WalletConnect, MetaMask, Trust Wallet and others. Connecting reveals the wallet address, enabling the page to identify holdings, but not yet move funds. The actual danger comes when subsequent prompts ask users to sign a message or approve a transaction, which can grant attackers permission to move tokens out of the wallet. The post notes that blockchain transactions are typically irreversible, making recovery unlikely.
Evidence of compromise includes a set of250+ suspicious domains using the sitemu…xyz pattern and near-identical copy text, including a recurring 1,25x boost phrasing. Practical responses include verifying votes via official project channels, avoiding signing unfamiliar prompts, disconnecting from suspicious sites, and using dedicated or separate wallets. Malwarebytes Browser Guard and Scam Guard are highlighted as protections.