Crypto Rewards Vote Scam Exposed: Fake xStocks Pages Seek Wallet Access

A crypto project asks its community to vote on a reward date. The page looks familiar, and the promised bonus is just large enough to seem plausible.

The next screen is where a routine-looking community action deserves a slower, more careful look.

Illustrative fictional crypto rewards voting webpage with a 1.25x boost offer

Overview

The vote that is not a vote

Fraudulent pages are borrowing the names and visual style of real cryptocurrency projects to advertise a supposed rewards-date vote.

The pitch is modest: choose a distribution date and receive a 1.25x boost for participating. It resembles ordinary community governance.

But on the pages researchers inspected, the Vote now button did not open a ballot. It opened a wallet-connection prompt.

That change of task is the heart of the trap. A reader arrives to express a preference and is pushed toward wallet permissions instead.

What the investigation established

Malwarebytes identified 70 related sites imitating projects including xStocks, Pendle, Zama, Kinetiq, Yield Basis, and Firelight.

The sites reused the same reward-vote language and wallet connection interface. Their domains followed a common, unusual naming pattern.

Researchers did not claim that every connected wallet lost funds. The observed behavior was a deceptive wallet prompt that could lead to dangerous approvals.

  • The brands being copied are real projects; the lookalike voting pages are not their official sites.
  • The 1.25x reward boost is bait, not evidence of an actual distribution.
  • Connecting a wallet exposes its public address, but does not alone authorize token transfers.
  • A later signature or spending approval can create the actual theft risk.

Why familiar branding is not enough

A copied logo can make the first screen convincing. So can real project news pasted into the fake page.

Some projects genuinely use governance votes or points programs. That history makes a fabricated reward poll easier to believe.

The safe comparison is not between two logos. It is between the page’s domain and the domain published through the project’s own channels.

One legitimate Pendle promotion cannot validate an unrelated page claiming an extra vote-based boost. Verify the exact action, not just the brand.

How the Crypto Rewards Vote Scam Works

Step 1: The operator copies a project people already trust

A fake page borrows the colors, menus, product language, and token imagery of a real crypto platform.

This is more persuasive than creating a brand from scratch. Visitors already know the project and may have used its real website.

Malwarebytes found copies targeting several communities rather than one token. That lets the operator reuse infrastructure while changing the visual wrapper.

Some pages even carried real project announcements. Accurate background information can coexist with a malicious call to action.

A reader who checks only the headline may see familiar news and lower their guard. The domain and button behavior tell the more important story.

Never assume a page is official because a chart, logo, or project update looks right. Those elements can be copied from public material.

Step 2: A small reward makes urgency look reasonable

Most copies promised a 1.25x boost for active voters when rewards were distributed. The number is specific, but not so extravagant that it sounds absurd.

A few variants changed the script. One Pendle-themed page added fake dates and a countdown. Another promised points rather than a multiplier.

A NetNet-themed page warned that unclaimed tokens would be burned within 48 hours, replacing the vote with a loss-avoidance message.

These differences matter because the operator can swap the story without changing the underlying wallet prompt.

A deadline can make a user skip independent verification. A modest multiplier can make the risk seem small, even when the wallet permissions are not.

Real rewards may have deadlines, but they should be documented through the project’s official site and established community channels.

Step 3: The Vote button asks for a wallet

Clicking Vote now brought up a familiar-looking Connect Wallet window on the pages Malwarebytes examined.

It offered common wallet brands, including MetaMask, Trust Wallet, WalletConnect, OKX Wallet, Binance Wallet, Bitget Wallet, and Rabby.

A long list makes the interface look integrated with the wider crypto ecosystem. It does not establish that the page is authorized.

Connecting normally reveals a public address. The site can then see holdings and transaction history associated with that address.

Connection alone is not the same as granting token-spending permission. Telling people otherwise would hide the actual point where consent becomes dangerous.

Still, a connection gives the page context. It can tailor the next prompt to the assets the wallet holds.

Step 4: A later approval can turn the lure into theft

After connection, a malicious page may request a signature or transaction approval while describing it as confirmation of the vote.

Some signatures merely prove control of an address. Others authorize actions with financial consequences. The surrounding page copy cannot explain away the wallet’s actual request.

A token approval may let a contract spend a specified asset. An unlimited approval is especially risky when the requester is untrusted.

That is why the crucial check happens in the wallet popup. Read the permission details, spender address, token, and amount before accepting.

If the prompt is unclear, reject it. A legitimate vote is not worth granting unexplained control over funds.

Malwarebytes described this as the first step toward requests that could authorize token access. It did not document a completed theft for every listed site.

Illustrative wallet token-spending permission dialog on a fictional DeFi website

Step 5: Copies spread faster than warnings

The 70 pages shared an unusual domain pattern, with random-looking text under a .xyz extension. That helped researchers connect the campaign.

It also means any single blocked domain is only one piece of the operation. The operator can replace it and keep the template.

Several pages repeated the same wording, even using a comma in the multiplier as 1,25x. Small mistakes can reveal a shared kit.

Do not depend on spotting that exact typo. A future copy can fix it while keeping the same deceptive wallet flow.

The better habit is to navigate from the project’s verified site, then confirm that the exact vote exists there.

Links in replies, direct messages, sponsored posts, and search results deserve the same check, regardless of how established the brand looks.

Step 6: The real project gets blamed for a copycat page

If a visitor loses funds, the copied brand may be the first name they remember. That confusion can send complaints to the wrong place.

The projects named in the campaign were impersonated. The research did not establish that they operated the counterfeit sites.

Someone claiming to be project support may then offer to reverse a wallet transaction or recover tokens for a fee.

That is a second warning sign. On-chain transfers usually cannot be canceled by a social-media support account.

Save the transaction hash, suspicious URL, and wallet prompt details. Report them through the project’s verified security channel if one exists.

Do not enter a recovery phrase into a page that promises to restore a vote, validate your wallet, or unlock a missing bonus.

The Difference Between Connecting, Signing, and Approving

These actions are often grouped together in casual advice, but they have different consequences. Understanding them prevents both panic and false reassurance.

A connection usually shares a public wallet address. It lets the site know which wallet is present and what on-chain assets it can see.

A signature can authenticate a message. Its safety depends on what the message says and how an application interprets it.

A transaction is an on-chain action. It may move assets, approve a spender, interact with a contract, or change a permission.

An approval can remain active after the browser tab closes. Disconnecting the website does not necessarily revoke that on-chain permission.

The wallet should show the requesting application and the precise action. If you cannot understand it, pause and seek independent explanation.

Do not let a page rush you with an expiring bonus. Any real governance vote should allow time to verify its proposal and contract address.

A wallet connected to a valuable portfolio deserves extra separation. Consider using a low-balance wallet for unfamiliar experiments.

Checks Before You Follow a Crypto Rewards Link

Open the project’s official website from a saved bookmark or its verified social profile. Look for the same vote announcement there.

Compare the entire domain, not just the project name somewhere in the address. Random strings can appear in genuine links, but they demand context.

Read the governance proposal itself. A real vote normally identifies the decision, eligibility, timing, and voting process.

Ask why selecting a date would require a wallet approval to spend tokens. The action requested by the wallet should match the action promised.

Look for consistent announcements across established channels. A single reply from a new account is not equivalent to a formal project notice.

Search the exact wording of the page. Repeated copy across unrelated projects can signal a reused template rather than coordinated official campaigns.

Do not assume an influencer’s repost proves a campaign is genuine. Compromised accounts, paid promotions, and copied screenshots can spread a bad link quickly.

Check the project’s announcement history too. A sudden vote with no proposal record or discussion may be an imitation of governance rather than governance itself.

When in doubt, ask a moderator in a channel you reached independently. Paste the suspicious URL as plain text only if that community permits reporting it.

Do not treat HTTPS as proof of affiliation. A scam page can encrypt its traffic just as a genuine page can.

Be careful with browser extensions claiming to “verify” a vote. An added extension may create another path to wallet compromise.

If a project truly offers a boost, there should be documentation explaining how it is calculated and who pays it. Vague promises need scrutiny.

What to Do if You Connected to a Fake Voting Page

The response depends on what you actually approved. A public-address connection is different from signing away token permissions or exposing a recovery phrase.

  1. Stop interacting with the page. Reject pending prompts and save the URL. Do not reconnect to test whether the reward appears.
  2. Check the wallet’s recent activity. Identify any signatures, token approvals, or transfers made after opening the page. Note the transaction hashes.
  3. Revoke suspicious approvals. Use the wallet’s built-in controls or a trusted approval manager reached independently. Disconnecting the site alone may leave permissions active.
  4. Move funds if the recovery phrase was exposed. Create a new wallet with a new phrase on a trusted device. Transfer remaining assets and retire the old wallet.
  5. Secure connected accounts. Change passwords if you typed them into related pages. Review exchange sessions, API keys, and withdrawal settings.
  6. Inspect the device if software was installed. Malwarebytes can scan for unwanted software; AdGuard can help block malicious web destinations. Neither reverses on-chain approvals.
  7. Report the evidence. Notify the real project through its verified channel and your national cybercrime service. Include the URL, timestamps, and transaction hashes.

Do not pay a “recovery agent” who contacts you privately. The FBI warns that supposed crypto recovery services can become another theft.

If no approval or signature occurred, the immediate financial risk may be lower. Still, review the connection and watch for targeted follow-up messages.

If funds already moved, contact any involved exchange promptly. Freezing or tracing may be possible in limited circumstances, but recovery is never guaranteed.

Frequently Asked Questions

Are xStocks and Pendle themselves scams?

No conclusion about the legitimate projects follows from this campaign. The reported pages copied their branding without authorization.

Reach the genuine project through its established website or verified account before acting on any reward notice.

Does connecting a wallet give the page control of my coins?

Usually not by itself. A connection normally reveals your public address and lets the page inspect on-chain holdings.

Danger arises when the site asks you to sign a harmful message, approve spending, or send a transaction.

What does a 1.25x voting boost mean here?

It was the promise used on many fake pages researchers found, not a verified reward from the impersonated projects.

The modest number helps the page sound credible. Verify any actual program through the project’s official documentation.

Can I fix a bad approval by disconnecting the website?

No. Disconnecting a site removes a browser relationship, but an on-chain token allowance may remain active.

Review and revoke suspicious permissions separately through your wallet or a trusted approval tool reached independently.

What if I only clicked Vote now?

Clicking the button exposed the wallet prompt. If you rejected it and signed nothing, there may be no token permission to revoke.

Check the wallet’s activity anyway. It is safer to confirm than to rely on memory of a fast sequence of popups.

Can stolen crypto be reversed?

Blockchain transfers generally cannot be undone by a wallet provider. Exchanges and investigators may sometimes help trace funds, without promising recovery.

Preserve transaction records, report quickly, and refuse anyone who demands a release fee or your recovery phrase.

The Bottom Line

The fake vote offers a small reward for a harmless-looking action, then changes the task to connecting and potentially authorizing a wallet.

Trust the project’s verified domain and the wallet’s permission details, not the copied design or countdown on a lookalike page.

10 Rules to Avoid Online Scams

Here are 10 practical safety rules to help you avoid malware, online shopping scams, crypto scams, and other online fraud. Each tip includes a quick “if you already got hit” action.

  1. Stop and verify before you click, log in, download, or pay.

    warning sign

    Most scams win by creating urgency. Verify using a trusted method: type the website address yourself, use the official app, or call a known number (not the one in the message).

    If you already clicked: close the page, do not enter passwords, and run a malware scan.

  2. Keep your operating system, browser, and apps updated.

    updates guide

    Updates patch security holes used by malware and malicious ads. Turn on automatic updates where possible.

    If you saw a scary “update now” pop-up: close it and update only through your device settings or the official app store.

  3. Use layered protection: antivirus plus an ad blocker.

    shield guide

    Antivirus helps block malware. An ad blocker reduces scam redirects, phishing pages, and malvertising.

    If your browser is acting weird: remove unknown extensions, reset the browser, then run a full scan.

  4. Install apps, software, and extensions only from official sources.

    install guide

    Avoid cracked software, “keygens,” and random downloads. During installs, choose Custom/Advanced and decline bundled offers you do not recognize.

    If you already installed something suspicious: uninstall it, restart, and scan again.

  5. Treat links and attachments as untrusted by default.

    cursor sign

    Phishing often impersonates delivery services, banks, and popular brands. If it is unexpected, do not open attachments or log in through the message.

    If you entered credentials: change the password immediately and enable 2FA.

  6. Shop safely: research the store, then pay with protection.

    trojan horse

    Be cautious with brand-new stores, “closing sale” stories, and prices that make no sense. Prefer credit cards or PayPal for dispute options. Avoid wire transfers, gift cards, and crypto payments.

    If you already paid: contact your card issuer or PayPal quickly to dispute the transaction.

  7. Crypto rule: never pay a “fee” to withdraw or recover money.

    lock sign

    Common patterns include fake profits, then “tax,” “gas,” or “verification” fees. Another is a “recovery agent” who demands upfront crypto.

    If you already sent crypto: stop paying, save evidence (wallet addresses, TXIDs, chats), and report the scam to the platform used.

  8. Secure your accounts with unique passwords and 2FA (start with email).

    lock sign

    Use a password manager and unique passwords for every account. Enable 2FA using an authenticator app when possible.

    If you suspect an account takeover: change passwords, sign out of all devices, and review recent logins and recovery settings.

  9. Back up important files and keep one backup offline.

    backup sign

    Backups protect you from ransomware and device failure. Keep at least one backup on an external drive that is not always connected.

    If you suspect infection: do not connect backup drives until the system is clean.

  10. If you think you are a victim: stop losses, document evidence, and escalate fast.

    warning sign

    Move quickly. Speed matters for disputes, account recovery, and limiting damage.

    • Stop payments and contact: do not send more money or respond to the scammer.
    • Call your bank or card issuer: block transactions, replace the card if needed, and start a dispute or chargeback.
    • Secure your email first: change the email password, enable 2FA, and remove unfamiliar recovery options.
    • Secure other accounts: change passwords, enable 2FA, and log out of all sessions.
    • Scan your device: remove suspicious apps or extensions, then run a full malware scan.
    • Save evidence: screenshots, emails, order pages, tracking pages, wallet addresses, TXIDs, and chat logs.
    • Report it: to the payment provider, marketplace, social platform, exchange, or wallet service involved.

These rules are intentionally simple. Most online losses happen when decisions are rushed. Slow down, verify independently, and use payment methods and account controls that give you recourse.

Comment on this post

Next

Hypevora.shop EXPOSED – Scam or Legit? What to Know