70 Fake Rewards Vote Sites Target Pendle, xStocks Users
Published October 5, 2026, 04:36 UTC. Based on research Malwarebytes published on October 1, 2026.
Security firm Malwarebytes says it has found 70 websites impersonating crypto projects that ask visitors to "vote" on the date of an upcoming rewards distribution. According to the firm, the vote is fake, and the Vote now button opens a wallet connection prompt. That prompt is the first step toward requests that could trick users into giving the attackers access to their tokens.
Which brands are being copied
Malwarebytes listed xStocks from Kraken, Pendle, Zama, Kinetiq, Yield Basis and Firelight among the brands being copied, along with smaller platforms Umia, Keeta and NetNet. None of the pages is affiliated with the projects it imitates.
The firm said the copies closely match the real sites, down to logos, menus and colours. Most offer a small, believable reward: vote and get a "1.25x boost" when rewards are paid out. Some vary the pitch. The Pendle copy adds fake dates and a countdown, the Keeta copy promises points, and the NetNet copy warns that unclaimed tokens will be burned after 48 hours.
Malwarebytes said the targets appear to have been chosen deliberately. Several held a token launch, airdrop or public sale in the past year, or run points programmes, so their users are used to hearing about claims and allocations.
How the theft works
Connecting a wallet on its own only shares the wallet's address, Malwarebytes noted, and does not give a site permission to spend tokens. The danger comes next: in wallet-draining scams, a page may follow up with a request to sign a message or approve a transaction. A malicious approval or signature can let an attacker move tokens without further confirmation, and blockchain transactions generally cannot be reversed.
Signs of a single operation
The researchers believe one operator or phishing kit is behind the campaign. Every domain they listed follows the same pattern: "sitemu" plus a random-looking string on the .xyz domain. The same template text, including writing the boost as "1,25x" with a comma, appears across different brands, and the wallet window is identical on every site.
How to protect yourself
Malwarebytes recommends checking the address bar rather than the design, and going to a project's official site or established social accounts directly instead of following links. Voting should never require approving token spending, so reject any request that mentions approvals, permits or transfers. If you have already signed something, disconnecting is not enough: review and revoke approvals with your wallet's approval tools. If you think your recovery phrase was exposed, move funds to a new wallet.
For more warning signs, see our explainer on how to spot a crypto scam.
This article is news reporting and is not investment advice.
Sources
- Malwarebytes, Fake xStocks, Pendle, and other sites bait crypto users with rewards votes (Oct. 1, 2026; includes full list of indicator domains)
MABOnChain Daily Brief
The key crypto and markets stories in one short, plain-language email. Free. Unsubscribe any time.
Prefer chat? Join us on Telegram
Keep reading
Ledger Phishing: Fake Google Ads Steal Recovery Phrases
Zscaler says fraudulent Google ads under a verified advertiser sent Ledger users through Google-hosted pages to a fake setup that steals recovery phrases.
Belgium Flags 51 Scam Platforms; BaFin Warns on Crypto Site
Belgium's FSMA added 51 fraudulent trading platforms to its warning list, and Germany's BaFin warned about btcx(.)investments under its crypto law.
Strategy Buys 334 BTC; Holdings Reach 848,000
Strategy bought 334 bitcoin from Oct. 1 to 4 for about $28.7 million. Holdings are now 848,000 BTC, bought for about $63.97 billion.
Illinois Agrees to Seek Crypto Tax Delay to July 2027
Illinois officials and two crypto groups jointly asked a court to push the state's 0.2% digital asset tax from Jan. 1 to July 1, 2027. A judge must still approve.



