Home › Intelligence › Brief
BREACH BRIEF🟠 High ThreatIntel

Fake Crypto Project Sites Use “Rewards Vote” Pages to Phish Wallet Connections

Researchers uncovered 70 counterfeit crypto‑project sites that lure users with fake rewards‑vote offers. Clicking the vote button opens a wallet‑connection prompt that can be used to harvest addresses and later request token‑spending permissions, posing a high risk of token theft. This underscores the need for documented security‑awareness controls in audit readiness programs.

LiveThreat™ Intelligence · 📅 October 02, 2026· 📰 malwarebytes.com
🟠
Severity
High
TI
Type
ThreatIntel
🎯
Confidence
High
🏢
Affected
3 sector(s)
✅
Actions
4 recommended
📰
Source
malwarebytes.com

Fake Crypto Project Sites Use “Rewards Vote” Pages to Phish Wallet Connections

What Happened — Researchers identified 70 counterfeit websites that mimic legitimate crypto projects (e.g., xStocks, Pendle, Zama). Each site invites visitors to “vote” on a rewards‑distribution date, promising a 1.25× boost. Clicking the “Vote now” button launches a wallet‑connection prompt that can be used to harvest wallet addresses and later request token‑spending permissions.

Why It Matters for Trust & Control Assurance

  • The campaign exploits the same social‑engineering tactics that continuous security‑awareness programs are designed to detect and mitigate.
  • Demonstrates the need for verifiable, auditable training records and phishing‑simulation evidence to satisfy control‑monitoring requirements.
  • Highlights the importance of documenting user‑awareness controls as part of a broader control‑assurance framework.

Who Is Affected – Crypto investors, DeFi platforms, token‑issuers, and any organization that promotes wallet connections on public‑facing sites.

Recommended Actions – Review and update your security‑awareness curriculum to include crypto‑phishing scenarios; deploy phishing‑simulation tools; enforce multi‑factor verification for wallet‑connection requests; continuously monitor for brand‑impersonation domains. Source: Malwarebytes Labs

Technical Notes – Attack vector: phishing via fraudulent web pages; no known CVE; data type targeted: cryptocurrency wallet addresses and token balances. Source: Malwarebytes Labs

📰 Original Source
https://www.malwarebytes.com/blog/threat-intel/2026/10/fake-xstocks-pendle-and-other-sites-bait-crypto-users-with-rewards-votes ↗

This LiveThreat Intelligence Brief is an independent analysis. Read the original reporting at the link above.

From the Verisq platform · Security Awareness

Phishing and social engineering are a people-and-policy problem.

The Verisq AI Trust Operations platform pairs Security Awareness Training with policy adoption tracking, so human-risk controls are documented and audit-ready.

Explore the Verisq AI Trust Operations platform →