Fake Crypto Project Sites Use “Rewards Vote” Pages to Phish Wallet Connections
What Happened — Researchers identified 70 counterfeit websites that mimic legitimate crypto projects (e.g., xStocks, Pendle, Zama). Each site invites visitors to “vote” on a rewards‑distribution date, promising a 1.25× boost. Clicking the “Vote now” button launches a wallet‑connection prompt that can be used to harvest wallet addresses and later request token‑spending permissions.
Why It Matters for Trust & Control Assurance
- The campaign exploits the same social‑engineering tactics that continuous security‑awareness programs are designed to detect and mitigate.
- Demonstrates the need for verifiable, auditable training records and phishing‑simulation evidence to satisfy control‑monitoring requirements.
- Highlights the importance of documenting user‑awareness controls as part of a broader control‑assurance framework.
Who Is Affected – Crypto investors, DeFi platforms, token‑issuers, and any organization that promotes wallet connections on public‑facing sites.
Recommended Actions – Review and update your security‑awareness curriculum to include crypto‑phishing scenarios; deploy phishing‑simulation tools; enforce multi‑factor verification for wallet‑connection requests; continuously monitor for brand‑impersonation domains. Source: Malwarebytes Labs
Technical Notes – Attack vector: phishing via fraudulent web pages; no known CVE; data type targeted: cryptocurrency wallet addresses and token balances. Source: Malwarebytes Labs