Fake xStocks and Pendle Votes Lure Users to Wallet Permissions

Daniel Zimmermann
6 Min Read
A crypto wallet shaped as a ballot box beside a golden hook
A supposed rewards vote can lead toward a wallet permission request

A supposed vote on when crypto rewards should arrive is sending people to a wallet connection screen instead of a ballot. In an October 1 investigation, Malwarebytes researcher Stefan Dasic identified 70 websites impersonating projects including Kraken’s xStocks, Pendle and Firelight. Most promise a 1.25x reward boost for voting. These are copies, not campaigns run by the named projects. [1]

The important boundary comes after the click: connecting a wallet is not the same as authorizing someone to spend its tokens. A familiar wallet chooser can make the next request feel routine, but an approval or signature needs its own scrutiny.

A copied announcement makes the invented vote fit

The Firelight impersonation carries a genuine announcement about the protocol’s deposit cap alongside the invented reward proposal. The Pendle version adds a countdown; another copy, posing as NetNet, threatens to burn unclaimed tokens after 48 hours. Dasic also found repeated templates, identical wallet selectors and domains built from sitemu, random-looking characters and .xyz. Those similarities suggest shared infrastructure or a kit; they do not establish who operates it. [1]

The deception joins two different decisions. A visitor arrives to express a preference about a distribution date. The page then asks for access to a financial account. Copying a real announcement helps bridge that gap: the surrounding information looks current, so the invented action may seem to belong there too. A project’s logo and a genuine piece of news cannot authenticate a separate proposal.

The wallet list is part of the lure

Firelight copy with a wallet chooser and a sitemu domain in the address bar
The captured Firelight copy opens a wallet chooser instead of a ballot. This shows the connection lure, not an executed token approval. Source: Stefan Dasic / Malwarebytes Labs.

The captured Firelight copy shows the useful contradiction: the address belongs to the sitemu…[.]xyz cluster while the page presents Firelight branding and a list of recognizable wallets. The chooser shows what the visitor is being asked to open; it does not demonstrate that those providers endorse the page, that an approval was granted, or that funds were stolen.

This October report documents a newly enumerated cluster. The broader pattern appears in our guide to fake crypto vote rewards; the overlapping reward pitch alone does not prove the earlier examples and these 70 sites have the same operator.

Connection, spending approval and a signature are separate checks

A normal connection lets a site see a public wallet address and look up its holdings. A token approval is a separate permission for a contract to move a particular token on the owner’s behalf. MetaMask’s explanation distinguishes the requesting site, contract address and spending cap. A copied page’s promise of a voting bonus tells you nothing about whether that contract should receive access. [2]

Before confirming anything, compare the wallet’s actual request with the action you intended. A spending allowance or transfer is a different action from choosing a rewards date. An unfamiliar signature also deserves a stop and a check: some signatures authorize later transfers, while others are ordinary sign-in messages. Do not assume every signature is harmless because no immediate payment appears.

The investigation reports fake pages and the connection lure, not a verified victim count, loss total or completed theft on every domain. The practical lesson is to verify the proposal through the project’s established channels before reaching this permission stage.

Closing the page does not cancel an existing approval

If you only connected, close the site and remove its connection through your wallet’s trusted controls. If you approved token spending, review the token, network and authorized contract, then revoke suspicious allowances through the wallet provider’s documented flow or that network’s established block explorer. MetaMask notes that revocation is an on-chain transaction and requires a network fee. Disconnecting a site alone leaves token approvals in place. [3]

Keep transaction hashes and the domain if you need to investigate a request you signed. Revoking an allowance does not undo a completed transfer, and its scope should not be mistaken for a guarantee that every other authorization has disappeared. For the separate problem of being asked to move coins, our wallet-address verification guide explains the recipient checks.

A real-looking reward page can still ask for the wrong permission. Verify the proposal first, then judge the wallet request on what it authorizes—not on the bonus the page promises.

References

  1. Stefan Dasic. “Fake xStocks, Pendle, and other sites bait crypto users with rewards votes.” Malwarebytes Labs, October 1, 2026. Research report.
  2. MetaMask. “What is a token approval?” Help Center, accessed October 2, 2026. Token permissions.
  3. MetaMask. “How to revoke smart contract allowances/token approvals.” Help Center, accessed October 2, 2026. Revocation and disconnection.
Share This Article
With a strong background in consumer safety and fraud prevention, Daniel specializes in providing actionable tips and advice to users. His focus is on helping individuals understand the risks of interacting with fraudulent sites and services
Leave a Comment

AI Assistant

Hello! 👋 How can I help you today?