Scammers are taking advantage of the festive moods and scams are ramping up to try and lure users into bogus websites promising rewards.
The bait is very simple — users who have used MetaMask after 2019 supposedly are eligible for “rewards”.
The threat actors leverage social media, email spam, discord, telegram, fake conversations on reddit between “investors”, “lucky users” who just claimed the rewards and impatient users who are happy they didn’t “miss their chance”. Those are all fake and the goal is to get users to visitm the scam sites.
Remember MetaMask is only at metamask.io
Scam tweet promising reward — link to wallet drainer
Scam tweet promising reward — link to wallet drainer
Scam tweet promising reward — link to wallet drainer
Scam As usual there is a false sense of urgency and FOMO triggers:
Instead of getting any rewards users get drained immediately after visiting the bogus sites and sigining a malicious transaction.
Once a malicious given domain gets flagged the cyber criminals just switch to another one, without even changing the redirect one linked in the scam posts.
Scam site — Wallet drainer.
The scammers use intermediate redirect domains before landing the users on the final scam page.
⚠ SCAM SITE
metamask-redirect.com - redirects to:
metamaskcoin.io
themasktoken.io
metamasktokens.io
metamaskcoin.io
⚠ SCAM SITE ⚠
metamask-redirects.com - redirects to:
maskbymetamask.com
themask.claims
As usual the phishing scam domains and hosting are registered and paid for with BTC as a payment method by dubious registrar and web hosting “companies”, who happily accept dirty money from repeat-offender cyber criminals and turn a blind eye to abuse. Or act upon the abuse only after a third party alerts them, which gives a pretty big window of opportunity to the scammers.
Scam twitter accounts pushing the fake advertisements (just a few, there are many more)
- twitter.com/PelbyBTC
- twitter.com/0xSez
- twitter.com/0xJLMark
- x.com/Lminhui1/status/1742690805138256303?s=20
- x.com/sigrlamiETH/status/1742760906642100692?s=20
- x.com/EverSupreme7SOL/status/1742755154036670772?s=20
- x.com/Jimmy_eth51/status/1742702135077212213?s=20
- x.com/DuckyEth5i/status/1742769379463295461?s=20
- x.com/ParkerDarianETH/status/1742768285631049952?s=20
- x.com/AaronChao2/status/1742683493786845528?s=20
- x.com/TupcioSOL/status/1742680728188473829?s=20
- x.com/PRSDWGMYjLBpmUQ/status/1742766334750896493?s=20
- x.com/ChrystRevel/status/1742815867908301018?s=20
- x.com/EmmanuelAngelC2/status/1742783087535116528?s=20
- x.com/VGranina/status/1742821342347505759?s=20
- x.com/BesufkadWEB3/status/1742877381944283504?s=20
- x.com/0xUtkuu/status/1742868134036709818?s=20
- x.com/egetchesNFT/status/1742862595126870121?s=20
- x.com/_fearanphoist/status/1742897959677604017?s=20
- x.com/HimesHub/status/1743001576682184718?s=20
- x.com/sgary4/status/1743047211414360447?s=20
Stay safe!