Popup drains cryptocurrency wallets

Foto del autor

By Berto R

A new scam method is affecting cryptocurrency users through fake pop-ups that imitate the operation of digital wallets.

The scheme was detailed by a developer and cybersecurity specialist known on X as NFT_Dreww, who warned that attackers are taking advantage of a common habit: accept signature requests without reviewing their origin.

The scheme begins when the victim reaches a fraudulent site through social engineering, paid advertisements or misleading links on social networks. These pages exactly copy legitimate sites and simulate known campaigns, such as alleged airdrops.

In one of the cases analyzed, the fake site imitated a page linked to Jupiter Exchangea Solana platform, although the offer was not real.

The fraudulent site reproduces the normal flow: it invites you to “connect the wallet” and detects which wallets are installed in the browser. Here appears the critical point.

Instead of activating the actual wallet extension, the site opens a new browser window that visually surpasses popular wallets like MetaMask o Phantom. This fake window displays a web address and interface almost identical to the original, creating a feeling of legitimacy.

How does this type of scam that drains cryptocurrency wallets operate?

The screenshot below, taken from an explanatory video released by the developer, clearly illustrates how the deception operates when trying to connect a wallet, in this case Phantom.

Interface of the researcher who detected fraud with pop-up windows of fake wallets.
Hackers build fake pop-ups that drain users’ wallets. Source: NFT_Dreww/X.

In the center there is a pop-up window that appears to be Phantom, but actually opens as a separate browser tab and not as the legitimate wallet extension.

The left red arrow points a web address outside the official domainone of the main warning signs.

On the right, in parallel, the authentic Phantom window appears requesting the password, which allows the scam site to overlay its own fake popup and prepare the malicious signature request that can lead to the draining of the wallet.

On the other hand, according to the researcher, when he wanted to connect MetaMask to the fraudulent site, since that wallet did not have funds, the pop-up window rejected the connection, inviting him to use another wallet.

Screenshot of a video posted by an investigator about a cryptocurrency wallet scam. Screenshot of a video posted by an investigator about a cryptocurrency wallet scam.
Since the developer emptied his MetaMask account, he was unable to connect it. Source: NFT_Dreww/X.

The researcher clarified that the fraudulent site cannot know if a wallet has cryptocurrencies before a person connects it. First, it only detects which wallet is installed in the browser and, only when the user accepts the connection, obtains information about the account.

From that moment on, if funds are available, the system moves forward with the signature request to empty the wallet.

Many people fall because they do not check what they are signing. Simple details, like a Strange URL in address bar (for example, generic accommodations used for testing) are key clues to detect fraud.

Deja un comentario