How Fake Staking Sites Work, and How to Spot One
A fake Flare staking site took $8.5M in eight days. How both fake staking models work, and nine checks before you stake.
Fake staking sites do not stake anything. They either take a deposit and run, or they get you to sign a permission that lets someone else empty your wallet — and the dashboard showing your rewards ticking up is a webpage, not a blockchain. In July 2026, Seoul police detailed a fake Flare Network staking site that had taken 3.4 million XRP, around $8.5 million, from 71 investors in eight days, according to CoinDesk. This guide covers both scam models, the specific checks that separate a real staking page from a copy, and what to do if you already connected.
The two business models behind fake staking sites
Fake staking splits into two mechanically different scams, and the warning signs differ.
| Model | How you lose the money | Typical tell |
|---|---|---|
| Deposit-and-run | You send funds to an address the operator controls; a fake dashboard shows growing "rewards" | Fixed monthly returns, "principal guaranteed," withdrawals that work for small amounts and stall on large ones |
| Connect-and-drain | You connect your wallet and sign what looks like a staking approval; a drainer contract moves the assets out | The site asks for a signature that does not match the action, or requests approval for tokens you were not staking |
The deposit model is an old investment fraud wearing crypto clothes. The drain model is technical: as security researchers at PCrisk describe the pattern, "connecting a digital wallet to this fake page signs a malicious contract that facilitates the cryptocurrency drainer," after which funds move out through automated transactions — and drainers prioritize the highest-value assets they find.
Nothing prevents one operation from running both. A site can take deposits from cautious visitors and drain the wallets of anyone who connects.
Anatomy of an $8.5M fake staking site
The Flare Network case is the clearest recent example of how much effort goes into making a fake staking site look real.
The operation ran for roughly eight days, from 16 to 23 October 2025, and impersonated Flare Network and its FXRP token through a lookalike domain, per CoinDesk's report on the Seoul Metropolitan Police investigation. Victims were promised 1.5% to 1.8% monthly returns with principal guaranteed, and were instructed to move XRP through overseas exchanges into wallets the operators controlled. Seventy-one investors lost around $119,000 each on average, according to Cryptonomist's account of the police findings.
What makes the case instructive is the credibility layer. The operators planted material across blogs, online news articles and Wikipedia, and ran YouTube videos featuring a paid actor posing as a project representative. Investigators executed 54 search and seizure warrants, arrested three suspects, and froze 17.3 billion won on overseas exchanges — while tracing 27.3 billion won, roughly $18.8 million, which is more than the confirmed losses and suggests victims who never came forward.
The lesson worth carrying: search results, news coverage and a Wikipedia entry are not verification. They are the part of the scam that costs the least to manufacture.
What you are actually signing on a drainer page
On the connect-and-drain version, the theft happens in a signature — not in a transfer you approve.
The mechanism attackers favour is the off-chain approval. Scam Sniffer's 2025 data found that Permit and Permit2 signatures accounted for 38% of thefts exceeding $1 million, with the year's single largest phishing loss reaching $6.5 million in September through a Permit-style signature. The reason they work is structural, as Scam Sniffer puts it: "Permit and Permit2 allow approvals without transfers, making them prone to misuse."
In practice that means the wallet popup does not look like a withdrawal. It looks like a message to sign, often labelled as a session or a staking authorization. Our explainer on token approvals covers what that permission actually grants — the short version is that a signature can hand over the right to move a token balance without moving anything at the moment you sign it, and our guide to dApp permissions covers what a connection request does and does not include.
The wider numbers are worth keeping in proportion. Scam Sniffer recorded $83.85 million lost across 106,106 victims from wallet-drainer phishing in 2025, down from roughly $500 million and more than 330,000 victims in 2024. Drainer losses fell year-over-year; the surviving cases got larger and better disguised — 11 incidents exceeded $1 million in 2025, against 30 in 2024. Chainalysis, measuring the wider scam economy rather than drainers specifically, puts confirmed on-chain scam revenue for 2025 at $14 billion and projects it above $17 billion, with average scam payment severity up 253% year-over-year.
Nine checks before you stake anywhere
Run these in order. The first three catch most fake staking sites in under a minute.
- Reach the site through a route you control. Type the domain or use a saved bookmark rather than a search ad, a DM link, or a QR code from a comment section.
- Read the domain character by character. The Flare impersonation used a domain built to survive a glance, not a read.
- Check the yield against the network. Legitimate staking pays what the network pays. A fixed monthly percentage that never varies is a promise no proof-of-stake chain makes.
- Treat "principal guaranteed" as disqualifying. Real staking carries slashing risk, price risk and unbonding periods — our staking guide names all three.
- Look at where the money goes. Being asked to send funds to an address, especially via an exchange withdrawal, means you are not staking — you are transferring ownership.
- Read the signature request, not the button. If the page says "stake" and the wallet asks for a token approval or a Permit signature, those are different actions.
- Check the token being approved. A staking page for one asset requesting approval over unrelated balances is a drainer.
- Discount the marketing layer entirely. Wikipedia entries, YouTube explainers, press coverage and audit badges are all reproducible by an operator with a budget.
- Test with a trivial amount first, from a wallet that holds nothing else. A working small withdrawal is not proof of legitimacy, but a failing one is proof of the opposite.
What a legitimate staking flow looks like
Real staking is unglamorous on purpose: a variable rate, a named protocol, an on-chain transaction, and no promises about your principal.
Staking inside Coin98 Super Wallet is a reasonable reference point for the shape of the thing. Per our documentation on Dynamic Rate Staking, you reach it through Discover → Services → Stake Master inside the app rather than through a link, and the rate is explicitly variable — the APR "can increase or decrease depending on how many tokens are currently staked in the pool." The same page names smart contract and protocol risk directly, and notes that token prices move while assets are staked.
That combination — in-app entry point, floating rate, stated risks — is the opposite of the fake staking pitch, which offers a fixed number and no downside. Neither guarantees a good outcome. Only one of them is describing something that exists.
If you already connected
Move in this order, and do the approval work before anything else.
- Disconnect the site. In Coin98 Super Wallet, our documentation on managing wallet connections walks through it: More → More Wallet Features → Manage Connection, select the wallet, tap the X beside the dApp, then confirm.
- Revoke the approvals. Disconnecting ends the session; it does not withdraw a token permission you already granted. Our guide to revoking wallet permissions covers the mechanics.
- Scan the wallet. Wallet Health runs a multi-point scan across eight categories including Approval, Connections and Interacted URL, and surfaces unrevoked approvals and risky dApp connections with an immediate fix.
- Move what is left to a clean wallet. Our incident documentation on what to do when a wallet is hacked recommends creating a new multichain wallet with a fresh seed phrase, transferring remaining tokens out quickly, and retiring the old wallet rather than reusing it. One caveat from the same page is worth repeating: if a sweeper script may be running on the compromised wallet, sending in more tokens just to cover gas tends to feed it.
- Document and report. Our immediate action guide suggests collecting transaction hashes, addresses, amounts and screenshots, then filing with your exchange or wallet provider and with authorities such as ic3.gov. This is not futile — in the Flare case, police froze 17.3 billion won held on overseas exchanges. Funds that reach a centralized venue can sometimes be frozen when reported quickly.
FAQ
How can I tell if a staking site is legitimate? Check the route you arrived by, the exact domain spelling, and whether the advertised return is fixed or variable. Legitimate staking pays a floating network rate and discloses slashing, price and unbonding risk. Any site offering a guaranteed monthly percentage with protected principal is describing something proof-of-stake networks do not do.
Can a fake staking site steal my crypto if I only connect my wallet? Yes, if you sign what it asks for. Connecting alone shares your address, but the theft happens when you approve a token permission or sign an off-chain message. Scam Sniffer found Permit and Permit2 signatures behind 38% of 2025's thefts above $1 million, precisely because they authorize transfers without looking like one.
What is a wallet drainer? A drainer is a contract and toolkit that automatically moves assets out of a wallet once it has permission. Security researchers describe the fake staking page as the delivery method: the page collects the signature, and the drainer executes transfers, typically prioritizing the highest-value tokens it can reach.
Are guaranteed staking returns ever real? Fixed-rate products do exist on centralized platforms, but those are lending arrangements with counterparty risk rather than network staking, and the platform itself can still fail. On-chain staking rewards vary with network participation. The Flare impersonation offered 1.5%–1.8% monthly with principal guaranteed, which is the shape of a sales pitch rather than the shape of staking.
A site had a Wikipedia page and news coverage — is that verification? No. In the Flare case, operators planted material on blogs, news sites and Wikipedia, and hired an actor to appear as a project representative on YouTube. Media presence measures budget, not legitimacy.
Is staking through a wallet safer than through a website? It removes one failure mode — you are not relying on having reached the correct domain. It does not remove smart contract or protocol risk, which our staking documentation names directly. The safer habit is entering staking through an app you already trust rather than through a link you received.
The takeaway
Fake staking sites succeed because they sell a number that real staking cannot produce: a fixed return with no downside. Everything else — the interface, the Wikipedia entry, the paid spokesperson, the growing balance on the dashboard — is set dressing around that one impossible promise. The checks that catch them are unglamorous: arrive by a route you control, read the domain, compare the yield to what the network actually pays, and read the signature rather than the button. If you stake from inside Coin98 Super Wallet, you skip the domain problem entirely, and Wallet Health will flag the approvals a bad page left behind.
Last updated: August 2026