A new scam method is affecting cryptocurrency users through fake pop-ups that imitate the operation of digital wallets. The scheme was detailed by a developer and cybersecurity specialist known on X as NFT_Dreww, who warned that attackers are taking advantage of a common habit: accept signature requests without reviewing their origin. The scheme begins when the victim reaches a fraudulent site through social engineering, paid advertisements or misleading links on social networks. These pages exactly copy legitimate sites and simulate well-known campaigns, such as supposed airdrops. In one of the cases analyzed, the fake site imitated a page linked to Jupiter Exchangea Solana platform, although the offer was not real. The fraudulent site reproduces the normal flow: it invites you to “connect the wallet” and detects which wallets are installed in the browser. Here appears the critical point. Instead of activating the actual wallet extension, the site opens a new browser window that visually supplants popular wallets like MetaMask either Phantom. This fake window displays a web address and interface almost identical to the original, creating a feeling of legitimacy.
How does this type of scam that drains cryptocurrency wallets operate?
The screenshot below, taken from an explanatory video released by the developer, clearly illustrates how the deception operates when trying to connect a wallet, in this case Phantom.


From that moment on, if funds are available, the system moves forward with the signature request to empty the wallet. Many people fall because they do not check what they are signing. Simple details, like a Strange URL in address bar (for example, generic hosting used for testing) are key clues to detecting fraud.