🚨 Phishing Alert: kaspa-wallet[.]io 🚨
This morning,
@cohengiladh brought an interesting URL to my attention: kaspa-wallet[.]io. Strange, I don’t recall ever seeing this URL, but I often have to check myself because new stuff is popping up in the
$kas community every day.
Curious and slightly suspicious, I performed a quick WHOIS and DNS lookup.
Immediately, red flags began to appear…
To solidify my concerns, I compared this to
wallet.kaspanet.io, a legitimate URL I’ve used countless times before. The differences were clear. Something was wrong here.
Time to investigate.
At first glance, kaspa-wallet[.]io looked visually identical to the genuine Kaspa wallet page. Seamless to the casual eye. However, one crucial difference stood out: the primary function of this site was to encourage users to restore their wallets by entering their 12-word seed phrase. dodgy.
Attempting any other function dumped you back at the legitimate
wallet.kaspanet.io site. Classic phishing technique. Users, confused by the strange behaviour, would re-enter their credentials on the genuine site, not realising their seed phrase was already compromised.
Diving into the page’s code made everything painfully clear:
- Upon entering your seed phrase, JS sends it silently via POST to "https://fonts.up.railway[.]app/api/t1/image"
After successfully stealing the seed phrase, it redirects users to
wallet.kaspanet.io to mask the theft.
I verified this by sending a test request with dummy data via CURL-ing this endpoint and It immediately responded with:
{"status":true,"message":"sent"}
This means the backend is actively receiving and storing stolen seed phrases.
Actions I’ve taken so far:
-Reported to the domain registrar (Sarek)
-Reported to the hosting provider (Vercel)
Now, the backend of this phishing scam is hosted at Railway (
@Railway) , and unfortunately, I can’t submit a phishing report directly without an account.
@Railway please immediately suspend: fonts.up.railway[.]app
Concerningly, this website has also gamed Google SEO rankings and it’s now appearing on the first page of results for “Kaspa Wallet,” often the 4th or 5th result...
This is all the more reason that we need to swiftly remove this site before more unsuspecting victims are affected.
If you would like to help:
- Please report this to the domain registrar here:
sarek.fi/abuse/
- Please report this to the hosting provider here:
vercel.com/abuse
-Please report this to the backend hosting here:
@Railway
If the above is too technical for you, please a share of this post is more than enough to raise awareness for these type of scams.
Protect yourself:
- Always double check you’re using the correct URL
- Be wary of search results and sponsored links
- Bookmark official crypto wallet URLs