World Cup 2026 — Stake.com Impersonation Wallet Drainer Campaign
Summary
An active three-vector phishing and fraud campaign exploiting FIFA World Cup 2026 excitement was publicly documented by Forcepoint X-Labs in July 2026. The primary and most technically sophisticated vector operates a crypto wallet drainer at get.rpc-stake.com that impersonates the legitimate Stake.com gambling and crypto platform via a fake 'Token Farming DeFi event,' funneling victims through a Vercel-hosted redirect to evade email security filters. Two auxiliary vectors target a broader, non-crypto audience: a typosquatted ticket-selling site (seatgaek.com impersonating SeatGeek) and advance-fee lottery fraud emails falsely claiming FIFA prize winnings. The campaigns are live as of July 2026.
Connected Entities
1 entities · 10 linked investigationsTimeline(7 events)
2023-09-04
Stake.com suffers a genuine $41 million hot wallet drain attributed by the FBI to North Korea's Lazarus Group, establishing the platform as a high-profile crypto brand and a credible impersonation target.
BleepingComputer2026-01-01
Early World Cup 2026 fraud infrastructure begins appearing. A Bitcoin address associated with a fixed-match betting scheme receives small amounts, per TRM Labs tracking data spanning January through May 2026.
TRM Labs2026-04-01
A Polygon address linked to a fake World Cup ticketing site receives approximately USD 1,562, primarily on this date, per TRM Labs blockchain analysis.
TRM Labs2026-05-01
First spike in World Cup-themed wallet drainer activity detected by Blockaid, coinciding with the tournament ticket rush period. Fake dApps include betting platforms, fan-voting pages, and match-streaming sites.
Blockaid2026-06-01
Second spike in World Cup drainer activity coinciding with tournament kickoff. Blockaid identifies a malicious $WCUP token dApp flagged in real time. Drainer operations selling World Cup-specific affiliate packages are active.
Blockaid2026-06-01
The Hacker News reports FIFA World Cup 2026 scams are live, including fake sites, banking malware, and stolen login credential campaigns targeting fans during the tournament.
The Hacker News2026-07-01
Forcepoint X-Labs publishes its documented analysis of the three-vector World Cup 2026 campaign including the Stake.com impersonation wallet drainer at web-stake.com/rpc-stake.com, the seatgaek.com ticket phishing domain, and the advance-fee lottery fraud emails. All three campaigns confirmed active.
Forcepoint X-LabsDecision Log
- #1publish⛓ pending8/1/2026, 11:27:52 PMhash: EzoGdNdoPTvAKMp64cFf57Dix75xoFVfcjgaZegaE3Q7
15 of 16 cited source URLs have an Internet Archive snapshot.
model: claude-sonnet-4-6
generated: 8/1/2026, 11:27:41 PM
last updated: 8/2/2026, 5:16:07 PM
avoid.net — verified advice for a post-truth world