← World Cup 2026 — Stake.com Impersonation Wallet Drainer Campaign1 decision on this page
Audit log
Every state-changing event for World Cup 2026 — Stake.com Impersonation Wallet Drainer Campaign: moderation decisions on community submissions, plus corrections and updates from the news pipeline. URL-based decisions are designed to carry three independent witnesses — the original source, an Internet Archive snapshot, and a Solana memo signed by our publicly-disclosed publisher key. Archive coverage is still being backfilled, so each decision below reports its own snapshot status rather than assuming one exists.
- #1publishby system:backfill2026-08-01 23:27:52ZScore: ? → ? (no score change)anchorpending
- chain
- ●—
- hash
EzoGdNdoPTvA…ZegaE3Q7sha256 → base58
verifying row…canonical bytes (23524 B) ▸
{"actor":"system:backfill","investigation_id":"6babaa9b-d31d-4a67-ab59-eb01c3e66489","kind":"publish","page_slug":"world-cup-2026-stake-com-impersonation-wallet-drainer-campaign","published_at":"2026-08-01T23:27:52.681Z","sequence_num":1,"snapshot":{"content_type":"investigation","entity_name":"World Cup 2026 — Stake.com Impersonation Wallet Drainer Campaign","sections":[{"content":"Forcepoint X-Labs publicly documented this coordinated multi-vector campaign in July 2026, identifying it as a deliberate exploitation of heightened public interest in the 2026 FIFA World Cup hosted across the United States, Canada, and Mexico. The campaign combines three distinct fraud typologies — crypto wallet draining, payment-card phishing via a typosquatted domain, and classic advance-fee fraud — under a single opportunistic umbrella. The common pattern across all three vectors, as described by Forcepoint, is to 'exploit high-interest events, borrow the credibility of a trusted brand and move fast before defenses catch up.' No specific threat actor group has been publicly attributed to this campaign as of the time of writing. The wallet drainer component is the highest-severity vector due to its use of Web3 wallet-connection mechanics that cause irreversible asset loss the moment a victim acts.","heading":"Campaign Overview and Threat Actor Profile","severity":"critical","sources":[{"credibility":2,"name":"World Cup 2026 Scams: Phishing, Crypto Drainers and Ticket Fraud — Forcepoint X-Labs","type":"research","url":"https://www.forcepoint.com/blog/x-labs/world-cup-2026-scams"}]},{"content":"The primary and most technically sophisticated attack vector begins with phishing emails sent from the domain web-stake.com, impersonating Stake.com — a well-known legitimate online crypto gambling platform that processes significant volumes of cryptocurrency. The email invites recipients to participate in a fabricated 'World Cup 2026 Token Farming' DeFi event, a lure specifically crafted to appeal to crypto-native users already familiar with Stake's genuine promotions.\n\nThe embedded link does not lead directly to the drainer. Instead it routes victims through a Vercel-hosted intermediary (documented as hxxps://ilvvtestetd[.]vercel[.]app/) before delivering them to the fraudulent landing page at hxxps://get[.]rpc-stake[.]com/farm. According to Forcepoint X-Labs, the use of Vercel is deliberate: 'As a legitimate and widely used development platform, Vercel carries a positive reputation score with many email security filters,' making the redirect harder to flag at the gateway level. Victims who connect their cryptocurrency wallets on the drainer landing page trigger irreversible asset-transfer transactions to attacker-controlled addresses.\n\nThis attack chain — phishing email → legitimate CDN/hosting redirect → wallet drainer landing page — is consistent with wallet drainer-as-a-service infrastructure documented by Blockaid and other security researchers throughout 2025 and 2026, where named drainer operations (including AngelFerno, Quark, and others) sell World Cup-specific attack packages to affiliates. The specific drainer kit in use for this campaign has not been publicly identified by name.\n\nThe domain web-stake.com is fraudulent and has no affiliation with the legitimate Stake.com platform operated by Medium Rare N.V. The legitimate Stake.com help center explicitly states that the platform will never request wallet connections, passwords, or credentials via unsolicited email.","heading":"Vector 1: Stake.com Impersonation Wallet Drainer (web-stake.com / rpc-stake.com)","severity":"critical","sources":[{"credibility":2,"name":"World Cup 2026 Scams: Phishing, Crypto Drainers and Ticket Fraud — Forcepoint X-Labs","type":"research","url":"https://www.forcepoint.com/blog/x-labs/world-cup-2026-scams"},{"credibility":2,"name":"Wallet Drainers and Investment Scams Impersonating SpaceX and the FIFA World Cup — Blockaid","type":"research","url":"https://www.blockaid.io/blog/wallet-drainers-and-investment-scams-impersonating-spacex-and-the-fifa-world-cup"},{"credibility":1,"name":"Recognizing and Reporting Phishing Attempts — Stake Help Center","type":"official","url":"https://help.stake.us/en/articles/8570860-recognizing-and-reporting-phishing-attempts"}]},{"content":"A second attack vector targets sports fans seeking World Cup match tickets rather than crypto users specifically. Phishing emails promoting '50% off World Cup tickets, expires tomorrow' employ urgency and scarcity messaging to drive clicks to the fraudulent domain seatgaek.com — a typosquatted version of the legitimate ticket marketplace SeatGeek.com (seatgeek.com), differing by a single transposed letter ('a' and 'e' swapped in the middle). Victims who attempt to purchase tickets on seatgaek.com submit payment card details to attacker-controlled infrastructure and receive no tickets in return. This vector broadens the campaign's victim pool significantly beyond crypto-native users to include any sports fan attempting to acquire access to the tournament. Cybercriminals exploiting the 2026 World Cup registered an estimated 1,100 suspicious domains in the lead-up to and during the tournament, according to reporting cited by Paubox, indicating a systematic and large-scale ticket fraud operation of which the seatgaek.com site is one documented example.","heading":"Vector 2: Typosquatted Ticket Phishing Site (seatgaek.com)","severity":"high","sources":[{"credibility":2,"name":"World Cup 2026 Scams: Phishing, Crypto Drainers and Ticket Fraud — Forcepoint X-Labs","type":"research","url":"https://www.forcepoint.com/blog/x-labs/world-cup-2026-scams"},{"credibility":2,"name":"Cybercriminals Exploit 2026 FIFA World Cup With Phishing, Fake Stores, and Ticket Scams — CyberSecurityNews","type":"news_article","url":"https://cybersecuritynews.com/cybercriminals-exploit-2026-fifa-world-cup-with-phishing/"},{"credibility":2,"name":"FIFA World Cup phishing wave hits 1,100 suspicious domains — Paubox","type":"research","url":"https://www.paubox.com/blog/fifa-world-cup-phishing-wave-hits-1100-suspicious-domains"}]},{"content":"A third vector involves classic advance-fee fraud (also known as 419 fraud) targeting the general public via unsolicited emails falsely claiming that recipients have won multi-million-dollar or multi-million-pound FIFA World Cup lottery prizes. Forcepoint X-Labs identified two separately distributed email variants. The first is attributed to contact addresses lulchevar@gmail.com and mrrichardwerner@gmail.com; the second uses fifa2026@atomicmail.io and ukhouse.ahe@yandex.com — all free personal email accounts with no affiliation with FIFA.\n\nPrize amounts across documented variants range widely. PCRisk's analysis of related lottery scam emails identified variants promising $500,000, $1,200,000, and $2,010,000 in fabricated winnings. MalwareTips documented a variant claiming $500,000, attributed to an alleged 'claims agent' using calvinharrison2000@gmail.com. Additional contact personas documented by PCRisk include 'Mr. Jason Sillman' (fwc26@cnlgroup.co.uk, WhatsApp: +447754834289) and 'Mr. Foster Grant' (foster.grant2025@gmail.com).\n\nAll variants follow the same playbook: emails request extensive personal information (full name, address, telephone number, occupation, and employer details) and ultimately demand upfront fee payments framed as taxes or processing charges. FIFA does not operate prize draws of any kind, and no legitimate lottery notifies winners via unsolicited email. The Federal Trade Commission estimates advance-fee fraud collectively costs victims approximately $3 million daily in the United States.","heading":"Vector 3: Advance-Fee Fraud — Alleged FIFA Lottery Winnings","severity":"high","sources":[{"credibility":2,"name":"World Cup 2026 Scams: Phishing, Crypto Drainers and Ticket Fraud — Forcepoint X-Labs","type":"research","url":"https://www.forcepoint.com/blog/x-labs/world-cup-2026-scams"},{"credibility":2,"name":"2026 FIFA World Cup Lottery Email Scam — Removal and Recovery Steps — PCRisk","type":"research","url":"https://www.pcrisk.com/removal-guides/30264-2026-fifa-world-cup-lottery-email-scam"},{"credibility":2,"name":"Don't Fall For The 2026 FIFA World Cup Lottery Winner Email Scam — MalwareTips","type":"research","url":"https://malwaretips.com/blogs/2026-fifa-world-cup-lottery-winner-email-scam/"},{"credibility":2,"name":"Scam Alert: FIFA World Cup Lottery Scams are Back in Business — Bitdefender","type":"research","url":"https://www.bitdefender.com/en-us/blog/hotforsecurity/scam-alert-fifa-world-cup-lottery-scams-are-back-in-business"}]},{"content":"The following indicators of compromise (IOCs) have been documented by Forcepoint X-Labs and corroborating researchers. All domains and email addresses should be considered malicious.\n\nMalicious domains: web-stake.com (phishing sender domain impersonating Stake.com); rpc-stake.com (wallet drainer infrastructure, specifically get.rpc-stake.com/farm as the drainer landing page); seatgaek.com (typosquatted ticket phishing domain impersonating SeatGeek). Intermediate redirect infrastructure: ilvvtestetd.vercel.app (Vercel-hosted redirect used to bypass email security filters — note that Vercel itself is a legitimate platform and the subdomain is attacker-controlled).\n\nMalicious email addresses associated with the advance-fee lottery vector: lulchevar@gmail.com, mrrichardwerner@gmail.com, fifa2026@atomicmail.io, ukhouse.ahe@yandex.com, calvinharrison2000@gmail.com, fwc26@cnlgroup.co.uk, foster.grant2025@gmail.com, foster.grant@mcusa-2026wc.org, maryannduff@cdfcomiami-usa.com.\n\nBroader World Cup-themed drainer infrastructure documented by Blockaid (not directly attributed to this specific campaign) includes: roobet-worldcup.vercel.app, worldcupvp.app, watchfifa2026.xyz, vote-worldcuponpump.com, and fifaworldc.com. These domains are consistent with commercialized drainer-as-a-service affiliate operations and may share underlying kit infrastructure with the web-stake.com campaign.","heading":"Technical Indicators of Compromise","severity":"critical","sources":[{"credibility":2,"name":"World Cup 2026 Scams: Phishing, Crypto Drainers and Ticket Fraud — Forcepoint X-Labs","type":"research","url":"https://www.forcepoint.com/blog/x-labs/world-cup-2026-scams"},{"credibility":2,"name":"Wallet Drainers and Investment Scams Impersonating SpaceX and the FIFA World Cup — Blockaid","type":"research","url":"https://www.blockaid.io/blog/wallet-drainers-and-investment-scams-impersonating-spacex-and-the-fifa-world-cup"}]},{"content":"This campaign is notable for its unusually broad potential victim pool relative to a typical crypto-only phishing campaign. The wallet drainer vector (web-stake.com) primarily targets crypto-native users already familiar with Stake.com and DeFi farming mechanics — a population predisposed to connecting wallets to web-based dApps. The typosquatted ticket vector (seatgaek.com) targets any sports fan seeking World Cup tickets regardless of crypto knowledge. The advance-fee lottery vector targets the general population via mass unsolicited email with no technical prerequisites for victimhood.\n\nWallet drainer attacks targeting the broader World Cup theme were detected across multiple blockchain platforms including Solana and EVM-compatible chains, and affected users of Phantom, Backpack, Solflare, OKX, and Coinbase wallets, according to Blockaid's research. The professionalized, commercialized nature of the underlying drainer infrastructure — where named operations sell World Cup-specific phishing packages to affiliates — suggests the campaign is likely to persist and expand throughout the duration of the 2026 tournament.\n\nTRM Labs tracked separate but related World Cup crypto fraud addresses and found total funds received across the initially identified scam addresses remained under USD 1,700 as of their reporting date, with some infrastructure still unconverted, suggesting many campaigns were identified before reaching full scale. However, TRM noted over USD 1.9 billion in total historical scam funds moved through bridges, underscoring the systemic laundering risk.","heading":"Victim Pool and Risk Scope","severity":"high","sources":[{"credibility":2,"name":"Tracking Crypto Scammers Ahead of the 2026 World Cup — TRM Labs","type":"research","url":"https://www.trmlabs.com/resources/blog/tracking-crypto-scammers-ahead-of-the-2026-world-cup"},{"credibility":2,"name":"Wallet Drainers and Investment Scams Impersonating SpaceX and the FIFA World Cup — Blockaid","type":"research","url":"https://www.blockaid.io/blog/wallet-drainers-and-investment-scams-impersonating-spacex-and-the-fifa-world-cup"},{"credibility":2,"name":"World Cup Scams Expose Web3 Gaming Wallet UX Gaps — CryptoDaily","type":"news_article","url":"https://cryptodaily.co.uk/2026/06/world-cup-fraud-web3-gaming-wallets-fan-safety-ux"}]},{"content":"The choice of Stake.com as the impersonated brand for the wallet drainer vector is not arbitrary. Stake.com (operated by Medium Rare N.V.) is one of the world's largest crypto gambling platforms and has a large base of users who regularly interact with crypto assets and DeFi-style promotions. The platform was itself the victim of a genuine $41 million hot wallet drain in September 2023, attributed by the FBI to the North Korean Lazarus Group, which drained approximately 9,620 ETH on Ethereum mainnet, 14.24 million MATIC on Polygon, and 82,650 BNB on BNB Chain. That high-profile incident established Stake.com as a recognizable name in the crypto security threat landscape.\n\nThe use of Stake.com's brand identity in this 2026 campaign allows attackers to target users who have an existing trust relationship with the platform and who may be conditioned to expect legitimate promotional communications about betting events tied to the World Cup. Stake.com's help center explicitly cautions users that the platform never requests credentials or wallet connections via unsolicited email, and urges users to verify sender domains carefully. This impersonation campaign has no affiliation with the legitimate Stake.com platform.","heading":"Context: Stake.com as a High-Value Impersonation Target","severity":"medium","sources":[{"credibility":1,"name":"Crypto casino Stake.com loses $41 million to hot wallet hackers — BleepingComputer","type":"news_article","url":"https://www.bleepingcomputer.com/news/security/crypto-casino-stakecom-loses-41-million-to-hot-wallet-hackers/"},{"credibility":2,"name":"Stake (online casino) — Wikipedia","type":"other","url":"https://en.wikipedia.org/wiki/Stake_(online_casino)"},{"credibility":1,"name":"Recognizing and Reporting Phishing Attempts — Stake Help Center","type":"official","url":"https://help.stake.us/en/articles/8570860-recognizing-and-reporting-phishing-attempts"}]},{"content":"Security researchers across Forcepoint, Blockaid, TRM Labs, and Kaspersky have published consistent protective guidance for users. For the wallet drainer vector: never connect a crypto wallet via a link received in an unsolicited email; always navigate directly to a platform's official domain rather than following embedded links; verify the sender domain carefully against the official platform domain (stake.com vs. web-stake.com); and treat any 'Token Farming' or DeFi promotional email received unsolicited as suspicious regardless of branding quality. For the ticket phishing vector: only purchase World Cup tickets through officially designated ticket channels published by FIFA directly; verify domain spelling character by character before entering payment information. For the advance-fee lottery vector: FIFA does not operate lottery or prize-draw programs of any kind; any unsolicited email claiming World Cup lottery winnings should be deleted without response; providing personal information in response to such emails creates risk of follow-on identity fraud independent of any financial loss.","heading":"Protective Guidance","severity":"low","sources":[{"credibility":2,"name":"World Cup 2026 Scams: Phishing, Crypto Drainers and Ticket Fraud — Forcepoint X-Labs","type":"research","url":"https://www.forcepoint.com/blog/x-labs/world-cup-2026-scams"},{"credibility":2,"name":"FIFA World Cup 2026 Ticket Scams: How to Spot Fake Tickets and QR Codes — Kaspersky","type":"research","url":"https://www.kaspersky.com/resource-center/preemptive-safety/fake-world-cup-2026-tickets-qr-codes"},{"credibility":2,"name":"World Cup 2026: how to avoid ticket scams and fake sites — Proton","type":"research","url":"https://proton.me/blog/world-cup-2026-scams-phishing"}]}],"sources_used":[{"credibility":2,"name":"World Cup 2026 Scams: Phishing, Crypto Drainers and Ticket Fraud — Forcepoint X-Labs","type":"research","url":"https://www.forcepoint.com/blog/x-labs/world-cup-2026-scams"},{"credibility":2,"name":"Wallet Drainers and Investment Scams Impersonating SpaceX and the FIFA World Cup — Blockaid","type":"research","url":"https://www.blockaid.io/blog/wallet-drainers-and-investment-scams-impersonating-spacex-and-the-fifa-world-cup"},{"credibility":2,"name":"Tracking Crypto Scammers Ahead of the 2026 World Cup — TRM Labs","type":"research","url":"https://www.trmlabs.com/resources/blog/tracking-crypto-scammers-ahead-of-the-2026-world-cup"},{"credibility":2,"name":"Cybercriminals Exploit 2026 FIFA World Cup With Phishing, Fake Stores, and Ticket Scams — CyberSecurityNews","type":"news_article","url":"https://cybersecuritynews.com/cybercriminals-exploit-2026-fifa-world-cup-with-phishing/"},{"credibility":1,"name":"FIFA World Cup 2026 Scams Are Already Live — The Hacker News","type":"news_article","url":"https://thehackernews.com/2026/06/fifa-world-cup-2026-scams-are-already.html"},{"credibility":2,"name":"2026 FIFA World Cup Lottery Email Scam — Removal and Recovery Steps — PCRisk","type":"research","url":"https://www.pcrisk.com/removal-guides/30264-2026-fifa-world-cup-lottery-email-scam"},{"credibility":2,"name":"Don't Fall For The 2026 FIFA World Cup Lottery Winner Email Scam — MalwareTips","type":"research","url":"https://malwaretips.com/blogs/2026-fifa-world-cup-lottery-winner-email-scam/"},{"credibility":2,"name":"Scam Alert: FIFA World Cup Lottery Scams are Back in Business — Bitdefender","type":"research","url":"https://www.bitdefender.com/en-us/blog/hotforsecurity/scam-alert-fifa-world-cup-lottery-scams-are-back-in-business"},{"credibility":2,"name":"FIFA World Cup phishing wave hits 1,100 suspicious domains — Paubox","type":"research","url":"https://www.paubox.com/blog/fifa-world-cup-phishing-wave-hits-1100-suspicious-domains"},{"credibility":1,"name":"FBI warns of fake FIFA World Cup 2026 ticket sites stealing fan data — Fox News","type":"news_article","url":"https://www.foxnews.com/tech/world-cup-ticket-scams-target-desperate-fans"},{"credibility":2,"name":"FIFA World Cup 2026 Ticket Scams: How to Spot Fake Tickets and QR Codes — Kaspersky","type":"research","url":"https://www.kaspersky.com/resource-center/preemptive-safety/fake-world-cup-2026-tickets-qr-codes"},{"credibility":2,"name":"World Cup 2026: how to avoid ticket scams and fake sites — Proton","type":"research","url":"https://proton.me/blog/world-cup-2026-scams-phishing"},{"credibility":1,"name":"Crypto casino Stake.com loses $41 million to hot wallet hackers — BleepingComputer","type":"news_article","url":"https://www.bleepingcomputer.com/news/security/crypto-casino-stakecom-loses-41-million-to-hot-wallet-hackers/"},{"credibility":1,"name":"Recognizing and Reporting Phishing Attempts — Stake Help Center","type":"official","url":"https://help.stake.us/en/articles/8570860-recognizing-and-reporting-phishing-attempts"},{"credibility":2,"name":"How Wallet Drainers are Mimicking FIFA 2026 Brand Identity — Coin Wallet","type":"research","url":"https://coin.space/how-wallet-drainers-are-mimicking-fifa-2026-brand-identity/"},{"credibility":2,"name":"World Cup Scams Expose Web3 Gaming Wallet UX Gaps — CryptoDaily","type":"news_article","url":"https://cryptodaily.co.uk/2026/06/world-cup-fraud-web3-gaming-wallets-fan-safety-ux"}],"summary":"An active three-vector phishing and fraud campaign exploiting FIFA World Cup 2026 excitement was publicly documented by Forcepoint X-Labs in July 2026. The primary and most technically sophisticated vector operates a crypto wallet drainer at get.rpc-stake.com that impersonates the legitimate Stake.com gambling and crypto platform via a fake 'Token Farming DeFi event,' funneling victims through a Vercel-hosted redirect to evade email security filters. Two auxiliary vectors target a broader, non-crypto audience: a typosquatted ticket-selling site (seatgaek.com impersonating SeatGeek) and advance-fee lottery fraud emails falsely claiming FIFA prize winnings. The campaigns are live as of July 2026.","timeline":[{"date":"2023-09-04","event":"Stake.com suffers a genuine $41 million hot wallet drain attributed by the FBI to North Korea's Lazarus Group, establishing the platform as a high-profile crypto brand and a credible impersonation target.","source":"BleepingComputer","source_url":"https://www.bleepingcomputer.com/news/security/crypto-casino-stakecom-loses-41-million-to-hot-wallet-hackers/"},{"date":"2026-01-01","event":"Early World Cup 2026 fraud infrastructure begins appearing. A Bitcoin address associated with a fixed-match betting scheme receives small amounts, per TRM Labs tracking data spanning January through May 2026.","source":"TRM Labs","source_url":"https://www.trmlabs.com/resources/blog/tracking-crypto-scammers-ahead-of-the-2026-world-cup"},{"date":"2026-04-01","event":"A Polygon address linked to a fake World Cup ticketing site receives approximately USD 1,562, primarily on this date, per TRM Labs blockchain analysis.","source":"TRM Labs","source_url":"https://www.trmlabs.com/resources/blog/tracking-crypto-scammers-ahead-of-the-2026-world-cup"},{"date":"2026-05-01","event":"First spike in World Cup-themed wallet drainer activity detected by Blockaid, coinciding with the tournament ticket rush period. Fake dApps include betting platforms, fan-voting pages, and match-streaming sites.","source":"Blockaid","source_url":"https://www.blockaid.io/blog/wallet-drainers-and-investment-scams-impersonating-spacex-and-the-fifa-world-cup"},{"date":"2026-06-01","event":"Second spike in World Cup drainer activity coinciding with tournament kickoff. Blockaid identifies a malicious $WCUP token dApp flagged in real time. Drainer operations selling World Cup-specific affiliate packages are active.","source":"Blockaid","source_url":"https://www.blockaid.io/blog/wallet-drainers-and-investment-scams-impersonating-spacex-and-the-fifa-world-cup"},{"date":"2026-06-01","event":"The Hacker News reports FIFA World Cup 2026 scams are live, including fake sites, banking malware, and stolen login credential campaigns targeting fans during the tournament.","source":"The Hacker News","source_url":"https://thehackernews.com/2026/06/fifa-world-cup-2026-scams-are-already.html"},{"date":"2026-07-01","event":"Forcepoint X-Labs publishes its documented analysis of the three-vector World Cup 2026 campaign including the Stake.com impersonation wallet drainer at web-stake.com/rpc-stake.com, the seatgaek.com ticket phishing domain, and the advance-fee lottery fraud emails. All three campaigns confirmed active.","source":"Forcepoint X-Labs","source_url":"https://www.forcepoint.com/blog/x-labs/world-cup-2026-scams"}]},"v":1}Verify offline (run on your own machine)python -m src.verify_decision ea3a80d8-eb96-45f0-b11b-e597c323ed3f
How verification works. The “Row integrity” check above is computed in your browser — your machine recomputes the SHA-256 of the canonical bytes and compares against the stored hash. No avoid.net server can fake that check. The “full verify” link goes one level deeper: your browser fetches the on-chain transaction from a Solana RPC node and confirms the same hash is in the memo. If you don’t want to trust either avoid.net or the public RPC, run the CLI verifier on your own machine —
python -m src.verify_decision <event_id>.