Restaking & Liquid-Staking (LST/LRT) Scams
Fake liquid-staking and restaking platforms, look-alike protocol clones, and "points" or airdrop-farming sites promise outsized restaked yields — then drain a wallet the moment it connects and approves a token spend.
Last reviewed: 27 July 2026
What this scam is
A restaking or liquid-staking scam is any con that rides the hype around liquid-staking tokens (LSTs) and liquid-restaking tokens (LRTs) — the idea that a staked asset can be represented by a tradable token and then "restaked" again to earn additional layered yield. The legitimate version of this is a real, complex corner of crypto; the scams imitate it. They take a few recurring shapes. Some are entirely fake platforms and tokens advertising restaked returns far above anything the real protocols pay. Some are look-alike clones of genuine restaking protocols, sitting on domains one character or one lookalike-letter away from the real one. And a large branch are "points" or airdrop-farming sites that promise early-user rewards for staking or restaking through them. Across all of them, the payload is the same: the site asks you to connect your wallet and approve a transaction, and that approval — not a deposit — is what hands your funds to the attacker. The distinction that matters most is that here you are almost never scammed out of a payment you send; you are scammed out of a permission you grant.
How it works
The lure arrives where crypto users already are: search ads on a protocol's name, promoted social posts, replies under real project announcements, airdrop-tracker listings, and messages hyping a "points campaign" that is ending soon. The link leads to a site that looks like a real staking or restaking dashboard — often a near-pixel-perfect clone of a genuine protocol, on a domain built from a swapped letter, an extra word, or a different top-level domain. It shows a connect-wallet button and inflated APYs or a points balance you can "claim". When you connect and click stake, restake, or claim, the transaction presented is not a stake at all: it is a token-approval or permit signature granting the site's contract permission to move your tokens, or a signature that hands over an entire asset. A wallet-drainer contract executes the moment you sign, sweeping the approved tokens — and often everything else it was pre-authorised to touch — in one or more transactions. Some drainers wait, so the loss appears minutes or days later. Points and airdrop-farming variants add urgency ("snapshot tonight") to push signing without reading, and clone sites lean on the real brand's reputation so nothing feels off until the wallet is empty.
Why this scam works
Real restaking is genuinely confusing, which is the scam's cover: layered yields, wrapped tokens, points systems, and multi-step approvals are all normal here, so a request to sign an unusual-looking transaction does not stand out the way it would elsewhere. The audience is primed for high returns and for racing to be early, and points and airdrop framing turns that into fear of missing a snapshot. Clone domains defeat the one check most people rely on — recognising the brand — because the brand is exactly what has been copied. And the mechanism itself is quiet: connecting a wallet and approving a token feel harmless, cost almost nothing, and produce no immediate warning, so the victim often has no sense of danger until funds are already gone. The habit of clicking through wallet pop-ups makes the fatal signature routine.
Common red flags
- Restaking or liquid-staking yields far above what the established protocols pay
- A domain that is almost, but not exactly, the real protocol's — a swapped letter, extra word, or different top-level domain
- A 'stake', 'restake', or 'claim' button that produces a token-approval, permit, or transfer signature instead of a deposit
- Urgency around a points 'snapshot' or airdrop deadline pushing you to sign quickly
- A site reached through an ad, reply, or DM rather than an official channel
- Requests to approve unlimited spending or to sign a message you don't understand
- A brand-new project or token with heavy promotion but no verifiable contract or documentation
Sanitized example messages
Illustrative, sanitized examples. Personal details are replaced with placeholders such as [phone number] and [fake link].
Restaking campaign live: earn layered rewards + 3x points. Snapshot closes tonight — connect and restake before it ends.
You have unclaimed LRT points from the early-access program. Claim now: app-restake-rewards[.]xyz
Official migration required: connect your wallet to re-stake your LSTs on our new contract before the old one is deprecated.
DM: saw you're staking — our new restaking vault is paying way above the main protocols, early users get the biggest airdrop allocation.
How to verify before you act
Verify the destination before you ever connect, because after you sign it is usually too late. Reach real protocols only through links you already trust — a bookmark, the project's verified social profile, or a well-known aggregator — never through an ad, a DM, or a reply, and read the domain character by character. Confirm the contract address against the protocol's official documentation before interacting, and be sceptical of any yield or points offer that beats the real protocols by a wide margin. Most importantly, read what your wallet is actually asking you to sign: an unlimited token approval, a "permit", or a signature that transfers an asset is not the same as staking, and a hardware wallet plus a transaction-simulation or approval-checking tool will show you the difference. Test unfamiliar sites with a fresh wallet holding almost nothing first. When in doubt, stop — a genuine campaign will still be there after you check.
Payment methods used
- Wallet approval signatures
- Cryptocurrency
- Token permits
Who is usually targeted
- DeFi and staking users
- Airdrop and points farmers
- New crypto investors
- Holders of large token balances
What to do immediately
- Move any remaining funds to a new, uncompromised wallet immediately — assume the old one is fully exposed
- Revoke the malicious token approvals using an approval-checker tool, but treat revocation as secondary to moving funds out
- Record the scam site's URL, the contract and wallet addresses, and the transaction hashes before anything disappears
- Report the address and site to the impersonated protocol, your wallet provider, and block-explorer/scam-registry services
- Report the fraud to your national fraud service and any crypto-crime reporting channel available to you
- Warn others in the protocol's real community channels so the clone and drainer are flagged
How to prevent it
- Reach staking and restaking sites only through your own bookmarks or a project's verified channels — never through ads, DMs, or reply links
- Read the domain character by character; clone sites live on lookalike spellings and different top-level domains
- Confirm the contract address against official documentation before connecting or signing anything
- Treat outsized 'restaked' APYs or urgent points/airdrop snapshots as bait, not opportunity
- Read every wallet prompt: an unlimited approval, a permit, or a transfer signature is not the same as staking
- Use a hardware wallet and a transaction-simulation or approval-checking tool, and revoke stale token approvals regularly
Evidence to preserve
- The scam site's exact URL and screenshots, showing the lookalike domain
- The malicious contract address, the drainer's wallet address, and every transaction hash
- Screenshots of the wallet prompts you were asked to sign, including approvals and permits
- The message, ad, or post that led you to the site, with the account or link that shared it
Where to report it
- Action Fraud (UK) — UK national fraud & cybercrime reporting centre
- FTC ReportFraud (US) — US Federal Trade Commission fraud reports
- FBI IC3 (US) — US Internet Crime Complaint Center
- Scamwatch (Australia) — Australian competition & consumer reporting
- Your bank's fraud line — Use the number on the back of your card or in your banking app — never a number the caller gives you
Always verify reporting routes and emergency contacts on the official government or agency website for your country.
Frequently asked questions
How is this different from a normal staking or yield scam?
A generic staking-yield scam usually persuades you to deposit funds into a platform that then refuses to pay out. Restaking and liquid-staking scams more often take your money through a wallet approval or signature, not a deposit: the moment you connect and 'stake' or 'claim', you authorise a drainer contract to move your tokens. They also lean heavily on cloning real restaking protocols and their points and airdrop campaigns, because that specific hype is what gives an unusual signing request its cover.
I only connected my wallet — am I safe if I didn't send anything?
Connecting alone typically only lets a site see your address, which is low-risk. The danger is what you sign afterwards. If you approved a token, signed a 'permit', or authorised a transfer, the attacker may be able to move funds even though you never 'sent' anything. If you signed anything at all on a site you now doubt, treat the wallet as compromised: move remaining assets to a fresh wallet and revoke the approvals. If you only connected and closed the tab, you are most likely fine.
How do I know a restaking site or contract is the real one?
Do not trust the design, the brand, or the domain at a glance — all three are copied. Reach the protocol only through a link you already trust, such as a bookmark or its verified social profile, and read the domain letter by letter. Then confirm the contract address against the project's official documentation before you interact. Be sceptical of any yield or points offer well above the established protocols. A hardware wallet and a transaction-simulation tool let you see what you are really signing before you commit.