MalwareBytes Alert: Counterfeit Pudgy Penguins Scam Site

"MalwareBytes Issues Warning on Fake Pudgy Penguins Site Scam"

In Brief

  • Cybercriminals have created a fake Pudgy Penguins’ Pudgy World game website, attempting to steal cryptocurrency wallet credentials.
  • The phishing site pudgypengu-gamegifts[.]live mimics legitimate wallet interfaces to deceive users, especially newcomers.
  • With phishing scams causing significant financial losses in 2024, users are urged to only access official sites and carefully verify all URLs.

Phishing Alert Issued for Pudgy World Browser Game

A new cybersecurity alert has been issued by Malwarebytes Labs concerning a phishing website that is posing as the Pudgy World browser game, specifically targeting users’ cryptocurrency wallet passwords. The deceptive website, recognized as pudgypengu-gamegifts[.]live, features counterfeit wallet interfaces that prompt users to input their secure information. Stefan Dasic, a senior malware research engineer at Malwarebytes, described the methods used by the phishing site, stating, “The phishing site abuses that step: When a visitor selects their wallet on this fake site, it shows what appears to be that wallet’s own unlock screen. To the user, it looks for all the world like the real crypto wallet software they already trust.”

Rising Concern Over Crypto-Related Scams

The Incident of this phishing site comes amid a growing concern over scams related to cryptocurrency. The FBI’s Internet Crime Complaint Center (IC3) reported over 193,407 complaints related to phishing and spoofing in 2024, with financial losses topping $70 million. Pudgy World game, linked to the popular NFT brand Pudgy Penguins, necessitates players linking their cryptocurrency wallets, presenting an opportunity that scammers are quick to exploit, primarily targeting inexperienced users.

Details on Pudgy Penguins and Pudgy World

Pudgy Penguins, having been acquired by CEO Luca Netz in 2022, transitioned from merely an NFT collection to a comprehensive consumer brand featuring retail products and games. Despite this expansion and recent success, the brand’s market value witnessed a decline from its peak in December 2024.

Recommendations for Users

Acknowledging the risk, Malwarebytes has strenuously recommended that users engage only with verified and official websites. They advise users to utilize trusted bookmarks for navigation and to avoid any questionable links from sources such as social media or direct messages. Users are also urged to recognize that legitimate cryptocurrency wallet interactions should not prompt password entry on embedded web pages. If users have inadvertently entered their credentials into a suspicious site, it is imperative to change their wallet passwords immediately and consider relocating their funds to a new wallet as a safety measure.

In this era of sophisticated digital scams, staying vigilant and adhering to recommended security measures remains crucial for safeguarding digital assets.