A phishing site mimicking Pudgy Penguins' Pudgy World game forged 11 crypto wallet unlock screens within a week of launch. The post Fake “Pudgy World” Site LuresA phishing site mimicking Pudgy Penguins' Pudgy World game forged 11 crypto wallet unlock screens within a week of launch. The post Fake “Pudgy World” Site Lures

Fake “Pudgy World” Site Lures Gamers Into Handing Over Crypto Wallet Passwords

2026/03/23 13:33
3 min read
For feedback or concerns regarding this content, please contact us at crypto.news@mexc.com
  • Malwarebytes researchers discovered a phishing site impersonating Pudgy Penguins’ new Pudgy World game, deploying 11 wallet-specific unlock screen forgeries covering Ethereum, Solana, and multi-chain wallets.
  • The fake site at pudgypengu-gamegifts[.]live tricks hardware wallet users into typing seed phrases through a “manual option” fallback when the spoofed connection flow fails.
  • Pudgy Penguins has now been targeted by phishing campaigns twice since December 2024, as FBI data shows phishing complaints exceeded 193,000 in 2024 with losses topping US$70 million.

A phishing campaign targeting players of Pudgy Penguins’ Pudgy World game has been identified days after the title’s launch on March 10, using a fake website to steal cryptocurrency wallet credentials.

Cybersecurity firm Malwarebytes said the site mimics legitimate wallet connection flows used for in-game items and digital collectibles. 

Hosted at pudgypengu-gamegifts[.]live, the page includes 11 tailored wallet interfaces designed to imitate different providers, indicating a coordinated and resource-intensive setup.

The practical consequence of all this is that automated scanning tools are likely to rate the initial page as benign, because on their infrastructure, it behaves like one. The malicious functionality never loads unless the attacker’s server decides the visitor is worth targeting.

Stefan Dasic, Malwarebytes Labs.

Related: US Senate Eyes April Vote on Landmark Crypto Market Structure Bill

No public response has been issued by Pudgy Penguins or Igloo Inc.

Hardware Wallet Trap

The attack focuses on extracting seed phrases, particularly from hardware wallet users. When the spoofed connection process fails, users are redirected to a manual input option that requests recovery credentials, which are then captured by the attackers.

The site also includes evasion mechanisms to avoid detection. It checks for virtual machines, automated analysis tools, and other research environments. 

If such conditions are detected, the malicious components do not load, limiting exposure to security investigators.

This is not the first phishing campaign linked to Pudgy Penguins, though. In December 2024, a separate operation used malicious Google Ads and embedded scripts to identify crypto wallets before redirecting users to fraudulent pages.

The Pudgy Penguins NFT collection, managed by Igloo Inc, has declined significantly in value. Its floor price has fallen 88.3% from 36.33 ETH in December 2024 to 4.10 ETH, or about US$8.5K (AU$12K).

Phishing remains a persistent risk across crypto platforms (and basically everywhere on the internet). FBI data for 2024 recorded 193,407 phishing and spoofing incidents, with reported losses exceeding US$70 million (AU$107 million).

Related: Kalshi Slams Arizona Charges as ‘Overstep’ in Prediction Market Showdown

The post Fake “Pudgy World” Site Lures Gamers Into Handing Over Crypto Wallet Passwords appeared first on Crypto News Australia.

Market Opportunity
SQUID MEME Logo
SQUID MEME Price(GAME)
$35,9773
$35,9773$35,9773
-4,19%
USD
SQUID MEME (GAME) Live Price Chart
Disclaimer: The articles reposted on this site are sourced from public platforms and are provided for informational purposes only. They do not necessarily reflect the views of MEXC. All rights remain with the original authors. If you believe any content infringes on third-party rights, please contact crypto.news@mexc.com for removal. MEXC makes no guarantees regarding the accuracy, completeness, or timeliness of the content and is not responsible for any actions taken based on the information provided. The content does not constitute financial, legal, or other professional advice, nor should it be considered a recommendation or endorsement by MEXC.

You May Also Like

Supported by hike speculation and PMIs – Danske Bank

Supported by hike speculation and PMIs – Danske Bank

The post Supported by hike speculation and PMIs – Danske Bank appeared on BitcoinEthereumNews.com. Danske Research Team points out that the Euro was the second-
Share
BitcoinEthereumNews2026/03/23 15:59
The geopolitics of anti-corruption as global advisory firms face debarment in the Horn of Africa

The geopolitics of anti-corruption as global advisory firms face debarment in the Horn of Africa

The World Bank’s debarment of PwC and EY for fraud in Ethiopia and Somalia has lifted the veil on the fragility of the Western development model, creating a strategic
Share
Theexchange2026/03/23 16:33
BitGo wins BaFIN nod to offer regulated crypto trading in Europe

BitGo wins BaFIN nod to offer regulated crypto trading in Europe

                                                                               BitGo’s move creates further competition in a burgeoning European crypto market that is expected to generate $26 billion revenue this year, according to one estimate.                     BitGo, a digital asset infrastructure company with more than $100 billion in assets under custody, has received an extension of its license from Germany’s Federal Financial Supervisory Authority (BaFin), enabling it to offer crypto services to European investors. The company said its local subsidiary, BitGo Europe, can now provide custody, staking, transfer, and trading services. Institutional clients will also have access to an over-the-counter (OTC) trading desk and multiple liquidity venues.The extension builds on BitGo’s previous Markets-in-Crypto-Assets (MiCA) license, also issued by BaFIN, and adds trading to the existing custody, transfer and staking services. BitGo acquired its initial MiCA license in May 2025, which allowed it to offer certain services to traditional institutions and crypto native companies in the European Union.Read more
Share
Coinstats2025/09/18 06:02