MetaMask “Launchpad” phishing on Vercel
A hosted site impersonates MetaMask and instructs victims to "restore" a wallet and import a seed phrase, keystore, or private key. It was promoted in Discord DMs pretending to be Hyperliquid support. This page documents technical IOCs for takedowns and public awareness — never submit real credentials to test it.
Phishing host (IOCs — report, do not visit casually)
metamask-launchpad.vercel.app
How the scam works
- Attackers DM victims using Hyperliquid-themed display names (e.g. "Hyperliquid Server Chat," "Support," etc.).
- They invent a deposit or wallet issue and send a link to the fake "MetaMask launchpad" with steps to restore / import a wallet.
- The phishing
connect.htmlpage uses HTML forms that POST stolen data to a third-party form mailer — not on-chain logic — so victims lose full wallet access immediately. - A separate deposit address may be given in parallel for ETH/USDT; on-chain tracing is separate from the phishing site itself.
Technical IOCs (passive review)
- Primary URL:
https://metamask-launchpad.vercel.app/→connect.html(harvest page) - Post-submit redirect:
/access/point/barcode-generated.html(fake confirmation; HTTrack mirror comments reference older hosts such asfixuserwallet.vercel.appanddapperconnect.live) - Exfiltration: forms POST to
formsubmit.coendpoints tied to throwaway Gmail addresses — report to FormSubmit and Google abuse; do not engage. - Landing page: cloned MetaMask Webflow marketing content; CTAs relabeled as "Restore Account" pointing to the harvester.
Evidence (screenshots)
Discord context and URL embed preview from the investigation archive (click to enlarge).
Reporting & takedowns
- Vercel — abuse reporting for phishing on
vercel.appsubdomains. - FormSubmit / email provider — abuse for credential collection endpoints.
- Discord — Trust & Safety with user IDs and message links from exports.
- MetaMask / Consensys — phishing reports for brand misuse.
What To Do If You've Been Scammed
1. Report to Authorities
- • FBI IC3: ic3.gov (Internet Crime Complaint Center)
- • FTC: reportfraud.ftc.gov
- • Local law enforcement
2. Report Wallet Addresses
- • Chainabuse: chainabuse.com
- • Bitcoin Abuse: bitcoinabuse.com
- • Report to exchanges (Binance, Coinbase, Kraken, etc.)
3. Report the Discord Account
Report the impersonator account to Discord Trust & Safety with screenshots of the conversation and the fake username.
4. Document Everything
Save all messages, transaction records, wallet addresses, and screenshots. This evidence is crucial for any investigation.
5. Warn Others
Share this page to help prevent others from falling victim to this scam.
Related Scam Operations
This scam uses identical methodology to other known operations
OxyCapitals
$54,000+ stolen
MirrorExp
$30,000+ stolen
TruCopy
$30,000+ stolen (8 chains)
BridgeStocks
$35,389 stolen (TAKEN DOWN)
EverrexTrade
Under Investigation
AffluenceAura
$0 stolen (abandoned)
Pattern Match: These scams use Discord impersonation, fake trading platforms, and shared infrastructure. They may be operated by the same criminal network.