Fake DeepSeek websites pose crypto theft threats

By Dat Nguyen   February 9, 2025 | 07:33 pm PT
Cybersecurity researchers have uncovered a widespread campaign involving at least 50 fake DeepSeek websites designed to steal user credentials, cryptocurrency, and personal information.

Researcher Dominic Alvieri has identified over 50 active fraudulent sites and more than a thousand suspicious domains, according to a report by security news outlet SecurityWeek.

These sites, such as deepseek-login[.]com, employ various tactics, from mimicking legitimate login pages to distributing cryptocurrency-draining software and promoting fake token sales.

Deepseek logo is seen in this illustration taken January 27, 2025. Photo by Reuters

Deepseek logo is seen in this illustration taken January 27, 2025. Photo by Reuters

While some sites are clearly amateurish, others are sophisticated and difficult to distinguish from the real DeepSeek website, with their quality increasing recently.

The rise in number of scam sites came as DeepSeek, a Chinese AI developer, made global headlines in recent weeks by offering a platform said to be similar to that of ChatGPT but with a fraction of the costs.

The platform had average of 22.2 million daily active users as of January, or 40% of ChatGPT’s user base.

Cybersecurity firm Cyble has confirmed reports of fraudulent DeepSeek sites asking for users’ crypto wallets, which will enable the attackers to steal their funds via QR codes.

"What we’re seeing with DeepSeek may not just be another wave of phishing sites, but a coordinated attack campaign that evolves in real-time," said Tzoor Cohen, head of cyber threat intelligence at digital impersonation protection firm Memcyco.

The lag in response times of traditional protection systems is being exploited by attackers to steal from users – often before the first reports even surface, he added.

 
 
go to top