Notification and current-status evidence
The sent-report ledger records the first outgoing report at . A report was sent to the recorded registrar; contact details remain in Domain Intelligence. The latest stored availability evidence still shows the domain reachable; 6 months has elapsed since the first outgoing report.
ICANN RAA §3.18 describes registrar abuse-contact and handling obligations. This section records outgoing timestamps and later availability. It does not by itself prove receipt, acknowledgement, investigation, remediation, or contractual non-compliance.
app[.]hyperliquid-testnet[.]xyz
“56,500 | HYPE/USDC | Hyperliquid”
ملاحظة محفوظة
تباين العناوين المرصود
ملخص الأدلة
The domain app.hyperliquid-testnet.xyz has been identified as a confirmed brand impersonation phishing site, specifically targeting the Hyperliquid cryptocurrency platform. This threat is categorized as a crypto drainer, designed to trick users into revealing sensitive information or connecting their wallets, leading to potential asset theft. The domain is currently offline, but its recent activity and technical indicators suggest it was actively used to deceive victims.
Technical analysis reveals that the domain was created on February 21, 2026, and registered through Squarespace Domains II LLC. It resolves to the IP address 99.84.152.74 and its page title displayed "56,500 | HYPE/USDC | Hyperliquid," mimicking the legitimate Hyperliquid trading interface. According to VirusTotal, 2 out of 95 security vendors flagged this domain as malicious, and it appears on 1 security blocklist. The SSL certificate, issued by Amazon / Amazon RSA 2048 M04, is commonly used for legitimate services but here was leveraged for fraudulent purposes. These indicators collectively highlight a sophisticated attempt to impersonate the Hyperliquid brand and deceive users.
Given that the domain is now offline, the immediate risk to users is reduced, but PhishDestroy recommends remaining vigilant. Users should always verify the authenticity of any website claiming to be a cryptocurrency platform by checking official domains and enabling two-factor authentication. If you have interacted with this site, immediately revoke any permissions granted and transfer assets to a secure wallet. For ongoing protection, regularly consult PhishDestroy's database to stay informed about emerging phishing threats targeting the crypto community.
لقطة الأدلة المرسلة
- أُرسل
- سجلات الدفتر
- 1
- معرّف القضية
PD-20260126-3C51FB- ملف PDF
- دليل PDF
الأساس القانوني
النص الكامل للدليل
Acceptable Use Policy: The domain app.hyperliquid-testnet.xyz is engaged in phishing activities, which directly contravenes your AUP prohibiting illegal activities and fraud.
Terms of Service: The use of this domain for deceptive practices constitutes a violation of your TOS, which reserves the right to suspend or terminate services for such infractions.
Applicable Laws (US):
Computer Fraud and Abuse Act (CFAA) - 18 U.S.C. § 1030: This law prohibits unauthorized access to computers and fraudulent activities involving computers, which includes phishing schemes.
CAN-SPAM Act - 15 U.S.C. § 7701: This act addresses commercial email and prohibits deceptive practices in electronic communications, including phishing.
Regulatory Note: Failure to take immediate action against this domain may expose your organization to legal liability and regulatory scrutiny. Non-compliance with your own policies and applicable laws could result in significant penalties.
Data Coverage
مؤشرات الأمان
استخبارات أمن الشبكات
مسار الاستجابة للتهديدات Pipeline
تغطية قوائم الحظر
١٠ مصادر خارجية مراقبة · لقطة محفوظة 11/08/2026
لقطة محفوظة
معلومات النطاق
التفاصيل التقنيةDNS وأسماء TLS والطوابع الزمنية
ICANN OVERSIGHT
Registration: hyperliquid-testnet.xyz
الاعتماد وسياق RAA
الاعتماد وسياق RAA
Registrar accreditation and DNS abuse obligations
For the registrable domain hyperliquid-testnet.xyz behind this subdomain, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
تحليل VirusTotal
تحليل أداء الموقع
Google PageSpeed Insights — mobile performance audit of app.hyperliquid-testnet.xyz · checked Mar 2, 2026
هل تأثرت بهذا الموقع؟
إذا أدخلت بيانات اعتماد الحساب أو المعلومات الشخصية أو معلومات الدفع أو قمت بتنزيل ملف من هذا النطاق، فاتخذ إجراءً فوريًا. فيما يلي موارد لمساعدتك في الإبلاغ عن الحادث وحماية نفسك.
أبلغ السلطات المحلية
حدد بلدك للحصول على الاتصالات الرسمية المتعلقة بالجرائم الإلكترونية أو إنشاء مسودة شكوى →.
تحقق من أي نطاق
تحليل التهديدات باستخدام قائمة الحظر المخزنة، وWHOIS، وDNS، وأدلة الفحص العامة
امسح الآنالإبلاغ عن محاولة تصيد احتيالي
أرسل النطاقات المشبوهة إلى قاعدة بيانات التهديدات الخاصة بنا — ساهم في حماية المجتمع
إبلاغتحديثات فورية حول التهديدات
تقارير التصيد الاحتيالي الأخيرة وتغييرات التوفر الملحوظة
مراقبةابقَ على اطلاع، وابقَ آمنًا
راقب التهديدات في الوقت الفعلي أو اعترض على هذا الإدراج إذا كنت تعتقد أنه إنذار كاذب