bafybeifl2mbkqcf3f3qw5a5kub74oowhqni3kor55v7d7if3gtlc5hady4.ipfs.dweb[.]link
Forensic brief
PhishDestroy has identified the domain bafybeifl2mbkqcf3f3qw5a5kub74oowhqni3kor55v7d7if3gtlc5hady4.ipfs.dweb.link as a medium-risk generic phishing threat. The domain was used to impersonate Onyx Protocol security notifications, misleading users into believing they needed to verify their accounts via a fraudulent page titled "2024 ONYXPROTOCOL SECURITY COMPROMISE: Check If You're Affected | Revoke.cash." Technical analysis reveals that the domain, registered in 2017 through CSC Corporate Domains, Inc., resolved to IP address 209.94.90.3 before being taken offline. It had a low trust score of 20/100 on Scamadviser, was detected by multiple security vendors, and appeared on four separate blocklists, all indicating suspicious activity consistent with phishing infrastructure hosted on decentralized IPFS gateways. Currently, the domain is offline, mitigating immediate risk. However, its past activity underlines the importance of vigilance against deceptive domains leveraging decentralized web services. PhishDestroy recommends blocking its associated IP and monitoring for any revived usage of similar IPFS-linked phishing sites in the future.
Threat response pipeline
Cloudflare Radar
VirusTotal
Forensic Evidence CollectionEvidence capture
Domain Intelligence
CSC Corporate Domains, Inc.
Technical details
Public blocklist status
Technologies
Technologies · 2 identified
VirusTotal consensus
Aggregated detection across 95 security vendors.
Evidence & external reports
Were you affected by this site?
Were You Affected?
Report to your local authorities
Email template — registrar abuse
tldsupport@cscinfo.com
Registrar: CSC Corporate Domains, Inc. Case: PD-
Embed this report
About this report
About this report: bafybeifl2mbkqcf3f3qw5a5kub74oowhqni3kor55v7d7if3gtlc5hady4.ipfs.dweb.link
This domain security report is maintained by PhishDestroy's automated threat-intelligence pipeline. Our system continuously monitors this domain across 95 security vendors on VirusTotal and 2 public blocklists.
The site displays a page titled “2024 ONYXPROTOCOL SECURITY COMPROMISE: Check If You're Affected | Revoke.cash”.
bafybeifl2mbkqcf3f3qw5a5kub74oowhqni3kor55v7d7if3gtlc5hady4.ipfs.dweb.link has been flagged by 9 security vendors as of May 17, 2026.
If you believe this listing is inaccurate, you can submit an appeal. For more information about our methodology, visit our FAQ page.