MALICIOUS — CRITICAL
exlimit[.]exchange
PhishDestroy identifies exlimit.exchange as an active crypto credential-stealing site running since January 29, 2026.
- VirusTotal
- 17/91
- Blocklists
- 2 · MetaMask, SEAL
- Verfügbarkeit
- Getarnt · erreichbar · HTTP 308
Do not enter credentials, seed phrases, payment details, or personal information on this domain.
Jump to section
exlimit.exchange — Getarnt · erreichbar (HTTP 308). Betrugstyp: Fake Exchange. Zusammenfassung der Beweislage: VirusTotal 17/91 (ADMINUSLabs, alphaMountain.ai, Bfore.Ai PreCrime, BitDefender, Chong Lua Dao); 2 external blocklist matches (MetaMask, SEAL); cloaking observed; PhishDestroy score 100/100. Registrar: Name.com.
Die ausführliche Analyse von PhishDestroy AI bleibt auf Englisch, damit der ursprüngliche forensische Bericht unverändert bleibt.
Evidence Analysis
PhishDestroy identifies exlimit.exchange as an active crypto credential-stealing site running since January 29, 2026. The domain advertises itself as a new exchange, but its real purpose is to trick visitors into connecting crypto wallets and signing malicious transactions that drain funds. Independent testing shows only 2 out of 95 VirusTotal security engines currently detect the threat, leaving most antivirus tools blind to the danger. WHOIS records reveal the domain was registered through Name.com, Inc. and resolves to the IP address 216.150.16.65. A Let’s Encrypt SSL certificate gives the site a deceptively trustworthy appearance, but SSL alone does not guarantee safety. If you visited exlimit.exchange or entered any wallet credentials, immediately disconnect any crypto wallets, revoke any signed permissions through your wallet’s “Connected Apps” or “Authorization” menu, and move remaining assets to a clean wallet on a different device. Scan your computer with updated antivirus software and consider rotating all passwords used on suspicious sites. Block the domain at your network level and report the URL to your local cybercrime unit to help protect others.
Datenabdeckung12 recorded checks
Pipeline zur Reaktion auf Sicherheitsbedrohungen
Status der öffentlichen Sperrliste
Gespeicherte Aufnahme
Domain-Intelligenz
Technische DetailsDNS, SSL-SANs, Zeitstempel
ICANN OVERSIGHT
Akkreditierung und RAA-Kontext
Akkreditierung und RAA-Kontext
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
VirusTotal-Analyse
Website-Performanceanalyse
Google PageSpeed Insights — mobile performance audit of exlimit.exchange · checked Apr 10, 2026
Nachweise und externe BerichteIndependent lookups and source reports
Victim safety and official reportingImmediate actions and verified reporting channels
Wenn Sie Kontoanmeldeinformationen, persönliche oder Zahlungsinformationen eingegeben oder eine Datei von dieser Domain heruntergeladen haben, ergreifen Sie sofort Maßnahmen. Nachfolgend finden Sie Ressourcen, die Ihnen helfen, den Vorfall zu melden und sich zu schützen.
Melden Sie sich bei Ihren örtlichen Behörden
Wählen Sie Ihr Land aus, um Offizielle Kontakte im Bereich Cyberkriminalität oder einen Beschwerdeentwurf erstellen → zu erhalten.