polymarket-demo-cfx[.]pages[.]dev
“Polymarket Demo · Polygon Wallet”
Zusammenfassung der Beweislage
Analysis indicates that polymarket-demo-cfx.pages.dev is an active brand impersonation domain targeting Polymarket users by presenting a counterfeit interface referencing Polygon wallet authentication. The page title 'Polymarket Demo · Polygon Wallet' suggests a deceptive attempt to simulate legitimate Web3 onboarding flows and encourage wallet connection or credential submission. The infrastructure is consistent with phishing or crypto drainer campaigns designed to harvest seed phrases or authorize malicious transactions.
Technical telemetry shows the domain is flagged by 2/95 VirusTotal security vendors and appears on 3 security blocklists. It is registered via Cloudflare Pages infrastructure and resolves to IP 172.66.47.152 located in CA (Cloudflare, Inc.). The domain creation date is May 08, 2026 and it uses a Let's Encrypt / E8 SSL certificate. Additional threat intelligence reports blocking by PhishDestroy, MetaMask, and SEAL. The domain remains active at time of analysis, indicating ongoing exposure risk.
Users interacting with this domain face high risk of credential theft and unauthorized blockchain transaction signing. Any connection of a crypto wallet may expose assets to immediate draining through malicious smart contract approvals. If the site was visited, users should immediately disconnect wallets, revoke token approvals via trusted blockchain permission tools, and transfer assets to a newly secured wallet if compromise is suspected. Security teams should block the IP 172.66.47.152 and domain at network perimeter, monitor authentication attempts, and review logs for suspicious wallet interaction signatures. Continued monitoring is recommended due to active status and recent domain creation, which are consistent with rapidly deployed impersonation infrastructure.
Data Coverage
Pipeline zur Reaktion auf Sicherheitsbedrohungen
Blocklistenabdeckung
10 überwachte externe Feeds · gespeicherter Stand 12.08.2026
8 überwachte externe Feeds Kein Treffer
Domain-Intelligenz
Technische DetailsDNS, TLS-Namen und Zeitstempel
VirusTotal-Analyse
Wurden Sie von dieser Website betroffen?
Wenn Sie Kontoanmeldeinformationen, persönliche oder Zahlungsinformationen eingegeben oder eine Datei von dieser Domain heruntergeladen haben, ergreifen Sie sofort Maßnahmen. Nachfolgend finden Sie Ressourcen, die Ihnen helfen, den Vorfall zu melden und sich zu schützen.
Melden Sie sich bei Ihren örtlichen Behörden
Wählen Sie Ihr Land aus, um Offizielle Kontakte im Bereich Cyberkriminalität oder einen Beschwerdeentwurf erstellen → zu erhalten.
Jede beliebige Domain prüfen
Bedrohungsanalyse anhand gespeicherter Blocklisten, WHOIS, DNS und öffentlicher Scan-Beweise
Jetzt scannenPhishing melden
Melden Sie verdächtige Domains an unsere Bedrohungsdatenbank – schützen Sie die Community
MeldenEchtzeit-Bedrohungsfeed
Aktuelle Phishing-Meldungen und beobachtete Verfügbarkeitsänderungen
ÜberwachenBleiben Sie auf dem Laufenden, bleiben Sie sicher
Beobachten Sie aktuelle Bedrohungen oder legen Sie Widerspruch gegen diesen Eintrag ein, wenn Sie der Meinung sind, dass es sich um einen Fehlalarm handelt