app[.]hyperliquid[.]global
“Login | Hyperliquid”
PhishDestroy has identified the domain app.hyperliquid.global as a potential brand impersonation threat targeting the cryptocurrency platform Hyperliquid. This domain hosts a fake login page designed to deceive users into submitting their credentials, which could be harvested for unauthorized access or malicious crypto draining activities. The main risk involves credential compromise that could lead to financial loss or account takeover.
Technical analysis reveals that app.hyperliquid.global resolves to the IP address 72.61.147.116 and uses an SSL certificate issued by ZeroSSL to create a seemingly legitimate connection. The page title is "Login | Hyperliquid," further contributing to the spoofing attempt. VirusTotal's current scan shows 0 detections out of 95 antivirus engines, indicating the domain has not yet been flagged as malicious by common security vendors. However, the domain is active and under investigation by threat analysts. There is no public data on the registrar or domain creation date provided, and no blocklist counts have been reported so far.
Users who have visited app.hyperliquid.global are strongly advised not to enter any login information or personal data. If credentials were submitted, immediate password changes on the official Hyperliquid platform and enabling two-factor authentication are recommended. Regular monitoring of account activity and reporting suspicious behavior to official support channels can help mitigate risks. Always verify URLs carefully and consult PhishDestroy or other threat intelligence sources for updated information before interacting with any site that mimics known brands like Hyperliquid.
Network Security Intelligence
| Detection System | Indicator | Verdict | Alert |
|---|---|---|---|
| DNS4EU | hyperfoundation.org |
malicious | Sinkholed |
Threat Response Pipeline
Public Blocklist Status
Stored Capture
Domain Intelligence
Technical detailsDNS, SSL SANs, timestamps
ICANN OVERSIGHT
Registration: hyperliquid.global
Accreditation and RAA context
Accreditation and RAA context
Registrar accreditation and DNS abuse obligations
For the registrable domain hyperliquid.global behind this subdomain, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Technologies · 5 identified
Popular CSS framework for responsive, mobile-first web development.
High-performance web server compatible with Apache configurations.
Free public CDN for open-source projects, serving files from npm and GitHub.
Third major version of HTTP protocol, built on QUIC for faster, more reliable connections.
VirusTotal Analysis
Site Performance Analysis
Google PageSpeed Insights — mobile performance audit of app.hyperliquid.global · checked Mar 25, 2026
Evidence & External Reports
PD-20260325-C29726 Recipient: abuse@hostinger.com Were You Affected by This Site?
If credentials, payment data, or files were exposed, report the incident immediately. Change affected passwords, revoke active sessions, and scan the device.
Report to Your Local Authorities
Select your country to get official cybercrime contacts, or create a complaint draft →.
Check Any Domain
Threat analysis using stored blocklist, WHOIS, DNS, and public scan evidence
Scan NowReport Phishing
Submit suspicious domains to our threat database — protect the community
ReportLive Threat Feed
Recent phishing reports and observed availability changes
MonitorStay Informed, Stay Safe
Monitor live threats or contest this listing if you believe it's a false positive