bdxn-sushi[.]cfd
“Um momento…”
The domain bdxn-sushi.cfd has been identified as a brand impersonation threat specifically targeting the decentralized exchange SushiSwap. This phishing domain attempts to trick users into believing they are interacting with legitimate SushiSwap services, potentially leading to credential theft or wallet compromise. No specific drainer kit was identified in this campaign, but the domain's structure and page title "Um momento…" suggest a fraudulent login or transaction approval flow.
Technical analysis reveals that only 2 out of 95 security vendors on VirusTotal flagged this domain, indicating a low detection rate that could allow it to bypass some security filters. The domain was registered on February 21, 2026, and resolves to IP address 172.67.160.198, which is associated with Cloudflare. The SSL certificate issued is WE1, and the domain currently appears on 4 security blocklists. Despite being taken offline, the domain's recent creation and low VT score highlight the importance of proactive monitoring.
As of the latest update, bdxn-sushi.cfd is offline, meaning the immediate threat has been neutralized. However, users should remain vigilant as similar domains may reappear. PhishDestroy recommends that SushiSwap users always verify URLs carefully, enable two-factor authentication, and avoid entering sensitive information on sites with suspicious domain names. If you have interacted with this domain, change your passwords and revoke any token approvals immediately.
Threat Response Pipeline
Public Blocklist Status
Stored Capture
Domain Intelligence
Technical detailsDNS, SSL SANs, timestamps
SHORTDOT ZONE · PUBLIC EVIDENCE
.cfd
ShortDot zone evidence
ShortDot zone evidence
The linked repository preserves daily zone observations across seven ShortDot-operated TLDs, including registration volume and abuse-related indicators. This registry context is supporting background and is not an independent detection for the domain in this report.
Forensic Intelligence
VirusTotal Analysis
Evidence & External Reports
Were You Affected by This Site?
If credentials, payment data, or files were exposed, report the incident immediately. Change affected passwords, revoke active sessions, and scan the device.
Report to Your Local Authorities
Select your country to get official cybercrime contacts, or create a complaint draft →.
Check Any Domain
Threat analysis using stored blocklist, WHOIS, DNS, and public scan evidence
Scan NowReport Phishing
Submit suspicious domains to our threat database — protect the community
ReportLive Threat Feed
Recent phishing reports and observed availability changes
MonitorStay Informed, Stay Safe
Monitor live threats or contest this listing if you believe it's a false positive