# bittorrenttoken.info — SUSPICIOUS > bittorrenttoken.info mimics OKX in a brand impersonation scam. VirusTotal shows 0/95 detections so far. Check the full report. ## Summary PhishDestroy identifies bittorrenttoken.info as an active brand impersonation domain targeting OKX users, posing as a legitimate token promotion site. This domain was flagged after registering on March 17, 2026, and currently resolves to IP 188.114.97.3 via NICENIC INTERNATIONAL GROUP CO., LIMITED. VirusTotal scans return 0/95 detections despite clear signs of impersonation, highlighting the need for continued monitoring as the threat evolves. The threat involves a spoofed crypto-token webpage designed to trick visitors into connecting wallets or entering credentials under the guise of an official OKX airdrop or giveaway. The domain uses a Let’s Encrypt SSL certificate to appear trustworthy, a common tactic in phishing campaigns to evade browser warnings. Investigations show no current blocklist presence, emphasizing the importance of proactive detection as threat actors refine their infrastructure. If you visited bittorrenttoken.info, disconnect any connected wallets immediately and revoke permissions through your wallet settings. Do not enter any private keys, recovery phrases, or login credentials on the site. Clear browser cache and cookies related to the domain. Report suspicious activity to OKX and consider running a malware scan. Stay vigilant—new impersonation domains emerge daily. ## Threat Details - Verdict: SUSPICIOUS - Site status: unknown (HTTP ?) - Target brand: OKX ## Domain Intelligence - Registered: 2026-03-17 23:25:10 - Registrar: NICENIC INTERNATIONAL GROUP CO., LIMITED - IP: 188.114.97.3 ## Detection Status - VirusTotal: 0 vendors flagged - Google Safe Browsing: clean - Blocklists: 0 hits ## Evidence - Cloudflare Radar: https://radar.cloudflare.com/scan/c579277a-7092-4fbe-a404-1779b4577dc6 - PhishDestroy: https://phishdestroy.io/domain/bittorrenttoken.info/ - LLM endpoint: https://phishdestroy.io/domain/bittorrenttoken.info/llm.txt ## If You Visited This Site 1. Change any passwords you may have entered 2. Enable 2FA on all related accounts 3. Monitor your accounts for unauthorized activity 4. Report to: FBI IC3, Europol, local authorities --- Report by PhishDestroy | https://phishdestroy.io/domain/bittorrenttoken.info/ Last updated: 2026-03-23