claims-hyperliquid[.]foundation
“Un momento…”
The domain claims-hyperliquid.foundation was identified as a brand impersonation phishing threat, specifically targeting the Foundation brand. While no drainer kit was explicitly detected, the domain's design and purpose strongly suggest credential harvesting or other fraudulent activities. The page title 'Un momento…' is typical of phishing landing pages that attempt to mimic legitimate login or verification processes.
Technical indicators provide a clear picture of the threat. VirusTotal flagged the domain with a score of 1 out of 95 security vendors, indicating low detection coverage at the time of analysis. The domain is listed on one security blocklist. It was registered on November 13, 2025, through PDR Ltd. d/b/a PublicDomainRegistry.com, and resolves to IP address 188.114.97.3. No SSL certificate was present, which is a common red flag for phishing sites. The domain's creation date is very recent, aligning with typical phishing domain lifecycles.
As of the latest check, the domain has been taken offline, reducing immediate risk. However, the low detection rate on VirusTotal suggests that similar domains may evade security filters. Users are advised to remain vigilant against unsolicited communications referencing Foundation-branded services. Always verify URLs directly through official channels and avoid clicking on links in emails or messages. Check the full report for detailed analysis and updates.
Threat Response Pipeline
Public Blocklist Status
Stored Capture
Domain Intelligence
Technical detailsDNS, SSL SANs, timestamps
ICANN OVERSIGHT
Accreditation and RAA context
Accreditation and RAA context
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
VirusTotal Analysis
Evidence & External Reports
Were You Affected by This Site?
If credentials, payment data, or files were exposed, report the incident immediately. Change affected passwords, revoke active sessions, and scan the device.
Report to Your Local Authorities
Select your country to get official cybercrime contacts, or create a complaint draft →.
Check Any Domain
Threat analysis using stored blocklist, WHOIS, DNS, and public scan evidence
Scan NowReport Phishing
Submit suspicious domains to our threat database — protect the community
ReportLive Threat Feed
Recent phishing reports and observed availability changes
MonitorStay Informed, Stay Safe
Monitor live threats or contest this listing if you believe it's a false positive