cryptox[.]exchange
“CryptoX.Exchange — Anonymous Crypto Exchange (No-KYC), Alternative to exch.cx”
The domain cryptox.exchange is assessed as a high-risk brand impersonation threat targeting the cryptocurrency brand aave. This assessment is based on multiple technical indicators and security vendor detections, indicating a significant potential for malicious activity.
Analysis indicates that cryptox.exchange has been flagged by 14 out of 95 security vendors on VirusTotal, which suggests a considerable level of suspicion among the cybersecurity community. The domain was registered through NICENIC INTERNATIONAL GROUP CO., LIMITED on August 11, 2025, and resolves to the IP address 104.21.96.116. The Gridinsoft trust score for this domain is 0/100, indicating a complete lack of trust. Additionally, cryptox.exchange appears on four security blocklists: Polkadot, Codeesura, PhishDestroy, and Enkrypt. The page title, 'CryptoX.Exchange — Anonymous Crypto Exchange (No-KYC), Alternative to exch.cx,' further reinforces the suspicion that the domain is attempting to impersonate a legitimate cryptocurrency exchange, potentially to deceive users and steal sensitive information.
To mitigate the risks associated with this brand impersonation threat, users should avoid visiting the domain cryptox.exchange and refrain from entering any personal or financial information on the site. Network administrators are advised to block the IP address 104.21.96.116 and the domain itself to prevent any access. Security teams should also monitor for any similar domains or IP addresses that may be used in future impersonation attempts and educate users about the dangers of visiting untrusted cryptocurrency exchanges.
Security Signals
Network Security Intelligence Registrar context
Threat Response Pipeline
Public Blocklist Status
Stored Capture
Domain Intelligence
Technical detailsDNS, SSL SANs, timestamps
ICANN OVERSIGHT
Accreditation and RAA context
Accreditation and RAA context
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Latest Classified Outcome 2026-08-22 02:57:46 UTC
VirusTotal Analysis
Archived Evidence
Evidence & External Reports
Were You Affected by This Site?
If credentials, payment data, or files were exposed, report the incident immediately. Change affected passwords, revoke active sessions, and scan the device.
Report to Your Local Authorities
Select your country to get official cybercrime contacts, or create a complaint draft →.
Check Any Domain
Threat analysis using stored blocklist, WHOIS, DNS, and public scan evidence
Scan NowReport Phishing
Submit suspicious domains to our threat database — protect the community
ReportLive Threat Feed
Recent phishing reports and observed availability changes
MonitorStay Informed, Stay Safe
Monitor live threats or contest this listing if you believe it's a false positive