# exoduspayweb3.com — MALICIOUS > ExodusPayWeb3.com poses a serious phishing risk by impersonating Exodus. Avoid interaction and report suspicious activity immediately to stay safe online. ## Summary PhishDestroy identifies exoduspayweb3.com as an active high-risk phishing domain impersonating the well-known cryptocurrency brand Exodus. This fraudulent site aims to deceive users by leveraging the trusted Exodus name and promoting an enticing "Exodus Pay Airdrop" offer. Such tactics are designed to steal sensitive personal and financial information, posing a significant threat to user security. The domain exoduspayweb3.com was registered on February 21, 2026, and currently resolves to IP address 87.120.254.192. It has been flagged in two AlienVault OTX threat intelligence pulses and appears on two separate security blocklists. Additionally, 13 out of 95 VirusTotal security vendors have detected malicious activity associated with this domain, reinforcing its dangerous profile. The ongoing activity and presence on multiple threat feeds underscore the urgent need for caution. Users are strongly advised to avoid visiting exoduspayweb3.com or engaging with any content labeled as "Exodus Pay Airdrop." To protect personal data and assets, never disclose login credentials or private keys on suspicious platforms. If users encounter this domain or suspect phishing attempts, they should immediately report the incident to their security team or utilize relevant cyber threat reporting channels. Staying vigilant and informed is critical to preventing compromise from brand impersonation scams like this one. ## Threat Details - Verdict: MALICIOUS - Site status: alive (HTTP 530) - Target brand: Exodus - Page title: Exodus Pay Airdrop ## Domain Intelligence - Registered: 2026-02-21 07:01:08 - IP: 87.120.254.192 - SSL Issuer: R13 ## Detection Status - VirusTotal: 13 vendors flagged Vendors: ["ChainPatrol", "alphaMountain.ai", "CRDF", "CyRadar", "Ermes", "Forcepoint ThreatSeeker", "Fortinet", "Gridinsoft", "Lionic", "Seclookup", "SOCRadar", "Sophos", "VIPRE"] - Google Safe Browsing: clean - Blocklists: 2 hits Lists: ["PhishDestroy", "MetaMask"] ## Evidence - Screenshot: https://urlscan.io/screenshots/019ba9ab-f8ed-767c-a72a-63dab5fa2d42.png - PhishDestroy: https://phishdestroy.io/domain/exoduspayweb3.com/ - LLM endpoint: https://phishdestroy.io/domain/exoduspayweb3.com/llm.txt ## If You Visited This Site 1. Change any passwords you may have entered 2. Enable 2FA on all related accounts 3. Monitor your accounts for unauthorized activity 4. Report to: FBI IC3, Europol, local authorities --- Report by PhishDestroy | https://phishdestroy.io/domain/exoduspayweb3.com/ Last updated: 2026-03-19