gaib[.]network
“GAIB Deposit | Stake AID & USDC to Earn Rewards”
Analysis of gaib.network indicates a high-risk phishing domain actively impersonating a staking platform to deceive users into depositing cryptocurrency. The domain, registered through Cloudflare, resolves to IPv6 address 2a06:98c1:3121::3 and is hosted on infrastructure utilizing HTTP/3 and Cloudflare services. The page title, 'GAIB Deposit | Stake AID & USDC to Earn Rewards,' explicitly targets users with a fraudulent staking offer, a tactic consistent with brand impersonation schemes. The domain appears in 24 threat intelligence pulses on AlienVault OTX and is flagged by 4 of 95 security vendors on VirusTotal, confirming its malicious classification. It is currently listed on six security blocklists, including Polkadot, ScamSniffer, and Enkrypt, which have blocked access due to confirmed phishing activity. The SSL certificate is issued by Google Trust Services, a common practice among threat actors to lend superficial legitimacy to fraudulent sites. Infrastructure analysis reveals no legitimate association with known staking platforms or financial services. The domain remains active as of July 12, 2026, with no indications of takedown efforts. Defenders should treat this domain as malicious and implement blocking measures at the network and endpoint levels. Further investigation into associated wallet addresses or transaction patterns is recommended to identify potential victim interactions. The exact content and functionality of the site remain unanalyzed, but the available indicators confirm its role in a fake staking phishing operation.
Threat Response Pipeline
Public Blocklist Status
Stored Capture
Domain Intelligence
Technical detailsDNS, SSL SANs, timestamps
ICANN OVERSIGHT
Accreditation and RAA context
Accreditation and RAA context
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Technologies · 2 identified
Web infrastructure and security company providing CDN, DDoS mitigation, and DNS services.
www.cloudflare.comThird major version of HTTP protocol, built on QUIC for faster, more reliable connections.
VirusTotal Analysis
Archived Evidence
Evidence & External Reports
Were You Affected by This Site?
If credentials, payment data, or files were exposed, report the incident immediately. Change affected passwords, revoke active sessions, and scan the device.
Report to Your Local Authorities
Select your country to get official cybercrime contacts, or create a complaint draft →.
Check Any Domain
Threat analysis using stored blocklist, WHOIS, DNS, and public scan evidence
Scan NowReport Phishing
Submit suspicious domains to our threat database — protect the community
ReportLive Threat Feed
Recent phishing reports and observed availability changes
MonitorStay Informed, Stay Safe
Monitor live threats or contest this listing if you believe it's a false positive