# hextoken.live — SUSPICIOUS > hextoken.live impersonates OKX to steal credentials. This domain, registered March 17 2026, is already active. Remove it from bookmarks and avoid login pages. ## Summary PhishDestroy identifies hextoken.live as an active brand-impersonation scam targeting OKX users. The threat is live credential phishing, not speculative malware downloads or generic fraud. This domain was flagged with zero detections on VirusTotal (0/95), registered through NICENIC INTERNATIONAL GROUP CO., LIMITED on March 17 2026, resolves to 188.114.96.3, and holds a Let’s Encrypt SSL certificate. No public blocklists or trust-score services currently list the domain, indicating a newly deployed campaign still under the radar. To mitigate, avoid any links or ads referencing OKX that point to hextoken.live. Bookmark only the official OKX domain (okx.com) and enable two-factor authentication. Report any accidental logins immediately to OKX support and your email provider. Monitor accounts for unauthorized withdrawals and consider revoking any browser-saved passwords tied to hextoken.live. ## Threat Details - Verdict: SUSPICIOUS - Site status: unknown (HTTP ?) - Target brand: OKX ## Domain Intelligence - Registered: 2026-03-17 20:31:31 - Registrar: NICENIC INTERNATIONAL GROUP CO., LIMITED - IP: 188.114.96.3 ## Detection Status - VirusTotal: 0 vendors flagged - Google Safe Browsing: clean - Blocklists: 0 hits ## Evidence - Cloudflare Radar: https://radar.cloudflare.com/scan/64bea6a9-9ddc-48bb-a6e2-88d2aa792565 - PhishDestroy: https://phishdestroy.io/domain/hextoken.live/ - LLM endpoint: https://phishdestroy.io/domain/hextoken.live/llm.txt ## If You Visited This Site 1. Change any passwords you may have entered 2. Enable 2FA on all related accounts 3. Monitor your accounts for unauthorized activity 4. Report to: FBI IC3, Europol, local authorities --- Report by PhishDestroy | https://phishdestroy.io/domain/hextoken.live/ Last updated: 2026-03-23