hyperliquid-claim[.]online
“Bot Verification”
Evidence Summary
Analysis of hyperliquid-claim.online indicates a crypto-themed phishing domain impersonating Hyperliquid, a decentralized exchange. The domain was registered on September 16, 2025, through HOSTINGER operations, UAB, and resolved to IP 82.25.113.137, hosted on AS47583 (Hostinger International Limited, FR). No SSL certificate was present, and nameservers were set to ns1.dns-parking.com and ns2.dns-parking.com. The page title, 'Bot Verification,' aligns with known airdrop scam patterns, where victims are prompted to complete fraudulent verification steps to claim non-existent crypto rewards.
Infrastructure review shows the domain was taken offline prior to July 24, 2026, though its prior activity remains under investigation. It appeared on one security blocklist (PhishDestroy) and was classified as an airdrop scam. Gridinsoft assigned a trust score of 0/100, reflecting high suspicion. While VirusTotal scans by 95 vendors returned no active detections, this absence does not confirm safety.
The domain’s registration details, hosting provider, and scam classification suggest targeted abuse of Hyperliquid’s branding to deceive users. Defenders should treat hyperliquid-claim.online as malicious and prioritize blocking the domain and its resolving IP. Monitoring for similar domains using the same registrar, nameservers, or hosting infrastructure may help identify related threats. Further forensic analysis is recommended if logs indicate user interaction with this domain.
Data Coverage
Threat Response Pipeline
Blocklist coverage
10 monitored external feeds · stored snapshot Aug 11, 2026
10 monitored external feeds No match
Detection timeline
-
Cloudflare Radar
Cloudflare Radar scan stored · Open scan
Stored Capture
Domain Intelligence
Technical detailsDNS, TLS names and timestamps
ICANN OVERSIGHT
Accreditation and RAA context
Accreditation and RAA context
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
VirusTotal Analysis
Were You Affected by This Site?
If credentials, payment data, or files were exposed, report the incident immediately. Change affected passwords, revoke active sessions, and scan the device.
Report to Your Local Authorities
Select your country to get official cybercrime contacts, or create a complaint draft →.
Check Any Domain
Threat analysis using stored blocklist, WHOIS, DNS, and public scan evidence
Scan NowReport Phishing
Submit suspicious domains to our threat database — protect the community
ReportLive Threat Feed
Recent phishing reports and observed availability changes
MonitorStay Informed, Stay Safe
Monitor live threats or contest this listing if you believe it's a false positive