# PhishDestroy threat dossier — hyperliquiddestops.xyz ================================================================ Fetched: 2026-05-19 03:58:00 UTC Canonical: https://phishdestroy.io/domain/hyperliquiddestops.xyz/ ## VERDICT ---------------------------------------------------------------- CRITICAL THREAT — DO NOT VISIT Composite threat score: 96/100 (PhishDestroy scoring — see methodology below) Scam classification: Impersonation Targeted brand: Hyperliquid ## DETECTION EVIDENCE ---------------------------------------------------------------- VirusTotal: 1/92 security vendors flagged this domain Flagging vendors: Fortinet ## INFRASTRUCTURE ---------------------------------------------------------------- IP address: 188.114.96.3 (CA, Toronto) ASN: AS13335 Cloudflare, Inc. Hosting org: CloudFlare, Inc. Registrar: NICENIC INTERNATIONAL GROUP CO., LIMITED !!! REGISTRAR INTEGRITY ALERT — NiceNIC !!! NiceNIC International: over 90% of its registered domains are associated with illegal content; documented systematic abuse-report non-response. Primary sources: https://phishdestroy.io/nicenic-real https://phishdestroy.io/nicenic-verdict Nameservers: eoin.ns.cloudflare.com, sofia.ns.cloudflare.com Registered: 2026-05-15 Page title: Hyperliquid Desktop HTTP response: 200 ## TLS CERTIFICATE ---------------------------------------------------------------- Issuer: Let's Encrypt / E8 Expires: 2026-08-13 Status: INVALID chain Fingerprint: 349b96ffffffe22aca6ff3b66f7aa44986d815ac7ccb0a5842a2830a30453db6 ## ABUSE-REPORT HISTORY (evidence of registrar non-response) ---------------------------------------------------------------- Status: pending notification queue. No abuse reports filed yet — this domain is waiting for the next cycle of our automated abuse-reporter. ## TIMELINE ---------------------------------------------------------------- Domain registered: 2026-05-15 (per WHOIS / CT — may reflect a renewal or transfer date, not first-ever registration) First detected: 2026-05-18 22:49:39 UTC (by PhishDestroy tracker) First reported: 2026-05-18 19:50:21 UTC (abuse notice filed) Last verified: 2026-05-19 03:19:54 UTC Current status: ACTIVE / observable ## EXTERNAL CORROBORATION (third-party evidence) ---------------------------------------------------------------- URLScan.io: https://urlscan.io/result/019e3ca2-1f04-7504-aa83-63717d312da9/ URLQuery: https://urlquery.net/report/7d7c275f-8136-4b25-888e-df2775c90ff4 Wayback Machine: https://web.archive.org/web/*/hyperliquiddestops.xyz crt.sh CT logs: https://crt.sh/?q=%25.hyperliquiddestops.xyz Google transparency: https://transparencyreport.google.com/safe-browsing/search?url=hyperliquiddestops.xyz AlienVault OTX: https://otx.alienvault.com/indicator/domain/hyperliquiddestops.xyz URLhaus: https://urlhaus.abuse.ch/host/hyperliquiddestops.xyz/ ## ANALYST NARRATIVE ---------------------------------------------------------------- [Generated: 2026-05-18 22:49:58 UTC — narrative may predate facts above. Treat fields in TIMELINE / DETECTION EVIDENCE / INFRASTRUCTURE as authoritative if they differ from the prose below.] PhishDestroy identifies hyperliquiddestops.xyz as an active crypto drainer impersonating the Hyperliquid brand, posing an elevated risk to cryptocurrency users. This domain mimics Hyperliquid’s official platform to deceive visitors into connecting wallets or entering credentials, enabling unauthorized fund transfers. The threat is classified as a crypto drainer due to its design to siphon assets from compromised wallets upon interaction. This domain was flagged by 1 out of 95 VirusTotal security vendors, indicating limited but concerning detection. It resolves to IP address 188.114.96.3 and was registered on May 15, 2026, through NICENIC INTERNATIONAL GROUP CO., LIMITED. The domain impersonates Hyperliquid and holds a valid SSL certificate from Let’s Encrypt, which may lend false legitimacy to unsuspecting users. These technical indicators suggest a recently established, malicious infrastructure designed to exploit trust in the Hyperliquid brand. To mitigate the risk posed by hyperliquiddestops.xyz, users should avoid interacting with the domain entirely. If you suspect exposure, immediately revoke any connected wallet permissions via your wallet provider’s security settings. Verify URLs against official Hyperliquid channels and use PhishDestroy’s real-time checks before entering sensitive information. Always enable wallet transaction confirmations and monitor for unauthorized transfers. Report this domain to PhishDestroy to aid in broader threat intelligence sharing. ## EVIDENCE HASHES ---------------------------------------------------------------- PhishDestroy Case ID: PD-20260518-2C7E5A Favicon MD5: 524eb329b84475a707f2b37726a6d4ee TLS cert SHA-256: 349b96ffffffe22aca6ff3b66f7aa44986d815ac7ccb0a5842a2830a30453db6 ## SCORING METHODOLOGY ---------------------------------------------------------------- Composite score is NOT derived from VirusTotal alone. PhishDestroy aggregates: - VirusTotal positive ratio - Public blocklist consensus (MetaMask, ScamSniffer, OpenPhish, PhishTank, URLhaus, CryptoFirewall, SEAL, Polkadot, Enkrypt, Phishunt, DiscordPhishing, PhishingDB) - Cloaking detection (HTTP 666 or rendering delta between bot and real visitor) - DNS-filter consensus (Quad9, CleanBrowsing, NextDNS, AdGuard, Cloudflare, etc.) - AlienVault OTX pulses + Cloudflare Radar + Google Safe Browsing - URLScan / URLQuery verdicts - Brand-impersonation heuristics (DOM analysis of forms, logos, wording) - Known phishing-kit fingerprinting (favicon hash, JS obfuscation signatures) - Wallet-drainer family classification (Angel, MS, Rainbow, Pink, Inferno, ...) - Free-TLS vs paid-cert ratio (throwaway infrastructure signal) - Registrar/hosting abuse history (this registrar's track record) - Human researcher sign-off (volunteer takedown team) A domain present in our database is ALREADY flagged. A low VT count by itself does NOT mean the domain is safe — new scam domains routinely show 0/95 VT for their first 7–30 days while actively draining wallets. Always cross-reference the composite score and the individual indicators above, not just VT. ## CORRECTIONS / APPEALS ---------------------------------------------------------------- Full HTML report: https://phishdestroy.io/domain/hyperliquiddestops.xyz/ JSON API: https://api.destroy.tools/v1/check?domain=hyperliquiddestops.xyz Appeal a flag: https://phishdestroy.io/appeals/ (responded to within 48 hours, FP rate <0.01%) Submit a report: https://t.me/PhishDestroy_bot About PhishDestroy: volunteer-driven open-source threat-intelligence platform. Tracked: 151,358 domains (36,773 alive under monitoring, 114,305 confirmed takedowns/dead). Site: https://phishdestroy.io