# hypersswaps.exchange — MALICIOUS — Crypto Drainer (Angel Drainer) > hypersswaps.exchange was linked to crypto draining attacks. Avoid interaction and do not share private keys or funds. ## Summary PhishDestroy has identified hypersswaps.exchange as a medium-risk crypto drainer domain targeting users with fraudulent airdrop schemes. Such threats aim to steal cryptocurrency by tricking users into connecting wallets or approving malicious transactions, leading to financial loss. The domain resolved to IP 172.67.156.202 and was flagged by 9 out of 95 security vendors on VirusTotal. It was associated with the Angel Drainer kit and appeared on two security blocklists. Registered through NiceNIC International Group Co., Limited on September 18, 2025, the site is currently offline but remains a point of concern due to prior malicious activity. Users should refrain from visiting hypersswaps.exchange or interacting with its content in any way. Never share private keys or authorize transactions from suspicious sites. Always verify the legitimacy of crypto airdrops through official channels to avoid falling victim to draining scams. ## Threat Details - Verdict: MALICIOUS — Crypto Drainer (Angel Drainer) - Site status: dead (HTTP 403) - Drainer type: Angel Drainer - Scam type: Airdrop Scam - Kit: Airdrop Scam - Page title: Airdrop | HyperSwap Exchange on Hyperliquid ## Domain Intelligence - Registered: 2025-09-18 00:00:00 - Expires: 2026-09-18 00:00:00 - Registrar: NiceNIC International Group Co., Limited - Country: HK - IP: 172.67.156.202 - IP Country: US - IP City: San Francisco - IP Org: AS13335 Cloudflare, Inc. - Nameservers: nash.ns.cloudflare.com karsyn.ns.cloudflare.com - SSL Issuer: none ## Detection Status - VirusTotal: 9 vendors flagged Vendors: ["ADMINUSLabs", "alphaMountain.ai", "BitDefender", "CRDF", "CyRadar", "Fortinet", "G-Data", "Gridinsoft", "SOCRadar"] - Google Safe Browsing: clean - Blocklists: 2 hits Lists: ["PhishDestroy", "MetaMask"] ## Evidence - Screenshot: https://urlscan.io/screenshots/019b1a84-3160-776f-a0d2-5a3db9c1f881.png - Cloudflare Radar: https://radar.cloudflare.com/scan/7356279c-fd28-4d2a-8708-bd92540abd4a - PhishDestroy: https://phishdestroy.io/domain/hypersswaps.exchange/ - LLM endpoint: https://phishdestroy.io/domain/hypersswaps.exchange/llm.txt ## If You Visited This Site 1. Revoke all token approvals immediately (revoke.cash / unrekt.net) 2. Move remaining funds to a new wallet 3. Do not interact with any transactions from this site 4. Report to: FBI IC3, Europol, local authorities --- Report by PhishDestroy | https://phishdestroy.io/domain/hypersswaps.exchange/ Last updated: 2026-03-19