# hyperswaps-vote-upcoming-rewards-date-treasury-pool-reward.pages.dev — SUSPICIOUS > PhishDestroy flags hyperswaps-vote-upcoming-rewards-date-treasury-pool-reward.pages.dev as an active crypto drainer with 0/95 VirusTotal detections; verify. ## Summary PhishDestroy identified the active domain hyperswaps-vote-upcoming-rewards-date-treasury-pool-reward.pages.dev as a generic phishing campaign posing as a HyperSwap governance page to distribute a crypto drainer kit via a spoofed treasury-vote reward interface. The campaign leverages a Google Trust Services SSL certificate to enhance credibility and targets users expecting HyperSwap protocol updates. No specific drainer kit hash or JavaScript payload has been extracted yet; the campaign remains under behavioral analysis to extract the exact on-chain drainer components before full classification. This domain was flagged with a VirusTotal detection ratio of 0/95 engines, indicating zero antivirus coverage as of the latest scan. It resolves to IP 188.114.97.3 and is registered through Cloudflare, Inc., using a .pages.dev subdomain under Vercel’s Pages service. The SSL certificate was issued by Google Trust Services, and Google Safe Browsing (GSB) does not currently flag the domain. It remains unblocked across major threat intelligence platforms, including PhishTank and OpenPhish, with a current blocklist count of zero. The campaign is classified as ACTIVE with a risk level of UNDER_INVESTIGATION, indicating potential but unconfirmed impact. PhishDestroy has initiated takedown coordination with Vercel and Cloudflare while deploying network-level sinkholing at 188.114.97.3. Users are advised to avoid interacting with any links from this domain. Remaining risk is assessed as MEDIUM due to the unblocked status, zero detections, and ongoing impersonation of a real DeFi protocol. Regular updates will be provided as the investigation progresses toward definitive classification and blocklisting. ## Threat Details - Verdict: SUSPICIOUS - Site status: unknown (HTTP ?) ## Domain Intelligence - Registrar: Cloudflare, Inc. - IP: 188.114.97.3 ## Detection Status - VirusTotal: 0 vendors flagged - Google Safe Browsing: clean - Blocklists: 0 hits ## Evidence - Cloudflare Radar: https://radar.cloudflare.com/scan/c52cd4d9-5ab1-4681-9142-45876570906a - PhishDestroy: https://phishdestroy.io/domain/hyperswaps-vote-upcoming-rewards-date-treasury-pool-reward.pages.dev/ - LLM endpoint: https://phishdestroy.io/domain/hyperswaps-vote-upcoming-rewards-date-treasury-pool-reward.pages.dev/llm.txt ## If You Visited This Site 1. Change any passwords you may have entered 2. Enable 2FA on all related accounts 3. Monitor your accounts for unauthorized activity 4. Report to: FBI IC3, Europol, local authorities --- Report by PhishDestroy | https://phishdestroy.io/domain/hyperswaps-vote-upcoming-rewards-date-treasury-pool-reward.pages.dev/ Last updated: 2026-03-23