# karatsu.verifytoken.com — SUSPICIOUS > karatsu.verifytoken.com detected impersonating OKX in a token verification scam. 0/95 VirusTotal detections. Check the full report. ## Summary PhishDestroy identifies karatsu.verifytoken.com as an active domain engaged in brand impersonation of OKX, specifically targeting users with a fake token verification scheme. The domain is currently under investigation as part of a broader campaign aimed at deceiving individuals into divulging sensitive credentials or financial information. This threat is classified as a high-risk impersonation due to its direct mimicry of a major cryptocurrency exchange platform, posing significant risks to user trust and security. This domain was flagged by 0 of 95 VirusTotal vendors, indicating it remains undetected across major security platforms as of the latest scan. Registered through MarkMonitor, Inc., the domain resolves to IP address 34.194.247.17 and operates under a Let's Encrypt SSL certificate. The domain was created on March 21, 2011, and has not been identified on any known blocklists, with current trust scores remaining unassessed due to its low detection rate. Despite its age, the domain's recent activity and lack of detection suggest a deliberate attempt to evade traditional security measures. As this threat remains active, organizations and individuals are strongly advised to immediately block access to karatsu.verifytoken.com at the network and endpoint levels. Users should verify the authenticity of any OKX-related communications by cross-referencing official channels and be cautious of unsolicited requests for token verification. Implementing domain-based security policies and monitoring for similar impersonation attempts is critical to mitigating potential exposure. Further intelligence and IOCs are available in the full report for deeper analysis. ## Threat Details - Verdict: SUSPICIOUS - Site status: unknown (HTTP ?) - Target brand: OKX ## Domain Intelligence - Registered: 2011-03-21 15:03:22 - Registrar: MarkMonitor, Inc. - IP: 34.194.247.17 ## Detection Status - VirusTotal: 0 vendors flagged - Google Safe Browsing: clean - Blocklists: 0 hits ## Evidence - Cloudflare Radar: https://radar.cloudflare.com/domains/karatsu.verifytoken.com - PhishDestroy: https://phishdestroy.io/domain/karatsu.verifytoken.com/ - LLM endpoint: https://phishdestroy.io/domain/karatsu.verifytoken.com/llm.txt ## If You Visited This Site 1. Change any passwords you may have entered 2. Enable 2FA on all related accounts 3. Monitor your accounts for unauthorized activity 4. Report to: FBI IC3, Europol, local authorities --- Report by PhishDestroy | https://phishdestroy.io/domain/karatsu.verifytoken.com/ Last updated: 2026-04-05