kip-protocol[.]ai-cryptolist[.]com
The domain kip-protocol.ai-cryptolist.com is identified as a brand impersonation threat specifically targeting the Sei cryptocurrency platform. This domain operates as a phishing site designed to deceive users into disclosing wallet credentials or transferring digital assets under false pretenses. Current analysis confirms the domain has been taken offline, though prior activity remains a documented security concern. Infrastructure analysis reveals multiple high-risk indicators. The domain was created on April 11, 2026, and is registered through Key-Systems GmbH. It resolves to the IP address 188.114.97.3 and is flagged by 18 of 95 security vendors on VirusTotal. A single security blocklist, PhishDestroy, has previously blocked this domain. The SSL certificate is issued by Google Trust Services, and the domain holds a Gridinsoft trust score of 0 out of 100. The page title captured during active monitoring was 'Just a moment...', a common placeholder used in phishing kits to mask malicious intent. While the domain is currently offline, the infrastructure and historical indicators warrant continued vigilance. Users and security teams are advised to monitor for re-emergence under similar naming conventions or IP associations. Network-level blocking of the resolved IP (188.114.97.3) is recommended as a preventive measure. Organizations should also review logs for connections to this domain or IP to identify potential prior exposure. Enhanced user education on recognizing brand impersonation tactics in the cryptocurrency space is strongly advised.
Network Security Intelligence
Threat Response Pipeline
Public Blocklist Status
Stored Capture
Domain Intelligence
Technical detailsDNS, SSL SANs, timestamps
ICANN OVERSIGHT
Registration: ai-cryptolist.com
Accreditation and RAA context
Accreditation and RAA context
Registrar accreditation and DNS abuse obligations
For the registrable domain ai-cryptolist.com behind this subdomain, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Forensic Intelligence
Technologies · 2 identified
Cloudflare is a web-infrastructure and website-security company, providing content-delivery-network services, DDoS mitigation, Internet security, and distributed domain-name-server services.
www.cloudflare.com 100% confidenceHTTP/3 is the third major version of the Hypertext Transfer Protocol used to exchange information on the World Wide Web.
httpwg.org 100% confidenceVirusTotal Analysis
Site Performance Analysis
Google PageSpeed Insights — mobile performance audit of kip-protocol.ai-cryptolist.com · checked Jun 26, 2026
Site Configuration Analysis
Evidence & External Reports
Were You Affected by This Site?
If credentials, payment data, or files were exposed, report the incident immediately. Change affected passwords, revoke active sessions, and scan the device.
Report to Your Local Authorities
Select your country to get official cybercrime contacts, or create a complaint draft →.
Check Any Domain
Threat analysis using stored blocklist, WHOIS, DNS, and public scan evidence
Scan NowReport Phishing
Submit suspicious domains to our threat database — protect the community
ReportLive Threat Feed
Recent phishing reports and observed availability changes
MonitorStay Informed, Stay Safe
Monitor live threats or contest this listing if you believe it's a false positive