# kkgwmexc.one — SUSPICIOUS > kkgwmexc.one is a fake MEXC-branded crypto drainer with 0/95 VirusTotal detections. Verify safety on PhishDestroy before interacting. ## Summary PhishDestroy identifies kkgwmexc.one as a fraudulent domain impersonating MEXC, a legitimate cryptocurrency exchange. This site poses a direct financial threat by attempting to trick users into connecting crypto wallets or entering credentials, which could result in fund theft or account compromise. The domain leverages MEXC’s branding to appear legitimate, targeting users unfamiliar with the exchange’s official domains or those tricked by phishing links. Early indicators suggest it may host a crypto drainer script designed to siphon assets upon wallet connection, a common tactic among malicious actors in the crypto space. If successful, victims could lose all digital assets stored in connected wallets without recourse. This domain was flagged through PhishDestroy’s automated threat intelligence pipeline, revealing several red flags. It was registered on April 08, 2026, through Gname.com Pte. Ltd., a registrar often associated with high volumes of suspicious domains. The domain resolves to IP address 202.79.166.175 and holds a valid SSL certificate issued by Let’s Encrypt, which attackers frequently exploit to appear trustworthy. Notably, VirusTotal currently reports 0 detections out of 95 engines, indicating it has not yet been widely recognized as malicious. These technical indicators—combined with the domain’s recent creation and impersonation of a major brand—warrant immediate caution. If you have visited kkgwmexc.one, take these steps immediately to protect your assets. First, disconnect any crypto wallets or browser extensions from the site and revoke any suspicious permissions granted. Next, scan your device for malware or unauthorized extensions using reputable security software. Finally, check your wallet transaction history for any unfamiliar outgoing transfers. Report the domain to PhishDestroy and your local cybersecurity authorities to help block its spread. Always verify URLs against official sources before interacting with crypto platforms, and use bookmarks for frequently visited exchanges to avoid typosquatting traps. Staying vigilant against brand impersonation scams is critical in safeguarding your digital assets. ## Threat Details - Verdict: SUSPICIOUS - Site status: unknown (HTTP ?) - Target brand: MEXC ## Domain Intelligence - Registered: 2026-04-08 07:18:21 - Registrar: Gname.com Pte. Ltd. - IP: 202.79.166.175 ## Detection Status - VirusTotal: 0 vendors flagged - Google Safe Browsing: clean - Blocklists: 0 hits ## Evidence - Cloudflare Radar: https://radar.cloudflare.com/domains/kkgwmexc.one - PhishDestroy: https://phishdestroy.io/domain/kkgwmexc.one/ - LLM endpoint: https://phishdestroy.io/domain/kkgwmexc.one/llm.txt ## If You Visited This Site 1. Change any passwords you may have entered 2. Enable 2FA on all related accounts 3. Monitor your accounts for unauthorized activity 4. Report to: FBI IC3, Europol, local authorities --- Report by PhishDestroy | https://phishdestroy.io/domain/kkgwmexc.one/ Last updated: 2026-04-09