layerswap.finance
“LayerSwap - Fast Cross-Chain Crypto Bridge | Transfer Assets Instantly”
Evidence Summary
This domain, layerswap.finance, is flagged as a critical crypto drainer threat targeting users of the Across cross-chain bridge platform. Registered on June 20, 2025, through Tucows Domains Inc., the domain impersonates the legitimate LayerSwap service, as evidenced by its page title, 'LayerSwap - Fast Cross-Chain Crypto Bridge | Transfer Assets Instantly,' and explicit targeting of Across in threat intelligence reports. Infrastructure analysis reveals the domain resolves to IP 172.66.0.96, hosted on Cloudflare's AS13335, with nameservers under Njalla (1-you.njalla.no, 2-can.njalla.in, 3-get.njalla.fo). The site currently returns an HTTP 200 status but lacks an SSL certificate, a common red flag in phishing infrastructure.
The domain appears on two security blocklists and is blocked by PhishDestroy and ScamSniffer. AlienVault OTX includes it in one threat intelligence pulse, while Gridinsoft assigns a trust score of 0/100. Four of 93 security vendors on VirusTotal flag the domain as malicious. The attack vector involves Wallet Connect abuse, a technique used to trick victims into connecting wallets to malicious smart contracts, enabling unauthorized asset transfers.
Defenders should treat this domain as actively hostile. Recommended actions include immediate blocking at DNS and proxy levels, monitoring for wallet connections originating from this domain, and alerting users about fake cross-chain bridge interfaces. Given the domain's registration age and continued activity, it is likely part of a broader campaign targeting cryptocurrency users. No legitimate LayerSwap or Across services are associated with this domain.
Forensic History & Detection Timeline
-
Domain Status Transition Aug 6, 2026 · 00:23 UTCDomain state transitioned from alive to dead.
-
Cloudflare Radar Scan Mar 7, 2026 · 11:26 UTCCloudflare Radar scan registered: View Radar report.
Threat Response Pipeline
Public Blocklist Status
Evasion analysis
Cloaking & traffic-distribution check
Stored crawler-versus-browser observations for this host, plus a live fingerprint check for Keitaro-style traffic distribution systems.
- Stored cloaking flag
- Not observed
- Cloaking score
- 0/6
- Last cloaking scan
Scanner note: dns_error: raw=dns_error; via=local_dns_prefilter
Stored Capture · 2 sources
Domain Intelligence
Technical detailsDNS, SSL SANs, timestamps
ICANN OVERSIGHT
Accreditation and RAA context
Accreditation and RAA context
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
VirusTotal Analysis
Community reports
Reported by 1 community member, first seen Dec 24, 2025
- Stored reports
- 1
- Unique reported URLs
- 1
Evidence & External Reports
Were You Affected by This Site?
If credentials, payment data, or files were exposed, report the incident immediately. Change affected passwords, revoke active sessions, and scan the device.
Report to Your Local Authorities
Select your country to get official cybercrime contacts, or create a complaint draft →.
Check Any Domain
Threat analysis using stored blocklist, WHOIS, DNS, and public scan evidence
Scan NowReport Phishing
Submit suspicious domains to our threat database — protect the community
ReportLive Threat Feed
Recent phishing reports and observed availability changes
MonitorStay Informed, Stay Safe
Monitor live threats or contest this listing if you believe it's a false positive