# modeswap.xyz — MALICIOUS > Warning: modeswap.xyz is a medium-risk phishing site now offline. Avoid interacting to protect your DeFi assets from scams. ## Summary PhishDestroy identifies modeswap.xyz as a medium-risk generic phishing domain targeting DeFi users by impersonating a modular Layer 2 application with misleading airdrop offers. Such phishing scams can compromise users’ private keys and funds, making this threat significant for the cryptocurrency community. The domain modeswap.xyz was created recently on February 21, 2026, and resolves to IP address 172.67.176.133. It has been flagged on 7 security blocklists and detected by 5 out of 95 VirusTotal vendors as malicious. The site has been taken offline, mitigating immediate risk, but its presence highlights ongoing phishing tactics exploiting DeFi buzz. Users are advised to avoid visiting modeswap.xyz and refrain from providing any personal or wallet information. Always verify official project URLs through trusted channels and utilize security tools to detect phishing attempts. Staying vigilant against unsolicited airdrop claims is essential to maintaining DeFi asset security. ## Threat Details - Verdict: MALICIOUS - Site status: dead (HTTP 0) - Page title: Mode App - The Modular DeFi L2 - Airdrop ## Domain Intelligence - Registered: 2026-02-21 07:01:08 - IP: 172.67.176.133 - SSL Issuer: WE1 ## Detection Status - VirusTotal: 5 vendors flagged Vendors: ["alphaMountain.ai", "CyRadar", "Forcepoint ThreatSeeker", "G-Data", "Webroot"] - Google Safe Browsing: clean - Blocklists: 7 hits Lists: ["PhishDestroy", "MetaMask", "ScamSniffer", "Polkadot", "SEAL", "Enkrypt", "Codeesura"] ## Evidence - Screenshot: https://urlscan.io/screenshots/01985a0c-db11-7226-bfcd-974eecdc993c.png - PhishDestroy: https://phishdestroy.io/domain/modeswap.xyz/ - LLM endpoint: https://phishdestroy.io/domain/modeswap.xyz/llm.txt ## If You Visited This Site 1. Change any passwords you may have entered 2. Enable 2FA on all related accounts 3. Monitor your accounts for unauthorized activity 4. Report to: FBI IC3, Europol, local authorities --- Report by PhishDestroy | https://phishdestroy.io/domain/modeswap.xyz/ Last updated: 2026-03-19