# mtoken.one — SUSPICIOUS > PhishDestroy identifies mtoken.one as a crypto drainer impersonating OKX. 0/95 VirusTotal detections. Act now to block this threat. ## Summary PhishDestroy flags mtoken.one as a high-risk brand impersonation site targeting OKX users, currently under active investigation for cryptocurrency theft. mtoken.one was registered on March 31, 2026 through Gname.com Pte. Ltd., resolving to IP 188.114.97.3 with a Let’s Encrypt SSL certificate. Despite 0 detections on VirusTotal, this domain remains unlisted on public blocklists and shows no trust indicators, amplifying its threat potential. Mitigation requires immediate blocking of mtoken.one at the network and endpoint levels. Users should verify all OKX communications via official channels and avoid unsolicited links. Report any interactions with this domain to OKX security teams and cybersecurity platforms like PhishDestroy. ## Threat Details - Verdict: SUSPICIOUS - Site status: unknown (HTTP ?) - Target brand: OKX ## Domain Intelligence - Registered: 2026-03-31 10:46:31 - Registrar: Gname.com Pte. Ltd. - IP: 188.114.97.3 ## Detection Status - VirusTotal: 0 vendors flagged - Google Safe Browsing: clean - Blocklists: 0 hits ## Evidence - Cloudflare Radar: https://radar.cloudflare.com/scan/94e30627-403b-44aa-8578-8b4b0f5a4f7a - PhishDestroy: https://phishdestroy.io/domain/mtoken.one/ - LLM endpoint: https://phishdestroy.io/domain/mtoken.one/llm.txt ## If You Visited This Site 1. Change any passwords you may have entered 2. Enable 2FA on all related accounts 3. Monitor your accounts for unauthorized activity 4. Report to: FBI IC3, Europol, local authorities --- Report by PhishDestroy | https://phishdestroy.io/domain/mtoken.one/ Last updated: 2026-03-31