# myswanbitcoin.com — MALICIOUS > Explore the phishing threat posed by myswanbitcoin.com, a medium-risk bitcoin scam domain now offline. Learn about its infrastructure and detection. ## Summary PhishDestroy identifies myswanbitcoin.com as a generic phishing domain primarily targeting cryptocurrency users. Classified under medium risk, this domain was designed to deceive victims by masquerading as a legitimate Bitcoin-related service. The domain was registered on February 21, 2026, and was linked to fraudulent activities aimed at harvesting sensitive user credentials. Technical indicators reveal that myswanbitcoin.com was flagged by multiple security vendors and appeared on seven distinct security blocklists. AlienVault OTX reported this domain in one threat intelligence pulse, confirming its association with phishing campaigns. The domain was registered through a defunct registrar, indicating potentially malicious intent and a lack of legitimate infrastructure. Despite its widespread detection, the domain’s hosting infrastructure was relatively short-lived. Currently, myswanbitcoin.com has been taken offline, mitigating ongoing risk to potential victims. The domain’s removal from active hosting environments demonstrates effective response measures from hosting providers and security communities. PhishDestroy recommends continued monitoring of related domains and IP addresses to prevent reemergence of similar threats in the cryptocurrency phishing landscape. ## Threat Details - Verdict: MALICIOUS - Site status: alive (HTTP 530) - Page title: Claim Reward with Swan, your Bitcoin specialists - Swan Bitcoin ## Domain Intelligence - Registered: 2026-02-21 07:01:08 - Registrar: Dead domain - IP: 159.100.18.138 - IP Country: DE - IP City: Frankfurt am Main - IP Org: AS214036 Ultahost, Inc. - SSL Issuer: R11 ## Detection Status - VirusTotal: 5 vendors flagged Vendors: ["alphaMountain.ai", "CyRadar", "Fortinet", "G-Data", "Webroot"] - Google Safe Browsing: clean - Blocklists: 7 hits Lists: ["PhishDestroy", "MetaMask", "ScamSniffer", "Polkadot", "SEAL", "Enkrypt", "Codeesura"] ## Evidence - Screenshot: https://urlscan.io/screenshots/019871cd-0f7b-72ee-a337-d74763c0c936.png - PhishDestroy: https://phishdestroy.io/domain/myswanbitcoin.com/ - LLM endpoint: https://phishdestroy.io/domain/myswanbitcoin.com/llm.txt ## If You Visited This Site 1. Change any passwords you may have entered 2. Enable 2FA on all related accounts 3. Monitor your accounts for unauthorized activity 4. Report to: FBI IC3, Europol, local authorities --- Report by PhishDestroy | https://phishdestroy.io/domain/myswanbitcoin.com/ Last updated: 2026-03-17