opensea[.]finance
Phishing and security check for opensea.finance
“opensea.finance”
The domain opensea.finance is a confirmed phishing site engaged in brand impersonation targeting OpenSea, a well-known cryptocurrency and NFT marketplace. It poses an elevated risk as a cryptocurrency scam, designed to deceive users into believing they are interacting with the legitimate OpenSea platform. As of the latest verification, opensea.finance has been taken offline, though it previously operated without an associated drainer kit.
Technical indicators confirm the malicious nature of opensea.finance. The domain was flagged by 13 of 95 security vendors on VirusTotal, including ChainPatrol, alphaMountain.ai, and Bfore.Ai PreCrime. It appears on one security blocklist, PhishDestroy, and is registered through AT-88-Z (ASN: 16509). The domain resolves to the IP address 15.197.130.221, hosted on Amazon.com, Inc.'s infrastructure (AS16509) in the US. No SSL certificate was observed, and the page title displayed was 'opensea.finance'. Nameservers for the domain are ina1.registrar.eu, ina2.registrar.eu, and ina3.registrar.eu. Google Safe Browsing did not flag the domain at the time of analysis.
Users who may have interacted with opensea.finance should take immediate action to secure their assets. Since this is a cryptocurrency scam, revoke any token approvals granted to the domain and transfer funds to a new wallet. Monitor accounts for unauthorized transactions and enable two-factor authentication (2FA) on all related platforms. Report the phishing domain to OpenSea's official support channels and submit it to platforms like Google Safe Browsing, PhishTank, or the Anti-Phishing Working Group (APWG) to help prevent further victimization.
Threat Response Pipeline
Public Blocklist Status
Stored Capture
Domain Intelligence
Technical detailsDNS, SSL SANs, timestamps
ICANN OVERSIGHT
Accreditation and RAA context
Accreditation and RAA context
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
VirusTotal Analysis
Evidence & External Reports
Were You Affected by This Site?
If credentials, payment data, or files were exposed, report the incident immediately. Change affected passwords, revoke active sessions, and scan the device.
Report to Your Local Authorities
Select your country to get official cybercrime contacts, or create a complaint draft →.
Check Any Domain
Threat analysis using stored blocklist, WHOIS, DNS, and public scan evidence
Scan NowReport Phishing
Submit suspicious domains to our threat database — protect the community
ReportLive Threat Feed
Recent phishing reports and observed availability changes
MonitorStay Informed, Stay Safe
Monitor live threats or contest this listing if you believe it's a false positive