pancakeservice.online
“Exchange | PancakeSwap”
Evidence Summary
This domain, pancakeservice.online, poses a high risk of brand impersonation, specifically targeting users of the well-known crypto exchange PancakeSwap. If accessed, users may be led to believe they are interacting with the legitimate PancakeSwap website, potentially leading to the compromise of personal and financial information.
Analysis indicates that pancakeservice.online is flagged by 17 out of 95 security vendors on VirusTotal, which is a significant proportion suggesting a credible threat. The domain was created on April 13, 2026, and is registered through NICENIC INTERNATIONAL GROUP CO., LIMITED, a registrar that has been associated with suspicious activities. Additionally, the domain appears in one threat intelligence pulse on AlienVault OTX and is listed on four security blocklists, further corroborating the risk. The IP address 104.21.11.90, to which the domain resolves, has also been observed as part of malicious infrastructure in other security reports. The page title 'Exchange | PancakeSwap' is a clear attempt to mimic the legitimate PancakeSwap website, enhancing the deceptive nature of the site.
If a user has visited pancakeservice.online, it is crucial to take immediate action to secure their accounts. First, they should check for any unauthorized transactions or account activities on their cryptocurrency wallets and exchange accounts. Changing passwords and enabling two-factor authentication (2FA) on all relevant accounts is highly recommended. Users should also monitor their financial statements and credit reports for any unusual activity. Reporting the incident to the PancakeSwap support team and the relevant authorities can help in mitigating the damage and preventing future incidents. It is advisable to avoid clicking on links or providing personal information on any site that does not use the official domain, pancakeswap.com.
Network Security Intelligence Registrar context
| Detection System | Indicator | Verdict | Alert |
|---|---|---|---|
| Cloudflare DNS | pancakeservice.online |
malicious | Sinkholed |
| OpenDNS | pancakeservice.online |
phishing | Phishing Block |
| DigiCert UltraDNS | pancakeservice.online |
malicious | Sinkholed |
| DNS4EU | pancakeservice.online |
malicious | Sinkholed |
| Quad9 DNS | pancakeservice.online |
malicious | Sinkholed |
Forensic History & Detection Timeline
-
Domain Status Transition Aug 5, 2026 · 18:27 UTCDomain state transitioned from alive to dead.
-
VirusTotal Detections Update Jun 26, 2026 · 09:05 UTCVirusTotal scanner detections updated from 16 to 17. Added scanner alerts: Chong Lua Dao, Cluster25, Criminal IP, Forcepoint ThreatSeeker, alphaMountain.ai. Resolved alerts: ESET, Kaspersky, OpenPhish, PhishFort.
Threat Response Pipeline
Public Blocklist Status
Evasion analysis
Cloaking & traffic-distribution check
Stored crawler-versus-browser observations for this host, plus a live fingerprint check for Keitaro-style traffic distribution systems.
- Stored cloaking flag
- Not observed
- Cloaking score
- 0/6
- Last cloaking scan
Scanner note: dns_error: raw=dns_error; via=local_dns_prefilter
Stored Capture · 2 sources
Domain Intelligence
Technical detailsDNS, SSL SANs, timestamps
ICANN OVERSIGHT
Accreditation and RAA context
Accreditation and RAA context
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Latest Classified Outcome 2026-09-17 04:10:10 UTC
VirusTotal Analysis
Lookalike domains
83 stored lookalike domains
Show all (71)
Community intelligence
1 community report
CategoryPHISHING
The PhishFort Detection System has flagged this as a domain threat, classified as null. Threat detected at 2026-04-13T13:22:52.323Z.
Community reports
Reported by 1 community member, first seen Apr 13, 2026
- Stored reports
- 1
- Unique reported URLs
- 1
Evidence & External Reports
Were You Affected by This Site?
If credentials, payment data, or files were exposed, report the incident immediately. Change affected passwords, revoke active sessions, and scan the device.
Report to Your Local Authorities
Select your country to get official cybercrime contacts, or create a complaint draft →.
Check Any Domain
Threat analysis using stored blocklist, WHOIS, DNS, and public scan evidence
Scan NowReport Phishing
Submit suspicious domains to our threat database — protect the community
ReportLive Threat Feed
Recent phishing reports and observed availability changes
MonitorStay Informed, Stay Safe
Monitor live threats or contest this listing if you believe it's a false positive