# phenomtoken.top — SUSPICIOUS > phenomtoken.top impersonates OKX with a fake crypto airdrop scam. VirusTotal shows 0/95 detections. Check the full report. ## Summary PhishDestroy identifies phenomtoken.top as an active brand-impersonation scam targeting OKX users. This malicious site claims to offer a cryptocurrency airdrop and is designed to steal personal data or crypto funds by tricking victims into entering login credentials or wallet information under the guise of a promotional giveaway. This domain was flagged by PhishDestroy after investigations revealed multiple red flags, including its very recent creation on March 30, 2026 — just days prior to this assessment — and zero detections out of 95 security engines on VirusTotal at the time of analysis. The site is registered via NICENIC INTERNATIONAL GROUP CO., LIMITED and resolves to IP address 172.67.150.188, using a valid Let’s Encrypt SSL certificate to appear legitimate. Unlike legitimate OKX domains, this deceptive site uses misspelled branding and promises unrealistic rewards to lure victims. If you visited phenomtoken.top, cease any interaction immediately. Do not enter any login credentials, wallet addresses, private keys, or personal information. Clear your browser cache, run a full malware scan on your device, and monitor your financial and crypto accounts for suspicious transactions. Report the domain to your antivirus provider and to OKX’s official security team. Use only official OKX channels (okx.com) for any real promotions or support. ## Threat Details - Verdict: SUSPICIOUS - Site status: unknown (HTTP ?) - Target brand: OKX ## Domain Intelligence - Registered: 2026-03-30 20:41:29 - Registrar: NICENIC INTERNATIONAL GROUP CO., LIMITED - IP: 172.67.150.188 ## Detection Status - VirusTotal: 0 vendors flagged - Google Safe Browsing: clean - Blocklists: 0 hits ## Evidence - Cloudflare Radar: https://radar.cloudflare.com/scan/474f84c2-82dc-4f40-9687-108cda4f67d8 - PhishDestroy: https://phishdestroy.io/domain/phenomtoken.top/ - LLM endpoint: https://phishdestroy.io/domain/phenomtoken.top/llm.txt ## If You Visited This Site 1. Change any passwords you may have entered 2. Enable 2FA on all related accounts 3. Monitor your accounts for unauthorized activity 4. Report to: FBI IC3, Europol, local authorities --- Report by PhishDestroy | https://phishdestroy.io/domain/phenomtoken.top/ Last updated: 2026-03-31