# polymarket.com-v2.v2i.us — SUSPICIOUS > polymarket.com-v2.v2i.us impersonates Polymarket with a fake crypto exchange scam. Avoid entering credentials—VirusTotal flags 0/95 until updated. ## Summary PhishDestroy identifies polymarket.com-v2.v2i.us as an active impersonation scam masquerading as the legitimate cryptocurrency prediction platform Polymarket. This domain employs a lookalike naming scheme (com-v2.v2i.us) to deceive users into believing they are accessing a secondary or mirrored version of the original site. Security analysts note that the threat actor leveraged a Let's Encrypt SSL certificate to enhance credibility, despite the domain's recently registered status and suspicious structure. Users who encounter this domain should immediately cease interaction, as it is designed to harvest login credentials and financial information under the guise of a trusted trading environment. This domain poses a high imminent risk due to multiple red flags confirmed by automated analysis tools. VirusTotal currently reports 0 detections out of 95 engines, indicating the domain has not yet been widely blacklisted or flagged by antivirus vendors. Technical investigation reveals the domain resolves to IP address 35.214.225.47 and was registered through Tucows Domains Inc. on March 22, 2026—less than one day before analysis—demonstrating opportunistic deployment. The use of a .us country-code top-level domain (ccTLD) combined with a nested subdomain structure (v2i.us) is a known tactic used in phishing campaigns to bypass basic domain scrutiny filters. Users who have visited polymarket.com-v2.v2i.us should assume their credentials or payment details may have been compromised. Immediately change passwords for all related accounts—especially Polymarket and any associated financial services—and enable two-factor authentication where available. Monitor bank and crypto accounts for unauthorized transactions, and consider revoking any API keys or connected wallet permissions shared with this impostor site. Report the domain to your browser provider, security vendor, and relevant financial institutions to aid in rapid takedown. Avoid interacting with similar subdomain-based sites that mimic legitimate platforms through convoluted naming patterns. ## Threat Details - Verdict: SUSPICIOUS - Site status: unknown (HTTP ?) ## Domain Intelligence - Registered: 2026-03-22 19:37:50 - Registrar: Tucows Domains Inc. - IP: 35.214.225.47 ## Detection Status - VirusTotal: 0 vendors flagged - Google Safe Browsing: clean - Blocklists: 0 hits ## Evidence - Cloudflare Radar: https://radar.cloudflare.com/scan/f07ee475-463e-49d1-8a0a-d92f761bcf59 - PhishDestroy: https://phishdestroy.io/domain/polymarket.com-v2.v2i.us/ - LLM endpoint: https://phishdestroy.io/domain/polymarket.com-v2.v2i.us/llm.txt ## If You Visited This Site 1. Change any passwords you may have entered 2. Enable 2FA on all related accounts 3. Monitor your accounts for unauthorized activity 4. Report to: FBI IC3, Europol, local authorities --- Report by PhishDestroy | https://phishdestroy.io/domain/polymarket.com-v2.v2i.us/ Last updated: 2026-03-22