polymerkat.com
“Polymarket | The World's Largest Prediction Market™”
Evidence Summary
This domain, polymerkat.com, is flagged as a generic phishing infrastructure impersonating Polymarket, a decentralized prediction market platform. Analysis indicates the site mimics the legitimate Polymarket interface, as evidenced by the page title 'Polymarket | The World's Largest Prediction Market™,' suggesting a targeted credential and cryptocurrency wallet drainer campaign. No specific drainer kit has been attributed yet, but the domain exhibits characteristics consistent with phishing operations designed to harvest user login credentials and private keys. Infrastructure analysis reveals polymerkat.com was registered on April 16, 2026, through Dynadot Inc and resolves to the IP address 172.67.150.195. The domain has been detected on 3 security blocklists and is referenced in 1 AlienVault OTX threat intelligence pulse. Despite these indicators, VirusTotal currently reports 0/95 detections, and the domain has not yet been flagged by Google Safe Browsing. Detected technologies include Google Cloud, Vercel, Amazon Web Services, and advertising trackers such as Twitter Ads and Reddit Ads, which are atypical for legitimate prediction market platforms and suggest malvertising or social engineering vectors. As of the latest assessment, polymerkat.com remains active and under investigation, with no confirmed takedown or sinkholing. Response actions by security entities include blocking by MetaMask, PhishDestroy, and SEAL, indicating recognition of the domain as a threat to cryptocurrency users. The remaining risk is elevated due to the domain's active status, lack of widespread detection, and potential for credential compromise. Users are advised to verify domain authenticity before interaction, avoid entering sensitive information, and cross-reference with official Polymarket communication channels. Organizations should update blocklists to include this domain and monitor for related infrastructure.
Network Security Intelligence
Forensic History & Detection Timeline
-
Domain Status Transition Aug 7, 2026 · 00:15 UTCDomain state transitioned from dead to alive.
-
Domain Status Transition Aug 6, 2026 · 00:30 UTCDomain state transitioned from alive to dead.
-
VirusTotal Detections Update Jun 26, 2026 · 08:26 UTCVirusTotal scanner detections updated from 1 to 0.
-
Cloudflare Radar Scan Apr 21, 2026 · 06:00 UTCCloudflare Radar scan registered: View Radar report.
Threat Response Pipeline
Public Blocklist Status
Technologies · 15 identified
VirusTotal Analysis
Archived Evidence
Community reports
Reported by 1 community member, first seen Apr 20, 2026
- Stored reports
- 1
- Unique reported URLs
- 1
Evidence & External Reports
PD-20260420-41FA76 Recipient: abuse@dynadot.com Were You Affected by This Site?
If credentials, payment data, or files were exposed, report the incident immediately. Change affected passwords, revoke active sessions, and scan the device.
Report to Your Local Authorities
Select your country to get official cybercrime contacts, or create a complaint draft →.
Check Any Domain
Threat analysis using stored blocklist, WHOIS, DNS, and public scan evidence
Scan NowReport Phishing
Submit suspicious domains to our threat database — protect the community
ReportLive Threat Feed
Recent phishing reports and observed availability changes
MonitorStay Informed, Stay Safe
Monitor live threats or contest this listing if you believe it's a false positive