pqc-ledger[.]io
Forensic brief
PhishDestroy identifies pqc-ledger.io as an active domain engaged in brand impersonation with elevated risk levels. This domain specifically mimics the Ledger brand, a well-known cryptocurrency hardware wallet provider, to deceive users into divulging sensitive information or transferring digital assets. The threat actor has deployed this domain with malicious intent, leveraging the trusted reputation of the impersonated brand to facilitate fraudulent activities. Current telemetry confirms the domain remains online and operational, posing an ongoing risk to unwary visitors. Technical analysis of pqc-ledger.io reveals multiple red flags consistent with malicious infrastructure. The domain is flagged by 3 of 95 VirusTotal security vendors, indicating preliminary but not definitive malicious classification. It resolves to IP address 104.21.63.93 and is registered through NICENIC INTERNATIONAL GROUP CO., LIMITED. Notably, the domain was created on May 10, 2026, which is a future-dated registration—a tactic sometimes used to obfuscate true ownership timelines. Additionally, this domain has been blocked by the Hagezi blocklist and appears on 1 security blocklist, further corroborating its malicious nature. Despite use of a Let's Encrypt SSL certificate, which may lend a false sense of legitimacy, the overall threat profile remains elevated due to the combination of these indicators. The current status of pqc-ledger.io is active and unremediated, continuing to pose a credible threat to users who may encounter it through phishing campaigns, typosquatting, or malicious advertisements. Given the domain’s impersonation of a major financial brand and its technical alignment with known malicious patterns, PhishDestroy strongly advises immediate caution. Users should avoid interacting with this domain entirely. Organizations are encouraged to update firewall rules, DNS blocklists, and endpoint protection platforms to include pqc-ledger.io and its associated IP address. All communications referencing Ledger should be verified through official, authenticated channels. If exposure is suspected, reset credentials, audit transaction histories, and report the incident to the legitimate brand and relevant cybersecurity authorities.
Threat response pipeline
Cloudflare Radar
VirusTotal
Forensic Evidence CollectionEvidence capture
Domain Intelligence
NICENIC INTERNATIONAL GROUP CO., LIMITED
Technical details
Public blocklist status
VirusTotal consensus
Aggregated detection across 95 security vendors.
Site performance
Site performance analysis
Google PageSpeed Insights — mobile audit of pqc-ledger.io
Evidence & external reports
Were you affected by this site?
Were You Affected?
Recommendations & Advice for Victims
- Do not pay anything else. Recovery agents demanding upfront fees are a second-stage scam.
- Disconnect compromised wallets. Move remaining funds to a fresh seed phrase generated offline.
- Preserve evidence. Screenshot transactions, save URLs, archive emails — chain-of-custody matters for prosecution.
- Report to authorities (see section 15 below) — even small reports help build case patterns.
- Notify your bank/exchange. Some chargebacks may still be possible within 24-72h.
Report to your local authorities
Email template — registrar abuse
abuse@nicenic international group co., limited
Registrar: NICENIC INTERNATIONAL GROUP CO., LIMITED Case: PD-
Embed this report
About this report
About this report: pqc-ledger.io
This domain security report is maintained by PhishDestroy's automated threat-intelligence pipeline. Our system continuously monitors this domain across 95 security vendors on VirusTotal and 2 public blocklists.
The site displays a page titled “Google”.
pqc-ledger.io has been flagged by 3 security vendors as of May 17, 2026.
If you believe this listing is inaccurate, you can submit an appeal. For more information about our methodology, visit our FAQ page.