risex[.]exchange
“risex.exchange”
Risex.exchange, a domain posing as a legitimate exchange, is flagged by 7 out of 91 VirusTotal vendors as malicious. The domain is now offline, but it previously operated as a fake exchange scam. It was hosted on an IP managed by Cloudflare, Inc., located in the United States. The domain was created on June 4, 2026, and PhishDestroy identified it as a threat by June 19, 2026.
The domain was blocklisted by four entities, including PhishDestroy, MetaMask, ScamSniffer, and SEAL. This indicates a coordinated effort to mitigate the threat posed by this fraudulent operation. The platform risk score of 75 out of 100 underscores the significant risk it posed during its active period.
Despite its relatively short lifespan, risex.exchange managed to deceive users by masquerading as a legitimate exchange platform. The use of a trusted SSL issuer, Google Trust Services, may have lent an air of legitimacy to unsuspecting victims. However, the swift action by security entities and its inclusion on multiple blocklists helped curb its impact. The case of risex.exchange highlights the importance of early detection and rapid response in combating online scams.
Threat Response Pipeline
Public Blocklist Status
Stored Capture
Domain Intelligence
Technical detailsDNS, SSL SANs, timestamps
ICANN OVERSIGHT
Accreditation and RAA context
Accreditation and RAA context
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
VirusTotal Analysis
Evidence & External Reports
Were You Affected by This Site?
If credentials, payment data, or files were exposed, report the incident immediately. Change affected passwords, revoke active sessions, and scan the device.
Report to Your Local Authorities
Select your country to get official cybercrime contacts, or create a complaint draft →.
Check Any Domain
Threat analysis using stored blocklist, WHOIS, DNS, and public scan evidence
Scan NowReport Phishing
Submit suspicious domains to our threat database — protect the community
ReportLive Threat Feed
Recent phishing reports and observed availability changes
MonitorStay Informed, Stay Safe
Monitor live threats or contest this listing if you believe it's a false positive