VirusTotal
12 / 91
“SyncFlux | Swap ⢠Presales ⢠Deploy ⢠Launch ⢠Earn”
The sent-report ledger records the first outgoing report at .
The recorded recipient is abuse@whiteprivacy.com.
The latest stored availability evidence still shows the domain reachable; 5 months has elapsed since the first outgoing report.
ICANN RAA §3.18 describes registrar abuse-contact and handling obligations. This section records outgoing timestamps, listed recipients, case identifiers, and later availability. It does not by itself prove receipt, acknowledgement, investigation, remediation, or contractual non-compliance.
12 / 91
1/100
Reportchecked — no detections recorded
Reportchecked — no match recorded
16 community references
Reportprovider verdict: suspicious
Reportstored report
Report Analysis completed
Report14 checked — no blocks
Checked; no threat flag recorded
ReportPhishDestroy identifies sfxprotocol.online as an active domain engaged in brand impersonation against Sei, a Layer-1 blockchain network. The domain mimics official Sei branding to deceive users into entering sensitive credentials or downloading malicious payloads. Cybersecurity teams should treat this domain as a high-risk threat vector due to its intent to exploit trust in the Sei ecosystem, particularly among developers and validators who may interact with protocol-related tools or interfaces.
This domain was flagged by PhishDestroy’s automated pipeline, revealing multiple red flags: it resolves to IP 163.61.188.9 and was registered through NAMECHEAP INC on April 28, 2026. As of this report, VirusTotal shows 3/95 detections, indicating it has not yet been widely blacklisted. The presence of a Let’s Encrypt SSL certificate suggests an attempt to appear legitimate, further increasing its deceptive potential. The impersonation of Sei—a growing blockchain platform—makes this domain particularly dangerous, as attackers often target emerging ecosystems where security monitoring lags.
Users who visited sfxprotocol.online or entered any information should immediately cease further interaction and revoke any credentials or API keys exposed. Run a full malware scan using updated antivirus tools and monitor accounts for unusual transactions or unauthorized access. Report the domain to your security team and platforms such as Google Safe Browsing, PhishTank, or the Sei Foundation’s security contact. Avoid downloading any files or connecting wallets to this domain. Always verify URLs against official Sei channels (e.g., sei.io, sei.network) before interacting.
Full extracted values, their blockchain and collection source. An address found in page content does not establish who controls it.
0x2260FAC5E5542a773Aa44fBCfeDf7C193bc2C599Format validated · Domain analysis0x50c5725949A6F0c72E6C4a641F24049A917DB0CbFormat validated · Domain analysis0x833589fCD6eDb6E08f4c7C32D4f71b54bdA02913Format validated · Domain analysis0x869B1E476139d48E7232DC04034385bDDfAC269BFormat validated · Domain analysis0xfde4C96c8593536E31F229EA8f37b2ADa2699bb2Format validated · Domain analysisIoC extraction recorded 2026-07-29 02:03:12 UTC
Stored crawler-versus-browser observations for this host, plus a live fingerprint check for Keitaro-style traffic distribution systems.
openrestyScanner note: alive_content: raw=ok; http=200; via=https_proxy; server=openresty
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
dns1.lytehosting.comdns2.lytehosting.comdns3.lytehosting.comdns4.lytehosting.comsfxprotocol.onlinepriority 0Location describes the IP network.
487a92449ba91893dfae64f999a3d84c84247e9beddad7bef4e5f76491f9a4caSaved certificate metadata. Certificate dates without a timezone are shown as stored. Transport encryption does not establish that the site is trustworthy.
Google PageSpeed Insights — mobile performance audit of sfxprotocol.online · checked May 7, 2026
10 recorded events. These records describe collected evidence, outgoing notifications and publication; they do not confirm a complete investigation or a takedown.
We scan suspicious URLs, inspect public results and send evidence through the appropriate abuse-reporting channels. The dated events above show what is recorded for this domain. The directory below explains the wider workflow.
Capture the rendered page, requests and visible infrastructure.
Compare the available engine results and retain the analysis timestamp.
Check whether Google currently lists the URL as unsafe.
Inspect a public scan and its recorded network and classification data.
Look for indicator references and related community intelligence.
Compare archived captures and preserve historical context.
Look for matching indicators and associated threat records.
Inspect certificate records and related hostnames.
Compare security resolver responses and record observed blocking.
Inspect the public DNS, TLS, HTTP and technology surface.
Security services used for scanning, reputation checks and reporting are listed below. A service being listed is not evidence that it received, accepted or acted on this particular domain. Recorded submissions appear in the notification history above.
Reported by 1 community member, first seen May 7, 2026
PD-20260507-03B201 Recipient: abuse@whiteprivacy.com Registrar: Namecheap Inc (United States) Policy Violations: Domain Registration Agreement prohibits hacking, misuse of domain to conduct attacks, scam and fraudulent activities; AUP allows immediate suspension Applicable Laws: CFAA 18 U.S.C. §1030, Wire Fraud 18 U.S.C. §1343, CAN-SPAM Act
If credentials, payment data, or files were exposed, report the incident immediately. Change affected passwords, revoke active sessions, and scan the device.
Select your country to get official cybercrime contacts, or create a complaint draft →.
Template-based draft · optional AI wording assistance requires separate consent
Threat analysis using stored blocklist, WHOIS, DNS, and public scan evidence
Scan NowSubmit suspicious domains to our threat database — protect the community
ReportRecent phishing reports and observed availability changes
MonitorMonitor live threats or contest this listing if you believe it's a false positive