simpleswapdex[.]com
Forensic brief
PhishDestroy identifies simpleswapdex.com as a malicious impersonation of a cryptocurrency exchange portal designed to harvest wallet credentials and private keys from unsuspecting users. The domain leverages social engineering tactics, presenting itself as a legitimate swap platform while operating under the guise of 'SimpleSwap.' Security researchers note that threat actors frequently abuse similar naming conventions to trick users into entering sensitive wallet information. This domain was flagged following its appearance on one security blocklist and immediate detection by MetaMask, which now blocks access to the site. Technical analysis reveals the domain was registered on May 14, 2026, through Dynadot Inc., and resolves to IP address 130.12.180.128. Despite using a valid Let's Encrypt SSL certificate to appear legitimate, VirusTotal currently shows zero detections out of 95 security engines, indicating a newly deployed but unflagged threat. If you visited simpleswapdex.com, stop entering any information immediately. Disconnect your wallet from the site, check your transaction history for unauthorized transfers, and revoke any suspicious token approvals using tools like revoke.cash. Report the domain to your wallet provider and local cybersecurity authorities. Always verify URLs and use official bookmarks or app links for cryptocurrency services.
Threat response pipeline
Cloudflare Radar
Forensic Evidence Collectionabuse@virtualine.org with forensic evidence (metadata, screenshots, PDF).Evidence capture
Domain Intelligence
Dynadot Inc
Technical details
Public blocklist status
VirusTotal consensus
Aggregated detection across 95 security vendors.
Evidence & external reports
Were you affected by this site?
Were You Affected?
Recommendations & Advice for Victims
- Do not pay anything else. Recovery agents demanding upfront fees are a second-stage scam.
- Disconnect compromised wallets. Move remaining funds to a fresh seed phrase generated offline.
- Preserve evidence. Screenshot transactions, save URLs, archive emails — chain-of-custody matters for prosecution.
- Report to authorities (see section 15 below) — even small reports help build case patterns.
- Notify your bank/exchange. Some chargebacks may still be possible within 24-72h.
Report to your local authorities
Email template — registrar abuse
abuse@virtualine.org, abuse@dynadot.com
Registrar: Dynadot Inc Case: PD-PD-20260517-CBB3DC
Embed this report
About this report
About this report: simpleswapdex.com
This domain security report is maintained by PhishDestroy's automated threat-intelligence pipeline. Our system continuously monitors this domain across 95 security vendors on VirusTotal and 2 public blocklists.
The site displays a page titled “SimpleSwap | Swap Crypto”.
simpleswapdex.com has been flagged by 0 security vendors as of May 17, 2026.
If you believe this listing is inaccurate, you can submit an appeal. For more information about our methodology, visit our FAQ page.