swapgate[.]online
“Bitcoin & Crypto Exchange. Fast & Secure Crypto Swap | swapgate.online”
Evidence Summary
Analysis of swapgate.online indicates a crypto scam domain impersonating the NEAR Protocol, operational from July 29, 2025, until its takedown. The domain resolved to 62.60.226.213 (AS214351, FEMO IT SOLUTIONS LIMITED, DE) and used Porkbun LLC nameservers (curitiba.ns.porkbun.com, fortaleza.ns.porkbun.com, maceio.ns.porkbun.com, salvador.ns.porkbun.com). No SSL certificate was detected, increasing exposure to interception risks. The page title, 'Bitcoin & Crypto Exchange. Fast & Secure Crypto Swap | swapgate.online,' aligns with crypto-themed fraud, though specific functionality remains unconfirmed due to the domain's offline status.
Detection data shows 10 of 95 security vendors on VirusTotal flagged the domain as malicious. It appears on one security blocklist and was included in an AlienVault OTX threat intelligence pulse, confirming its classification as a crypto scam. Gridinsoft assigned a trust score of 0/100, reinforcing its high-risk designation. The domain was blocked by PhishDestroy prior to going offline.
Defenders should treat this domain as confirmed malicious infrastructure. Historical DNS records and IP associations should be reviewed for potential lateral movement or reuse of hosting resources. Monitoring for re-registration or similar domains under Porkbun or the same hosting provider is recommended. No evidence suggests this domain was part of a broader phishing kit or campaign beyond its stated crypto scam classification.
Data Coverage
Threat Response Pipeline
Blocklist coverage
10 monitored external feeds · stored snapshot Aug 11, 2026
10 monitored external feeds No match
Detection timeline
-
Cloudflare Radar
Cloudflare Radar scan stored · Open scan
Stored Capture
Domain Intelligence
Technical detailsDNS, TLS names and timestamps
ICANN OVERSIGHT
Accreditation and RAA context
Accreditation and RAA context
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
VirusTotal Analysis
Were You Affected by This Site?
If credentials, payment data, or files were exposed, report the incident immediately. Change affected passwords, revoke active sessions, and scan the device.
Report to Your Local Authorities
Select your country to get official cybercrime contacts, or create a complaint draft →.
Check Any Domain
Threat analysis using stored blocklist, WHOIS, DNS, and public scan evidence
Scan NowReport Phishing
Submit suspicious domains to our threat database — protect the community
ReportLive Threat Feed
Recent phishing reports and observed availability changes
MonitorStay Informed, Stay Safe
Monitor live threats or contest this listing if you believe it's a false positive