# testnet-play.nexawarriors.cash — SUSPICIOUS > testnet-play.nexawarriors.cash is linked to credential theft with 0/95 VirusTotal detections. Users should proceed cautiously and avoid sharing data. ## Summary testnet-play.nexawarriors.cash is currently under investigation for posing a credential theft threat. This means it may attempt to deceive users into revealing sensitive login information, potentially compromising their accounts and digital assets. The domain's association with a credential theft scheme suggests it could be used to harvest usernames, passwords, or other authentication data, which is a common tactic in crypto-related scams. Technical analysis reveals the domain resolves to IP address 75.119.143.213 and uses a Let's Encrypt SSL certificate, which can lend an appearance of legitimacy despite malicious intent. According to VirusTotal, the site has 0 detections out of 95 antivirus engines, indicating it has not yet been flagged by major security vendors. The domain's status is active and under investigation, but no additional registrar or creation date data has been provided. No blocklist counts are currently recorded, which may suggest it is newly registered or not yet widely reported. Users who have visited testnet-play.nexawarriors.cash should remain vigilant and avoid entering any personal or login credentials on this site. It is advisable to change passwords if any information was submitted and enable two-factor authentication on related accounts. Monitoring for unusual activity on connected accounts and devices is also recommended. Until further notice, users should refrain from interacting with this domain and report any suspicious communications linked to it to their security teams or service providers. ## Threat Details - Verdict: SUSPICIOUS - Site status: unknown (HTTP ?) ## Domain Intelligence - Registrar: REGISTRAR_NOT_FOUND - IP: 75.119.143.213 ## Detection Status - VirusTotal: 0 vendors flagged - Google Safe Browsing: clean - Blocklists: 0 hits ## Evidence - Cloudflare Radar: https://radar.cloudflare.com/scan/54225cb4-f59a-4ef7-a188-9e84e083e9e7 - PhishDestroy: https://phishdestroy.io/domain/testnet-play.nexawarriors.cash/ - LLM endpoint: https://phishdestroy.io/domain/testnet-play.nexawarriors.cash/llm.txt ## If You Visited This Site 1. Change any passwords you may have entered 2. Enable 2FA on all related accounts 3. Monitor your accounts for unauthorized activity 4. Report to: FBI IC3, Europol, local authorities --- Report by PhishDestroy | https://phishdestroy.io/domain/testnet-play.nexawarriors.cash/ Last updated: 2026-04-01