# tokencket.app — MALICIOUS > tokencket.app is a brand impersonation scam impersonating OKX. Detected by 12/95 VirusTotal security vendors. Avoid this high-risk fake site immediately. ## Summary PhishDestroy identifies tokencket.app as an active brand impersonation scam targeting OKX users. This fraudulent domain mimics the legitimate OKX cryptocurrency exchange to deceive visitors into surrendering sensitive data or assets. The site leverages visual and operational similarities to trick users into believing it is an authentic platform, a common tactic in cryptocurrency scams designed to steal funds or credentials. This domain was flagged by 12 out of 95 VirusTotal security vendors, indicating widespread suspicion among cybersecurity tools. It was registered on September 23, 2023, through Dynadot LLC, a domain registrar known for accommodating both legitimate and malicious registrations. The domain resolves to IP address 195.85.59.161 and holds a Google Trust Services SSL certificate, which may give it an appearance of legitimacy to unsuspecting users. Despite its recent creation, the site is actively engaged in malicious activity. If you visited tokencket.app, immediately cease any interaction with the site. Do not enter any credentials, download files, or connect crypto wallets. If you entered login details, change your OKX (or any related) account password immediately using a secure, isolated device. Scan your device with reputable antivirus software and consider revoking any wallet connections made through the site. Report the domain to OKX's official fraud reporting channels and your local cybercrime unit. Monitor your accounts and financial transactions closely for signs of unauthorized activity. ## Threat Details - Verdict: MALICIOUS - Site status: alive (HTTP ?) - Target brand: OKX ## Domain Intelligence - Registered: 2025-09-23 09:16:36 - Registrar: Dynadot LLC. - IP: 195.85.59.161 ## Detection Status - VirusTotal: 12 vendors flagged - Google Safe Browsing: clean - Blocklists: 0 hits ## Evidence - Cloudflare Radar: https://radar.cloudflare.com/scan/fd7dd77b-19f3-4c4f-ae20-e64d46ee7373 - PhishDestroy: https://phishdestroy.io/domain/tokencket.app/ - LLM endpoint: https://phishdestroy.io/domain/tokencket.app/llm.txt ## If You Visited This Site 1. Change any passwords you may have entered 2. Enable 2FA on all related accounts 3. Monitor your accounts for unauthorized activity 4. Report to: FBI IC3, Europol, local authorities --- Report by PhishDestroy | https://phishdestroy.io/domain/tokencket.app/ Last updated: 2026-04-11