# tokenpocket.cn — MALICIOUS > tokenpocket.cn (brand impersonation) mimics OKX. Flagged by 11/95 VirusTotal scanners. Avoid downloads or credential entry. Close the tab immediately. ## Summary PhishDestroy identifies tokenpocket.cn as an elevated-risk domain engaged in brand impersonation targeting OKX. This site is likely deployed to trick users into revealing private keys or installing malicious wallet extensions under the guise of an official OKX service. This domain was flagged by 11 out of 95 security vendors on VirusTotal, indicating widespread suspicion. It was registered through Web Commerce Communications Limited on May 23, 2019, and currently resolves to IP 203.168.129.149 using a Let’s Encrypt SSL certificate—legitimacy cues often abused by threat actors. The age of the domain combined with the OKX impersonation pattern suggests long-term fraud intent, especially given its absence of organic web presence outside brand abuse. Users should never click through or interact with any links offering wallet downloads or login prompts tied to OKX from external sites like tokenpocket.cn. Always access official services directly via verified channels. If accidentally visited, disconnect immediately and check browser extensions for unauthorized crypto wallet installers. Report suspicious domains to your antivirus provider and consider blocking 203.168.129.149 at the network level. ## Threat Details - Verdict: MALICIOUS - Site status: unknown (HTTP ?) - Target brand: OKX ## Domain Intelligence - Registered: 2019-05-23 09:16:54 - Registrar: Web Commerce Communications Limited - IP: 203.168.129.149 ## Detection Status - VirusTotal: 11 vendors flagged - Google Safe Browsing: clean - Blocklists: 0 hits ## Evidence - Cloudflare Radar: https://radar.cloudflare.com/scan/7b053c55-7a28-401d-881f-b1984d5c2efa - PhishDestroy: https://phishdestroy.io/domain/tokenpocket.cn/ - LLM endpoint: https://phishdestroy.io/domain/tokenpocket.cn/llm.txt ## If You Visited This Site 1. Change any passwords you may have entered 2. Enable 2FA on all related accounts 3. Monitor your accounts for unauthorized activity 4. Report to: FBI IC3, Europol, local authorities --- Report by PhishDestroy | https://phishdestroy.io/domain/tokenpocket.cn/ Last updated: 2026-03-26