# tokenverify.live — SUSPICIOUS > PhishDestroy flags tokenverify.live as a crypto drainer that impersonates OKX; domain created 2026-03-28, VT 0/95. ## Summary PhishDestroy identifies tokenverify.live as an active crypto drainer site impersonating OKX to trick users into connecting wallets and signing malicious transactions. The page mimics OKX branding in order to harvest funds and private keys, exposing visitors to immediate theft risk. This domain was flagged on 2026-03-28, registered via GoDaddy.com, LLC less than a day ago and already resolving to IP 77.245.76.110 under a Let’s Encrypt SSL certificate. VirusTotal currently shows 0 detections out of 95 scanning engines, indicating it remains under the radar while the threat actors prepare their campaign. If you visited tokenverify.live, disconnect your wallet immediately and revoke any recently approved permissions in your wallet settings or on etherscan.io. Do not enter credentials or connect any accounts on this site. Report the domain and any transactions involving 0x… to PhishDestroy for rapid takedown and victim assistance. ## Threat Details - Verdict: SUSPICIOUS - Site status: unknown (HTTP ?) - Target brand: OKX ## Domain Intelligence - Registered: 2026-03-28 14:46:45 - Registrar: GoDaddy.com, LLC - IP: 77.245.76.110 ## Detection Status - VirusTotal: 0 vendors flagged - Google Safe Browsing: clean - Blocklists: 0 hits ## Evidence - Cloudflare Radar: https://radar.cloudflare.com/scan/6e849df6-2088-4be9-933e-f2e1a321f37c - PhishDestroy: https://phishdestroy.io/domain/tokenverify.live/ - LLM endpoint: https://phishdestroy.io/domain/tokenverify.live/llm.txt ## If You Visited This Site 1. Change any passwords you may have entered 2. Enable 2FA on all related accounts 3. Monitor your accounts for unauthorized activity 4. Report to: FBI IC3, Europol, local authorities --- Report by PhishDestroy | https://phishdestroy.io/domain/tokenverify.live/ Last updated: 2026-03-28