uniswapv3[.]limited
“Bitwarder | Bitwarder Giriş | Your One- Stop Design Solution | Bitwarder”
The domain uniswapv3.limited is currently listed as offline but retains a set of indicators that merit continued monitoring. Registration was performed through Cloudflare, Inc., and the domain is delegated to the Cloudflare authoritative nameservers darwin.ns.cloudflare.com and mallory.ns.cloudflare.com. DNS resolution points to the IP address 172.67.223.40, which belongs to AS13335 Cloudflare, Inc. and is geolocated in the United States. No SSL/TLS certificate was observed for the site, meaning HTTPS connections would be unencrypted if the domain were to become active again.
The page title retrieved from the site reads "Bitwarder | Bitwarder Giriş | Your One- Stop Design Solution | Bitwarder," indicating that the underlying web content is unrelated to the targeted brand. Nonetheless, threat intelligence classifies the domain as a crypto‑related brand impersonation campaign targeting Uniswap, with the scam type identified as a crypto scam. Security scanning on VirusTotal shows that three of ninety‑five vendors flagged the domain, and it appears on a single security blocklist. The site has been blocked by PhishDestroy and received a Gridinsoft trust score of 0 out of 100, reinforcing the low credibility assessment.
Risk is elevated, and the unique seed ba68ab ties this observation to a broader set of related infrastructure. Defenders should ensure that DNS resolvers and proxy filters block uniswapv3.limited, continue to monitor for any re‑hosting or certificate deployment, and correlate any future traffic to the Cloudflare IP range with existing detection rules. Additional hunting should include checks for the Bitwarder page title in other domains that may share the same hosting footprint, as this could indicate a reusable phishing kit.
Threat Response Pipeline
Public Blocklist Status
Stored Capture
Domain Intelligence
Technical detailsDNS, SSL SANs, timestamps
ICANN OVERSIGHT
Accreditation and RAA context
Accreditation and RAA context
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
VirusTotal Analysis
Evidence & External Reports
Were You Affected by This Site?
If credentials, payment data, or files were exposed, report the incident immediately. Change affected passwords, revoke active sessions, and scan the device.
Report to Your Local Authorities
Select your country to get official cybercrime contacts, or create a complaint draft →.
Check Any Domain
Threat analysis using stored blocklist, WHOIS, DNS, and public scan evidence
Scan NowReport Phishing
Submit suspicious domains to our threat database — protect the community
ReportLive Threat Feed
Recent phishing reports and observed availability changes
MonitorStay Informed, Stay Safe
Monitor live threats or contest this listing if you believe it's a false positive