Notification and current-status evidence
The sent-report ledger records the first outgoing report at .
The recorded recipient is abuse@nicenic.net.
The latest stored availability evidence still shows the domain reachable; 4 months has elapsed since the first outgoing report.
ICANN RAA §3.18 describes registrar abuse-contact and handling obligations. This section records outgoing timestamps, listed recipients, case identifiers, and later availability. It does not by itself prove receipt, acknowledgement, investigation, remediation, or contractual non-compliance.
usdt-swap-no-kyc[.]exchange
“Change USDT to XMR BTC ETH LTC SOL No KYC Fast Swap”
PhishDestroy identifies usdt-swap-no-kyc.exchange as a generic phishing domain currently active in the wild. This fraudulent website impersonates legitimate cryptocurrency exchanges by falsely advertising zero-KYC USDT swap services, a common tactic used to lure victims into providing sensitive wallet credentials or transferring funds directly to attacker-controlled addresses. The domain was registered through NICENIC INTERNATIONAL GROUP CO., LIMITED and has been flagged by 2 security blocklists, including MetaMask and SEAL.
This domain was flagged by 6 of 95 VirusTotal vendors as of the latest scan, indicating that signature-based detection mechanisms have not yet caught up with its threat potential. The domain resolves to IP address 104.21.61.174 and holds a valid SSL certificate issued by Let's Encrypt, which may contribute to its perceived legitimacy. Notably, the domain was created on March 06, 2026, suggesting a very recent deployment aimed at capitalizing on emerging market trends or user urgency. Despite its low VirusTotal detection score, the presence of a valid SSL certificate and recent registration date are red flags that warrant immediate caution.
The current status of usdt-swap-no-kyc.exchange remains under investigation, but users should treat it as a confirmed threat vector due to its active phishing operations and inclusion on multiple security blocklists. To mitigate risk, users are strongly advised to avoid accessing this domain entirely. If interaction has already occurred, disconnect any connected wallets immediately, revoke any granted permissions, and transfer remaining assets to a secure, hardware-backed wallet. Always verify the authenticity of cryptocurrency platforms through official channels and cross-check domain registrations, SSL certificates, and community feedback before engaging with financial services online. Users should also report this domain to their security vendors and relevant cryptocurrency fraud reporting platforms to aid in takedown efforts.
Network Security Intelligence Registrar context
| Detection System | Indicator | Verdict | Alert |
|---|---|---|---|
| Hagezi Threat Feed | usdt-swap-no-kyc.exchange |
malicious | Sinkholed |
| DNS4EU | usdt-swap-no-kyc.exchange |
malicious | Sinkholed |
Threat Response Pipeline
Public Blocklist Status
Stored Capture
Domain Intelligence
Technical detailsDNS, SSL SANs, timestamps
ICANN OVERSIGHT
Accreditation and RAA context
Accreditation and RAA context
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Latest Classified Outcome 2026-08-19 02:49:02 UTC
Forensic Intelligence
VirusTotal Analysis
Archived Evidence
Site Performance Analysis
Google PageSpeed Insights — mobile performance audit of usdt-swap-no-kyc.exchange · checked Apr 7, 2026
Site Configuration Analysis
Evidence & External Reports
PD-20260407-CF9DE6 Recipient: abuse@nicenic.net Were You Affected by This Site?
If credentials, payment data, or files were exposed, report the incident immediately. Change affected passwords, revoke active sessions, and scan the device.
Report to Your Local Authorities
Select your country to get official cybercrime contacts, or create a complaint draft →.
Check Any Domain
Threat analysis using stored blocklist, WHOIS, DNS, and public scan evidence
Scan NowReport Phishing
Submit suspicious domains to our threat database — protect the community
ReportLive Threat Feed
Recent phishing reports and observed availability changes
MonitorStay Informed, Stay Safe
Monitor live threats or contest this listing if you believe it's a false positive