v0-rblx[.]vercel[.]app
“Redeem Robux”
PhishDestroy identifies v0-rblx.vercel.app as an active brand impersonation campaign targeting Roblox users for credential theft. This domain leverages a fraudulent Vercel subdomain to mimic legitimate Roblox login pages, deceiving victims into submitting their credentials.
This domain was flagged by PhishDestroy with a risk level marked as 'under_investigation' due to emerging indicators. Intelligence shows it is registered through Vercel Inc. with 0 detections out of 95 VirusTotal scans, which may indicate a newly deployed or rapidly evolving threat. It resolves to IP 64.29.17.3 and utilizes a Google Trust Services SSL certificate, adding a misleading veneer of legitimacy. Notably, the domain has not yet appeared on any known blocklists, further complicating early detection.
To mitigate exposure to this Roblox credential theft scam, users must avoid clicking on unverified links purporting to be from Roblox, especially those hosted on third-party domains like vercel.app. Always navigate directly to the official Roblox website via a trusted browser bookmark or manually typed URL. Enable two-factor authentication (2FA) on all Roblox accounts as an additional security layer. Organizations should monitor for traffic to this domain and block access via firewall or DNS filtering to prevent credential harvesting. Report suspicious domains to Roblox abuse channels and update threat intelligence feeds to enhance collective defense.
Network Security Intelligence
| Detection System | Indicator | Verdict | Alert |
|---|---|---|---|
| DNS4EU | taprain.com |
malicious | Sinkholed |
Threat Response Pipeline
Public Blocklist Status
Technologies · 2 identified
Cloud platform for frontend deployment, optimized for Next.js.
HTTP Strict Transport Security — forces browsers to use HTTPS connections only.
VirusTotal Analysis
Site Performance Analysis
Google PageSpeed Insights — mobile performance audit of v0-rblx.vercel.app · checked Apr 14, 2026
Evidence & External Reports
Were You Affected by This Site?
If credentials, payment data, or files were exposed, report the incident immediately. Change affected passwords, revoke active sessions, and scan the device.
Report to Your Local Authorities
Select your country to get official cybercrime contacts, or create a complaint draft →.
Check Any Domain
Threat analysis using stored blocklist, WHOIS, DNS, and public scan evidence
Scan NowReport Phishing
Submit suspicious domains to our threat database — protect the community
ReportLive Threat Feed
Recent phishing reports and observed availability changes
MonitorStay Informed, Stay Safe
Monitor live threats or contest this listing if you believe it's a false positive