voidswap.finance
“Void | Private Cross-Chain Swaps”
voidswap.finance is under investigation for credential theft with a VirusTotal score of 0/95 detections.
The detailed PhishDestroy AI analysis below remains in English to preserve the original forensic record.
Evidence Summary
The domain voidswap.finance has been identified as a potential threat associated with credential theft. No specific brand impersonation has been reported; however, the nature of this threat concerns the unauthorized collection of user credentials, which is often seen in malicious financial setups. The page title includes references to 'Private Cross-Chain Swaps,' common terms in cryptocurrency, indicating its focus on the crypto market, which heightens the risk of exploitation for financial data.
Technical indicators reveal that the VirusTotal score stands at 0/95, meaning it has not yet been flagged by automated detection systems. The domain was registered through NameCheap, Inc. on February 21, 2026, and currently resolves to the IP address 216.198.79.1. Additionally, it has been recorded on one security blocklist and is known to utilize Vercel and HSTS technologies. The presence of an SSL certificate from Let's Encrypt indicates a level of encryption, but it does not ensure legitimacy, as attackers often employ encryption to lend credibility to their malicious sites.
Currently, voidswap.finance is taken offline, which indicates immediate mitigation steps have been taken. It has been blocked by PhishDestroy, limiting its access and potential impact. Given that the domain is currently offline, the immediate risk is lowered; however, it remains under investigation due to its initial indicators of being involved in credential theft. Continuous monitoring for any resurgence or similar domains is advisable to prevent future incidents.
Security Signals
Network Security Intelligence
| Detection System | Indicator | Verdict | Alert |
|---|---|---|---|
| DNS4EU | voidswap.finance |
malicious | Sinkholed |
Forensic History & Detection Timeline
-
VirusTotal Detections Update Jun 26, 2026 · 19:10 UTCVirusTotal scanner detections updated from 1 to 0. Resolved alerts: Gridinsoft.
-
VirusTotal Detections Update Mar 1, 2026 · 06:10 UTCVirusTotal scanner detections updated from 1 to 2. Added scanner alerts: SOCRadar.
-
Cloudflare Radar Scan Feb 27, 2026 · 05:00 UTCCloudflare Radar scan registered: View Radar report.
Threat Response Pipeline
Public Blocklist Status
Evasion evidence
Cloaking confirmed: scanners and victims see different content
The page served one response to a browser-like visitor and another to a crawler or security scanner. Cloaking exists only to keep reviewers away from the real landing page.
- Stored cloaking flag
- Observed
- Cloaking type
status_split- Cloaking score
- 1/6
- Last cloaking scan
- Server header seen by scanner
Vercel
Scanner note: dead_http: raw=http_404; http=404; via=https_direct; server=Vercel; provider_error=DEPLOYMENT_NOT_FOUND
Provider response during scan: DEPLOYMENT_NOT_FOUND
Stored Capture · 3 sources
Domain Intelligence
Technical detailsDNS, SSL SANs, timestamps
ICANN OVERSIGHT
Accreditation and RAA context
Accreditation and RAA context
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Technologies · 2 identified
VirusTotal Analysis
Archived Evidence
Site Performance Analysis
Google PageSpeed Insights — mobile performance audit of voidswap.finance · checked Jun 26, 2026
Community reports
Reported by 1 community member, first seen Feb 21, 2026
- Stored reports
- 1
- Unique reported URLs
- 1
Evidence & External Reports
PD-20260220-834725 Recipient: abuse@vercel.com Abuse notice text as sent to the provider
Policy Violations: Acceptable Use Policy (AUP): The domain voidswap.finance is engaged in phishing activities, which directly contravenes the AUP prohibiting illegal activities and fraud. Terms of Service (TOS): The use of this domain for deceptive practices constitutes a violation of the TOS, which reserves the right to suspend or terminate services for such infractions. Applicable Laws (Unknown): Computer Fraud and Abuse Act (CFAA): This U.S. federal law prohibits unauthorized access to computers and networks, which is applicable if the phishing activities target U.S. citizens. Wire Fraud Statute (18 U.S.C. § 1343): This law criminalizes schemes to defraud individuals or entities using electronic communications, relevant in cases of phishing. CAN-SPAM Act: This act regulates commercial email and prohibits misleading header information, applicable if the phishing scheme involves deceptive email practices. Regulatory Note: Failure to take immediate action against this domain may result in regulatory scrutiny and potential liability under applicable laws. Non-compliance could expose your organization to legal risks and reputational damage.
Were You Affected by This Site?
If credentials, payment data, or files were exposed, report the incident immediately. Change affected passwords, revoke active sessions, and scan the device.
Report to Your Local Authorities
Select your country to get official cybercrime contacts, or create a complaint draft →.
Check Any Domain
Threat analysis using stored blocklist, WHOIS, DNS, and public scan evidence
Scan NowReport Phishing
Submit suspicious domains to our threat database — protect the community
ReportLive Threat Feed
Recent phishing reports and observed availability changes
MonitorStay Informed, Stay Safe
Monitor live threats or contest this listing if you believe it's a false positive