voting-hyperlend[.]finance
Phishing and security check for voting-hyperlend.finance
“HyperLend”
PhishDestroy first observed voting-hyperlend.finance on Feb 13, 2026. Positive findings were recorded by VirusTotal, MetaMask, ScamSniffer, SEAL, and Spamhaus DBL. Evidence score: 79/100.
VirusTotal recorded 7 detections among 95 engines: alphaMountain.ai, CyRadar, Fortinet, Gridinsoft, Seclookup, SOCRadar, URLQuery on Jul 18, 2026 at 18:45 UTC. The external blocklist snapshot contained 3 matches (MetaMask, ScamSniffer, SEAL) on Aug 7, 2026 at 14:20 UTC. Spamhaus DBL: DBL_PHISH on Jul 14, 2026 at 10:34 UTC. URLQuery recorded no positive detection. Google Safe Browsing returned no flag on Jun 26, 2026 at 22:46 UTC. URLScan completed without a malicious verdict (score 0) on Mar 27, 2026 at 12:09 UTC.
An access-restricted HTTP 403 response was recorded on Aug 7, 2026 at 02:16 UTC. Latest classified outcome: provider block observed; cause cloudflare antiphishing; mechanism phishing interstitial; observed actor Cloudflare on Aug 7, 2026 at 00:16 UTC. Registration records list NiceNIC International Group Co., Limited as the registrar. At collection time, the domain resolved to 172.67.186.219. Captured page title: “HyperLend”. PhishDestroy classified the observed content as Banking Phishing. DOM analysis completed on Apr 23, 2026 at 03:23 UTC; stored DOM score 0/100. IoC extraction completed on Aug 2, 2026 at 04:01 UTC; stored 0 format-validated wallet addresses and 1 Telegram indicator.
Stored full analysisJun 27, 2026
This domain, voting-hyperlend.finance, operates as a crypto drainer phishing site designed to impersonate the legitimate HyperLend platform. The site targets users by presenting a fraudulent interface that mimics the appearance of a decentralized finance (DeFi) lending service. Once users connect their cryptocurrency wallets, the site executes unauthorized transactions, draining funds from the victim’s account without consent. The threat is classified as a crypto drainer due to its direct financial exploitation mechanism, which bypasses traditional credential theft in favor of immediate asset theft via malicious smart contract interactions. Analysis indicates multiple technical indicators supporting the malicious classification of this domain. The domain was registered on February 21, 2026, through NiceNIC International Group Co., Limited, a registrar frequently associated with high-risk domains. It resolves to the IP address 188.114.97.3 and is flagged by 8 out of 95 security vendors on VirusTotal. Additionally, the domain appears on 4 distinct security blocklists and is actively blocked by wallet security tools such as MetaMask and ScamSniffer. The SSL certificate is issued by Google Trust Services, and the site employs Cloudflare for hosting, which may obscure its true origin and complicate takedown efforts. The Gridinsoft trust score of 0/100 further corroborates its malicious intent. Users who have visited voting-hyperlend.finance or interacted with the site should immediately disconnect any connected wallets and revoke all smart contract approvals associated with the domain. It is critical to audit wallet transactions for unauthorized transfers and report the incident to relevant blockchain security platforms. If funds were transferred, victims should document all transaction hashes and contact their wallet provider for potential recovery options. Additionally, users should monitor their accounts for signs of further compromise and consider resetting credentials for any accounts linked to the wallet. Avoid re-engaging with the domain or any associated URLs to prevent additional exposure.
Network Security Intelligence Registrar Integrity Alert
Threat Response Pipeline
Public Blocklist Status
Stored Capture
Domain Intelligence
Technical detailsDNS, SSL SANs, timestamps
ICANN OVERSIGHT
Accreditation and RAA context
Accreditation and RAA context
ICANN Got Paid. Accountability Did Not Arrive.
For this gTLD, the registrar above operates under an ICANN contract. ICANN collects annual, variable and transaction-based fees tied to registrations, renewals and transfers.
Accreditation: monetized. Accountability: please check back later.
Then the magic starts: ICANN writes RAA §3.18, the registrar investigates abuse inside its own customer base, and victims deliver the evidence for free while every layer waits for someone else to act. If that makes victims feel safer, excellent—the invoice worked.
Latest Classified Outcome 2026-08-07 02:16:18 UTC
Technologies · 3 identified
HTTP Strict Transport Security (HSTS) informs browsers that the site should only be accessed using HTTPS.
www.rfc-editor.org 100% confidenceCloudflare is a web-infrastructure and website-security company, providing content-delivery-network services, DDoS mitigation, Internet security, and distributed domain-name-server services.
www.cloudflare.com 100% confidenceHTTP/3 is the third major version of the Hypertext Transfer Protocol used to exchange information on the World Wide Web.
httpwg.org 100% confidenceVirusTotal Analysis
Archived Evidence
Site Performance Analysis
Google PageSpeed Insights — mobile performance audit of voting-hyperlend.finance · checked Jun 27, 2026
Evidence & External Reports
Were You Affected by This Site?
If credentials, payment data, or files were exposed, report the incident immediately. Change affected passwords, revoke active sessions, and scan the device.
Report to Your Local Authorities
Select your country to get official cybercrime contacts, or create a complaint draft →.
About This Report: voting-hyperlend.finance
Stored evidence snapshot. Source timestamps appear where available.
Captured title: “HyperLend”.
VirusTotal detections for voting-hyperlend.finance: 7 (Aug 7, 2026).
submit an appeal or review the FAQ page.
Check Any Domain
Threat analysis using stored blocklist, WHOIS, DNS, and public scan evidence
Scan NowReport Phishing
Submit suspicious domains to our threat database — protect the community
ReportLive Threat Feed
Recent phishing reports and observed availability changes
MonitorStay Informed, Stay Safe
Monitor live threats or contest this listing if you believe it's a false positive