Analysis of web3-ai03.top indicates an active generic phishing infrastructure launched on July 30, 2026. The domain is registered through Dynadot LLC and resolves to the IPv4 address 85.137.57.218. Authoritative name servers are ns1.dyna-ns.net and ns2.dyna-ns.net, suggesting the use of a dynamic DNS service. The domain currently appears on three external security blocklists and has been flagged by PhishDestroy, MetaMask, and SEAL, confirming its classification as a phishing threat.
VirusTotal reports that the domain has been examined by 91 scanning engines without any current flags; however, the absence of detections does not guarantee safety and should be treated as a neutral data point. No additional intelligence such as SSL certificate details, HTTP response codes, or page titles is available at this time, leaving the exact content and lure mechanisms undocumented. The rapid registration-to-activation timeline and the immediate placement on multiple blocklists suggest a purpose‑built campaign, likely targeting users of blockchain‑related services given the "web3" component of the name.
Defenders should proactively block the domain and its resolving IP at network perimeters, update DNS filtering policies, and monitor for any changes to the name server records or IP address that could indicate a shift in hosting. Continuous re‑scanning with multi‑engine services is recommended to capture any future payloads or malicious scripts that may be deployed. Organizations using web3 or crypto wallets should alert users to the existence of this domain and reinforce credential hygiene, as the threat appears to be actively targeting such ecosystems.