# www.imtokentio.com — SUSPICIOUS > imtokentio.com impersonates OKX in a cryptocurrency scam. VirusTotal shows 0/95 detections. Check the full report. ## Summary PhishDestroy identifies imtokentio.com as an active brand impersonation site targeting OKX cryptocurrency exchange users. This domain was flagged within 48 hours of creation on September 2, 2025, and is hosted on a server with IP 156.238.250.124. The site leverages a Let's Encrypt SSL certificate to appear legitimate, despite being registered through Gname.com Pte. Ltd., a registrar often abused by malicious actors for short-lived fraudulent campaigns. This domain poses a high-risk threat through direct OKX impersonation, aiming to deceive users into entering login credentials or financial details into a counterfeit trading interface. VirusTotal currently shows 0 detections out of 95 engines, indicating this threat has not yet been widely recognized by automated scanners. The domain's age (under 48 hours) and low detection rate make it particularly dangerous, as users may unknowingly engage with the fake site before security systems catch up. The registration through Gname.com Pte. Ltd. further correlates with historical patterns of disposable fraud domains. Users who visited imtokentio.com should immediately cease any interaction with the site and disconnect from untrusted networks. Review all recent transactions for unauthorized activity, especially if credentials were entered. Systems administrators should block the IP address 156.238.250.124 at the firewall and add imtokentio.com to network blocklists. Report the domain to your cybersecurity team and OKX’s official fraud reporting channel. Enable multi-factor authentication on all cryptocurrency exchange accounts and use password managers to prevent credential theft. Monitor credit reports for signs of identity compromise. ## Threat Details - Verdict: SUSPICIOUS - Site status: unknown (HTTP ?) - Target brand: OKX ## Domain Intelligence - Registered: 2025-09-02 06:28:17 - Registrar: Gname.com Pte. Ltd. - IP: 156.238.250.124 ## Detection Status - VirusTotal: 0 vendors flagged - Google Safe Browsing: clean - Blocklists: 0 hits ## Evidence - Cloudflare Radar: https://radar.cloudflare.com/scan/2c100faa-8929-424f-88cd-5f8f9be830b8 - PhishDestroy: https://phishdestroy.io/domain/www.imtokentio.com/ - LLM endpoint: https://phishdestroy.io/domain/www.imtokentio.com/llm.txt ## If You Visited This Site 1. Change any passwords you may have entered 2. Enable 2FA on all related accounts 3. Monitor your accounts for unauthorized activity 4. Report to: FBI IC3, Europol, local authorities --- Report by PhishDestroy | https://phishdestroy.io/domain/www.imtokentio.com/ Last updated: 2026-03-25