thecrypto[.]capital
“The Crypto Capital”
Evidence Summary
The domain www.thecrypto.capital is a confirmed phishing site engaged in brand impersonation targeting users of the cryptocurrency platform 'base'. It operates as a cryptocurrency scam, designed to deceive victims into believing they are interacting with a legitimate service. No drainer kit was detected, but the site was actively used for fraudulent purposes before being taken offline.
Technical analysis of www.thecrypto.capital reveals limited but notable detection. As of the latest scan, 1 of 95 VirusTotal security vendors flagged the domain, while Google Safe Browsing did not issue a warning. The domain appears on 1 security blocklist, specifically PhishDestroy. Registered through GoDaddy.com, LLC on November 09, 2024, it resolves to the IP address 13.60.143.163, hosted on Amazon.com, Inc. infrastructure (AS16509) in Sweden. The SSL certificate was issued by Let's Encrypt (E7), and the observed page title was 'The Crypto Capital'. Detected technologies include Ubuntu, Bootstrap, Nginx, jQuery, Mautic, and DataTables. Gridinsoft assigned a trust score of 0 out of 100, further indicating its malicious nature.
Users who interacted with www.thecrypto.capital should immediately revoke any token approvals granted to unknown contracts and transfer remaining funds to a new, secure wallet. If credentials were entered, change passwords on the legitimate 'base' platform and enable two-factor authentication. Monitor accounts for unauthorized transactions and report the incident to the impersonated brand's support team. Additionally, victims can submit the domain to platforms like Google Safe Browsing, PhishTank, or local cybersecurity authorities to prevent further abuse.
Data Coverage
Threat Response Pipeline
Blocklist coverage
10 monitored external feeds · stored snapshot Aug 13, 2026
10 monitored external feeds No match
Stored Capture
Domain Intelligence
Technical detailsDNS, TLS names and timestamps
ICANN OVERSIGHT
Accreditation and RAA context
Accreditation and RAA context
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Technologies
6 high-confidence technologies identified
VirusTotal Analysis
Site Performance Analysis
Google PageSpeed Insights — mobile performance audit of thecrypto.capital · checked Mar 7, 2026
Were You Affected by This Site?
If credentials, payment data, or files were exposed, report the incident immediately. Change affected passwords, revoke active sessions, and scan the device.
Report to Your Local Authorities
Select your country to get official cybercrime contacts, or create a complaint draft →.
Check Any Domain
Threat analysis using stored blocklist, WHOIS, DNS, and public scan evidence
Scan NowReport Phishing
Submit suspicious domains to our threat database — protect the community
ReportLive Threat Feed
Recent phishing reports and observed availability changes
MonitorStay Informed, Stay Safe
Monitor live threats or contest this listing if you believe it's a false positive