xrpvault.network
“Flare — XRP Staking”
This domain, xrpvault.network, is identified as part of an investment scam infrastructure targeting users with a fraudulent XRP staking scheme.
The detailed PhishDestroy AI analysis below remains in English to preserve the original forensic record.
Evidence Summary
This domain, xrpvault.network, is identified as part of an investment scam infrastructure targeting users with a fraudulent XRP staking scheme. Registered on February 21, 2026, through NiceNIC International Group Co., Limited, the domain resolves to the IP address 216.198.79.65, hosted on Amazon.com, Inc. (AS16509) in the United States. Analysis of its infrastructure reveals the use of Cloudflare nameservers (zara.ns.cloudflare.com and damien.ns.cloudflare.com) and deployment on Vercel, with HSTS enabled. The SSL certificate is classified as R13, and the HTTP status code returned is 451, indicating unavailability due to legal or policy restrictions.
The page title, 'Flare — XRP Staking,' suggests an attempt to impersonate or leverage the Flare Network brand, a known blockchain platform, to deceive victims into engaging with the scam. Google Safe Browsing has flagged the domain for social engineering, aligning with its classification as an investment scam. Detection by security vendors is notable, with 10 out of 93 vendors on VirusTotal marking the domain as malicious. Additionally, the domain appears on four security blocklists and is actively blocked by PhishDestroy, Polkadot, Enkrypt, and Codeesura.
As of July 23, 2026, the domain is offline, though its prior activity and infrastructure remain a concern. Defenders should prioritize monitoring for re-emergence or similar domains leveraging the same hosting, registrar, or nameserver patterns. Organizations are advised to update blocklists with this domain and investigate any historical connections to internal networks or user reports. Given the use of Cloudflare and Vercel, further scrutiny of domains sharing these infrastructure components is recommended to identify related threats.
Network Security Intelligence Registrar context
Forensic History & Detection Timeline
-
Domain Status Transition Jul 27, 2026 · 00:48 UTCDomain state transitioned from dead to alive.
-
Cloudflare Radar Scan Mar 8, 2026 · 07:04 UTCCloudflare Radar scan registered: View Radar report.
-
Domain Status Transition Mar 3, 2026 · 05:11 UTCDomain state transitioned from alive to dead.
-
Cloudflare Radar Scan Mar 2, 2026 · 23:17 UTCCloudflare Radar scan registered: View Radar report.
Threat Response Pipeline
Public Blocklist Status
Evidence Capture
Public Blocklist Status
Stored Capture · 2 sources
Domain Intelligence
Technical detailsDNS, SSL SANs, timestamps
ICANN OVERSIGHT
Accreditation and RAA context
Accreditation and RAA context
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Latest Classified Outcome 2026-09-15 02:31:51 UTC
Technologies · 2 identified
Vercel is a cloud platform for static frontends and serverless functions.
vercel.com 100% confidenceHTTP Strict Transport Security (HSTS) informs browsers that the site should only be accessed using HTTPS.
www.rfc-editor.org 100% confidenceVirusTotal Analysis
Stored outcome evidence
Outcome & takedown attribution
- Outcome
Community reports
Reported by 1 community member, first seen Sep 16, 2025
- Stored reports
- 1
- Unique reported URLs
- 1
Evidence & External Reports
Were You Affected by This Site?
If credentials, payment data, or files were exposed, report the incident immediately. Change affected passwords, revoke active sessions, and scan the device.
Report to Your Local Authorities
Select your country to get official cybercrime contacts, or create a complaint draft →.
Check Any Domain
Threat analysis using stored blocklist, WHOIS, DNS, and public scan evidence
Scan NowReport Phishing
Submit suspicious domains to our threat database — protect the community
ReportLive Threat Feed
Recent phishing reports and observed availability changes
MonitorStay Informed, Stay Safe
Monitor live threats or contest this listing if you believe it's a false positive