Search tracked domains and review stored evidence, detections, and the latest observed availability.
How This Attack Works
Fake Token Presale scams trick victims into believing they are investing in legitimate cryptocurrency projects. Here's how the scam typically unfolds:
STEP 1
Create Fake Websites
Scammers set up realistic-looking websites mimicking legitimate token presale portals.
STEP 2
Promote Presale on Social Media
Using social media and fake endorsements, scammers attract potential investors.
STEP 3
Collect Cryptocurrency
Victims are prompted to send cryptocurrency to a specified address under the guise of buying tokens.
STEP 4
Disappear with Funds
Once funds are collected, scammers shut down the site and disappear, leaving victims without recourse.
Technical Analysis
Fake Token Presale scams often leverage phishing tactics combined with cryptocurrency-specific techniques. Attackers use homograph attacks to create URLs that closely resemble legitimate sites, often registered through top registrars like NICENIC INTERNATIONAL GROUP CO., LIMITED and PDR Ltd. d/b/a PublicDomainRegistry.com. They exploit the decentralized nature of blockchain networks, utilizing smart contracts that mimic legitimate presale contracts but are programmed to divert funds to the attacker’s wallet. The infrastructure often involves cloud-based hosting services to quickly deploy and dismantle sites, minimizing the chance of detection. HTML and JavaScript are commonly used to create dynamic, convincing interfaces that reassure potential victims of the site’s legitimacy. Additionally, attackers might deploy SEO techniques to improve the visibility of their fraudulent sites in search engine results, further increasing their reach.
Real Cases
CryptoX Presale Scam (2024)
$2 million stolen
A fake presale for a non-existent token, CryptoX, duped investors into contributing significant sums.
TokenLaunch Fraud (2023)
$1.5 million stolen
Victims were lured into a fake token launch with promises of high returns, only for the site to vanish post-collection.
QuickCoin Deception (2024)
$3 million stolen
Scammers created a sophisticated site mimicking a known exchange, leading to substantial financial losses.
How to Detect
Check for slight misspellings in domain names.
Look for inconsistent branding or layout compared to legitimate sites.
Be wary of unsolicited investment opportunities via social media.
Verify presale details on official project channels.
Beware of high-pressure tactics urging immediate investment.
How to Protect Yourself
1
Always verify URLs before entering personal information.
2
Use browser extensions to detect phishing attempts.
3
Consult official project websites or channels for presale information.
4
Enable two-factor authentication on cryptocurrency exchanges.
5
Report suspicious sites to authorities and platforms like PhishDestroy.
Frequently Asked Questions
Data sourced from PhishDestroy threat intelligence database — 230 domains tracked for this threat type
Fake Token Presale 230 domains


binance-dep30h.com


ripplecareer.com


baforth.guru


dreamsmart.pl


liquidchains.info


claims-bitcoinhyper.com


coiniist-rainbow.xyz


mbato.guru


agaricproku.com


claims-snortertoken.com


debraleslie.com


prizelink.net


appie.shop


coinlist-rainbow.xyz


colnilst.co


dep29k-binance.com


gro39k.info


invest-xai.com


mostgretoko.guru


othersko.guru


pepeheimer-claim.com


retikclaim.web.app


sonami-so.info


thecrito.guru


unilabs.finance


unisara.guru


zama.sale


003-bca.net


dep26k-binance.com


grok49k-cointelegraph.com


llittlepepe.com


myxaicoin.pages.dev


neexoraa.com


purchase2-blockdags-networks.pages.dev


xa500k.com


best-wallettoken.com


claim-pepenode.io


gro39k.org


grok25h.com


hotoj.guru


inqubetai-node.pages.dev


myxaiconnects.net


pepeheimer.io


resolvetics.web.app


ruviai.net


timwarrencoin.io


conilst.co


cryptoallstars-reward.web.app


grok54h-cointelegraph.com


one.link


pepeto-claiming.io


portalbridge.app


rnbw-coiniist.co


alphapepetokenpresale.online


blazpay.org


bullzila.com


grok35k.net


litlelpepe.com


nx0b6we.pages.dev


reward-snortertoken.com


sale-maxidoge.com


spx98k.com


bl0ckdaq.network


dashboard-bestwallet.firebaseapp.com


pepeascensionclaim.pages.dev


qubeticsverification.web.app


xaifusion.com


claim.snortertokn.live


grok35k-fxempire.com


rainbows.run


tapzi-io.xyz


www-grok-allocation.xyz


www.bestwalletsclaim.live


blockdagpresalenetwork.online


gr0k2025.com


gro75k.org


grok35k.com


grok49k.com


harambeaiclaim.web.app


ionichain.com


litltlepepe.com


pump-presale.org


bdagnetwork.info


bitcoinhyperresolves.netlify.app


block-dagnet.live


gro11k.com


gro39k-cointelegraph.com


gro47k.net


gro47k.org


gro87x.com


gro88k.com


gro88k.net


grok49k.net


liquidchain.info
Threat Response Pipeline
How every domain in this hub is verified and how confirmed threats are neutralized. Full pipeline visualization →
Threat Intelligence Checks— every domain is scanned & cross-checked against:
urlscan.ioScreenshot · DOM · HTTPVirusTotal90+ AV enginesGoogle Safe BrowsingTransparency ReportCloudflare RadarDNS · certs · categoriesAlienVault OTXThreat-intel pulsesWayback MachineHistorical evidenceabuse.ch ThreatFoxIOC correlationcrt.shCertificate TransparencyDNS Security FiltersQuad9 · AdGuard · CleanBrowsingWeb-CheckFull surface scan
Global Vendor Sync— confirmed detections are pushed to 29 partners:
GoogleSafe BrowsingGoogleWeb Risk APIMicrosoftSmartScreenVirusTotalDetection feedCloudflareRadar / 1.1.1.1YandexSafe BrowsingURLScan.ioPublic scanESETWebGuardBitdefenderThreat exchangeNortonSafe WebSymantecSiteReviewAviraCloud detectionAvast / AVGWeb ShieldKasperskyOpenTIPDr.WebOnline scannerNetcraftTakedown APIPhishTankVerified voteAPWG eCXBulk feedPhishStatsOpen feedPhish.ReportHosting abuseSpamhausDBL feedPolySwarmMarketplaceCheckPhishBolster scanQutteraMalware scanURLquerySandboxCriminal IPAsset intelCRDFThreat CenterScamadviserTrust scoreMyWOTWeb of Trust