Analysis of arcadexe.io indicates that the domain is actively being used for a high‑risk phishing campaign as of the report date, July 30, 2026. The domain was registered on July 29, 2026 through Namecheap Inc., and its authoritative nameservers are dns1.registrar-servers.com and dns2.registrar-servers.com. DNS resolution points to the address 23.139.82.99, confirming a single‑host infrastructure that is currently reachable. Google Safe Browsing classifies the site under the social engineering category, and three independent security blocklists have listed the domain.
Specific blocklist operators that have taken action include PhishDestroy, MetaMask, and SEAL, demonstrating that multiple threat‑intelligence feeds recognize the domain as malicious. VirusTotal analysis shows that 4 of 91 scanned security vendors have flagged the domain, providing additional corroboration of its suspicious nature. No publicly available SSL certificate details, HTTP response codes, or page title information have been disclosed, leaving those aspects of the site’s surface unverified.
Consequently, defenders should treat arcadexe.io as a confirmed phishing vector, block network communications to the domain and its resolved IP address, and add the domain to local deny lists. Continuous monitoring of the associated IP and any future DNS changes is advised, as the infrastructure could be expanded. Organizations employing web filtering or DNS sinkhole solutions should ensure the domain is included in their block policies, and incident response teams should be prepared to investigate any user reports involving the domain, given its recent creation and active status.