Analysis of bitcoinhypertoken-ai.web.app indicates that the domain is actively hosting a fraudulent cryptocurrency offering. The page title returned by the web server is “Bitcoin Hyper Official Website | BTC Hyper Layer 2 Presale”, which aligns with the reported scam type of a “Fake Airdrop”. The domain is registered through Google LLC, but the authoritative nameserver information is unavailable (NS_NOT_FOUND). Network resolution points to the IP address 199.36.158.100, a host that appears on two public security blocklists and is already listed by PhishDestroy and SEAL.
VirusTotal has scanned the site with 91 anti‑malware vendors; none of the scanners raised a detection, but the absence of alerts does not constitute a safety guarantee. The brand target is explicitly listed as Bitcoin, suggesting that the operators are attempting to exploit the reputation of the well‑known cryptocurrency. No SSL certificate details, HTTP response codes, or additional metadata are provided, leaving the transport security posture unknown. The domain remains marked as active and is currently under investigation.
Defenders should treat the domain as malicious, enforce network‑level blocking of the host IP and the full domain, and add it to local threat intelligence feeds. Users should be warned against any unsolicited airdrop or presale invitations referencing Bitcoin Hyper or related terms. Continuous monitoring of the IP address for potential pivot activity and periodic re‑scanning with updated detection engines are recommended to capture any future changes in payload or hosting infrastructure.