hyperilquid[.]co
Verifica phishing e sicurezza per hyperilquid.co
hyperilquid.co — Contenuto non disponibile (HTTP 502). Simulazione del marchio: Hyperliquid; Tipo di truffa: Brand Impersonation. Riepilogo delle prove: VirusTotal 3/94 (Fortinet, Seclookup, SOCRadar); Spamhaus DBL_SPAM; 2 external blocklist matches (MetaMask, SEAL); PhishDestroy score 66/100. Registrar: Dynadot.
L’analisi dettagliata di PhishDestroy AI resta in inglese per preservare il rapporto forense originale.
PhishDestroy identifies hyperilquid.co as a live brand impersonation domain targeting Hyperliquid, a well-known decentralized liquidity protocol. The domain is not associated with any legitimate drainer kit at this time, but it is actively masquerading as Hyperliquid’s official interface to deceive users into connecting wallets or entering credentials. The setup suggests a classic phishing operation designed to harvest private keys or seed phrases under the guise of trading or liquidity provision. The threat is classified as ‘under_investigation’ due to the low VT detection rate and lack of confirmed malicious payload delivery, but the intent is clear: fraudulent brand exploitation.
Technical analysis reveals critical red flags: VirusTotal currently scores the domain at 3/95 detections, indicating it remains undetected by most antivirus engines. It resolves to IP 130.12.180.128, hosted on infrastructure associated with suspicious activity. The domain was registered on April 06, 2026, through Dynadot Inc., a registrar known to host numerous fraudulent domains. It uses a Let's Encrypt SSL certificate, which is common among phishing sites to appear legitimate. Google Safe Browsing (GSB) status is not yet flagged, and blocklist inclusion remains at zero—further highlighting the need for proactive detection.
As of this report, hyperilquid.co remains active and unresolved. PhishDestroy has flagged the domain for brand impersonation and escalated it for further analysis. Users are advised to avoid interacting with this domain or any links associated with it. The current risk is elevated due to the absence of automated detection and the domain’s recent creation date, which allows it to evade early-stage filters. Immediate blocking at the network and endpoint level is recommended. The investigation is ongoing, and updates will be provided as new intelligence emerges.
Pipeline di risposta alle minacce
Stato della lista di blocco pubblica
Analisi di VirusTotal
Dati e relazioni esterne
PD-20260406-2EC5F5 Recipient: abuse@dynadot.com Questo sito ti ha influenzato in qualche modo?
Se hai inserito credenziali dell'account, informazioni personali o di pagamento oppure hai scaricato un file da questo dominio, agisci immediatamente. Di seguito sono riportate le risorse per aiutarti a segnalare l'incidente e proteggerti.
Segnalalo alle autorità locali
Seleziona il tuo Paese per ottenere contatti ufficiali del crimine informatico o creare una bozza di reclamo →.
Verifica qualsiasi dominio
Analisi delle minacce utilizzando blocklist archiviate, WHOIS, DNS e prove di scansione pubblica
Scansiona oraSegnala un tentativo di phishing
Segnala i domini sospetti al nostro database delle minacce — proteggi la comunità
SegnalaFeed in tempo reale sulle minacce
Segnalazioni recenti di phishing e modifiche osservate della disponibilità
MonitoraRimani informato, rimani al sicuro
Controlla le minacce in tempo reale oppure contesta questa segnalazione se ritieni che si tratti di un falso positivo