Analysis conducted on July 28, 2026, identifies vote-xaman.live as an active high-risk phishing domain targeting users of the Xaman cryptocurrency wallet. The domain was registered on July 25, 2026, through NICENIC INTERNATIONAL GROUP CO., LIMITED, a registrar frequently associated with abusive registrations. Infrastructure analysis reveals the domain resolves to IP address 188.114.96.3, hosted on Cloudflare nameservers stephane.ns.cloudflare.com and titan.ns.cloudflare.com, a configuration commonly observed in phishing campaigns to obscure hosting origins and leverage Cloudflare's privacy services. Detection metrics indicate the domain is flagged by three security blocklists, including PhishDestroy, MetaMask, and SEAL, which specialize in cryptocurrency-related threats.
VirusTotal scanning reports that 8 of 91 security vendors classify the domain as malicious, though the specific detection signatures and methodologies remain unconfirmed. The domain's recent registration, combined with its immediate appearance on multiple blocklists, suggests a targeted campaign with rapid deployment characteristics. At the time of analysis, the domain remains active, and no confirmed brand impersonation content beyond the domain name itself has been verified. The inclusion of 'xaman' in the domain strongly implies an intent to deceive users seeking the legitimate Xaman wallet service, though the exact phishing mechanism—such as credential harvesting, malicious payload delivery, or cryptocurrency drainer functionality—has not been independently confirmed.
Defenders are advised to treat this domain as hostile and implement blocking measures at the DNS, network, and endpoint layers. Organizations utilizing cryptocurrency transaction monitoring should add vote-xaman.live to their deny lists and alert users to the presence of this threat. Further investigation into associated IP infrastructure and SSL certificates may reveal additional linked domains or campaign clusters.