Analysis of the domain web3-ai10.top shows a newly‑registered internet resource that is actively being used for malicious phishing campaigns. The domain was created on July 30, 2026 and is registered through Dynadot LLC. It is delegated to the authoritative nameservers ns1.dyna-ns.net and ns2.dyna-ns.net, which are commonly associated with fast‑flux and disposable hosting services. DNS resolution points to the IPv4 address 85.137.57.218; no additional hostnames or reverse‑DNS entries have been observed for this IP.
The domain is presently listed on three security blocklists and has been explicitly blocked by PhishDestroy, MetaMask, and SEAL, indicating that multiple threat‑intelligence feeds have identified it as a phishing vector. VirusTotal reports that the domain was scanned by 91 vendors, and none of those scanners have generated a detection at the time of the scan; however, the absence of detections does not constitute a safety guarantee, especially given the recent creation date and active blocklist entries. No SSL/TLS certificate data, HTTP status codes, or page‑title information are available from the current intelligence set, leaving the exact content and hosting behavior unverified.
The lack of visible site metadata, combined with the rapid registration and immediate blocklist inclusion, suggests a short‑lived, opportunistic phishing operation likely targeting users of Web3 or AI‑related services. Defenders should proactively deny DNS resolution for web3-ai10.top, incorporate the domain into network‑level blocklists, and monitor outbound connections to the associated IP address. Continuous re‑scanning with sandbox and URL‑analysis tools is recommended to capture any evolving payloads, and any observed traffic should be reported to shared threat‑intel platforms to improve collective visibility.