polymarket-bot-nextjs[.]vercel[.]app
“Polymarket Liquidity Bot”
polymarket-bot-nextjs.vercel.app — Encoberto · alcançável. Tipo de golpe: Fake Exchange. Resumo das evidências: VirusTotal 2/94 (ChainPatrol, alphaMountain.ai); 2 external blocklist matches (MetaMask, SEAL); cloaking observed; PhishDestroy score 71/100. Registrador: Vercel.
A análise detalhada do PhishDestroy AI permanece em inglês para preservar o registro forense original.
This domain, polymarket-bot-nextjs.vercel.app, operates as a fraudulent Polymarket liquidity bot interface designed to deceive cryptocurrency users into disclosing wallet credentials or transferring funds. The site mimics legitimate trading automation tools by presenting a fake dashboard labeled 'Polymarket Liquidity Bot,' a tactic commonly employed in phishing campaigns targeting decentralized finance platforms. Analysis indicates the domain is actively harvesting sensitive information, likely through embedded form fields or malicious JavaScript payloads that intercept user input before submission to attacker-controlled endpoints.
Infrastructure analysis reveals multiple high-confidence indicators of compromise. The domain is registered through Vercel Inc. and resolves to the IP address 64.29.17.131, geolocated to the United States. It appears on three distinct security blocklists, including those maintained by cryptocurrency security providers, and is flagged by 1 of 95 security vendors on VirusTotal. The SSL certificate, issued by Google Trust Services (WR1), provides no inherent legitimacy, as phishing sites frequently abuse free certificate authorities to create a false sense of security. The domain remains active as of this report, with no observed takedown attempts from the hosting provider.
Users who have visited polymarket-bot-nextjs.vercel.app or interacted with its content should immediately revoke any connected wallet permissions and transfer assets to a new, secure wallet address. All credentials entered on the site must be considered compromised and should be changed across all platforms where identical or similar passwords were used. Network-level indicators, including the domain and IP 64.29.17.131, should be added to firewall and intrusion detection systems to prevent further exposure. Organizations should monitor for outbound connections to this infrastructure, particularly from systems that handle cryptocurrency transactions or store sensitive financial data.
Inteligência de segurança de rede
Pipeline de resposta a ameaças
Status da lista de bloqueios pública
Tecnologias · 2 identified
Cloud platform for frontend deployment, optimized for Next.js.
HTTP Strict Transport Security — forces browsers to use HTTPS connections only.
Análise do VirusTotal
Análise de desempenho do site
Google PageSpeed Insights — mobile performance audit of polymarket-bot-nextjs.vercel.app · checked Mar 21, 2026
Evidências e relatórios externos
Você foi afetado por este site?
Se você inseriu credenciais de conta, informações pessoais ou de pagamento, ou baixou um arquivo deste domínio, tome medidas imediatas. Abaixo estão os recursos para ajudá-lo a relatar o incidente e se proteger.
Notifique as autoridades locais
Selecione seu país para obter contactos oficiais do cibercrime ou crie um rascunho de reclamação →.
Verificar qualquer domínio
Análise de ameaças usando lista de bloqueio armazenada, WHOIS, DNS e evidências de verificação pública
Digitalize agoraDenunciar phishing
Envie domínios suspeitos para nosso banco de dados de ameaças — proteja a comunidade
DenunciarFeed de ameaças em tempo real
Relatórios recentes de phishing e alterações de disponibilidade observadas
MonitorarMantenha-se informado, mantenha-se seguro
Monitore ameaças em tempo real ou conteste esta listagem caso acredite que se trate de um falso positivo