polymarket-bot-nextjs[.]vercel[.]app
“Polymarket Liquidity Bot”
Сохранённое обнаружение
Обнаружена маскировка
- Тип маскировки
status_split- Оценка маскировки
- 1/6
Сводка доказательств
This domain, polymarket-bot-nextjs.vercel.app, operates as a fraudulent Polymarket liquidity bot interface designed to deceive cryptocurrency users into disclosing wallet credentials or transferring funds. The site mimics legitimate trading automation tools by presenting a fake dashboard labeled 'Polymarket Liquidity Bot,' a tactic commonly employed in phishing campaigns targeting decentralized finance platforms. Analysis indicates the domain is actively harvesting sensitive information, likely through embedded form fields or malicious JavaScript payloads that intercept user input before submission to attacker-controlled endpoints.
Infrastructure analysis reveals multiple high-confidence indicators of compromise. The domain is registered through Vercel Inc. and resolves to the IP address 64.29.17.131, geolocated to the United States. It appears on three distinct security blocklists, including those maintained by cryptocurrency security providers, and is flagged by 1 of 95 security vendors on VirusTotal. The SSL certificate, issued by Google Trust Services (WR1), provides no inherent legitimacy, as phishing sites frequently abuse free certificate authorities to create a false sense of security. The domain remains active as of this report, with no observed takedown attempts from the hosting provider.
Users who have visited polymarket-bot-nextjs.vercel.app or interacted with its content should immediately revoke any connected wallet permissions and transfer assets to a new, secure wallet address. All credentials entered on the site must be considered compromised and should be changed across all platforms where identical or similar passwords were used. Network-level indicators, including the domain and IP 64.29.17.131, should be added to firewall and intrusion detection systems to prevent further exposure. Organizations should monitor for outbound connections to this infrastructure, particularly from systems that handle cryptocurrency transactions or store sensitive financial data.
Data Coverage
Данные сетевой безопасности
Процесс реагирования на угрозы
Проверка по блок-листам
10 внешних источников под наблюдением · снимок от 13.08.2026
8 внешних источников под наблюдением Совпадений нет
Хронология обнаружения
-
VirusTotal
0 → 1
Анализ VirusTotal
Анализ производительности сайта
Google PageSpeed Insights — mobile performance audit of polymarket-bot-nextjs.vercel.app · checked Mar 21, 2026
Повлиял ли на вас этот сайт?
Если вы ввели учетные данные, личную или платежную информацию или загрузили файл с этого домена, примите немедленные меры. Ниже приведены ресурсы, которые помогут вам сообщить об инциденте и защитить себя.
Сообщите об этом в местные органы власти
Выберите свою страну, чтобы получить официальные контакты по киберпреступности или создать проект жалобы →.
Проверить любой домен
Анализ угроз с использованием сохраненного черного списка, WHOIS, DNS и общедоступных доказательств сканирования.
Сканировать сейчасСообщить о фишинге
Добавляйте подозрительные домены в нашу базу данных угроз — защищайте сообщество
СообщитьПоток оперативных данных об угрозах
Недавние сообщения о фишинге и наблюдаемые изменения доступности
ОтслеживатьБудьте в курсе событий, берегите себя
Отслеживайте актуальные угрозы или оспорьте эту запись, если считаете, что это ложное срабатывание