MALICIOUS — CRITICAL
hyperliq[.]uid[.]ong
The domain hyperliq.uid.ong is a confirmed phishing site engaged in brand impersonation targeting the 'foundation' brand.
- VirusTotal
- 3/91
- Blocklists
- 4 · ScamSniffer, Polkadot
- Kullanılabilirlik
- İçerik kullanılamıyor · HTTP 502
Do not enter credentials, seed phrases, payment details, or personal information on this domain.
Jump to section
hyperliq.uid.ong — İçerik kullanılamıyor (HTTP 502). Marka kimliğine bürünme: Foundation; Dolandırıcılık türü: Brand Impersonation. Kanıt özeti: VirusTotal 3/91 (alphaMountain.ai, CRDF, Gridinsoft); 4 external blocklist matches; PhishDestroy score 82/100.
Özgün adli kaydı korumak için aşağıdaki ayrıntılı PhishDestroy AI analizi İngilizce bırakılmıştır.
Evidence Analysis
The domain hyperliq.uid.ong is a confirmed phishing site engaged in brand impersonation targeting the 'foundation' brand. It presents itself as a legitimate platform related to Hyperliquid, a known entity, but is designed to deceive users into disclosing sensitive information or interacting with fraudulent content. No crypto drainer kit was identified in this campaign. As of the latest verification, hyperliq.uid.ong has been taken offline, though users who interacted with it prior to its removal may still be at risk.
Technical analysis reveals that hyperliq.uid.ong was flagged by 2 of 95 security vendors on VirusTotal, including G-Data and Gridinsoft, which assigned it a trust score of 0/100. The domain appears on 5 security blocklists, including PhishDestroy, ScamSniffer, and Polkadot. It was created on February 21, 2026, and resolved to the IP address 104.21.32.1, hosted by Cloudflare, Inc. (AS13335) in the US. The SSL certificate was issued by Cloudflare TLS Issuing ECC CA 1, and the observed page title was '49.491 | HYPE/USDC | Hyperliquid'. The registrar information is not available.
Users who visited hyperliq.uid.ong should immediately change any credentials entered on the site, enable two-factor authentication (2FA) on all accounts, and monitor for unauthorized transactions or suspicious activity. If cryptocurrency interactions occurred, revoke any token approvals granted to unknown contracts and consider transferring funds to a new wallet. Report the phishing domain to relevant platforms, including Google Safe Browsing, ScamSniffer, and local cybersecurity authorities, to aid in broader mitigation efforts.
Veri kapsamı12 recorded checks
Tehdit Müdahale Pipeline
Genel Engelleme Listesi Durumu
VirusTotal Analizi
Kanıtlar ve Dış RaporlarIndependent lookups and source reports
Victim safety and official reportingImmediate actions and verified reporting channels
Hesap kimlik bilgilerini, kişisel bilgileri veya ödeme bilgilerini girdiyseniz ya da bu alan adından bir dosya indirdiyseniz hemen harekete geçin. Aşağıda olayı bildirmenize ve kendinizi korumanıza yardımcı olacak kaynaklar bulunmaktadır.
Yerel Yetkililere Bildirin
resmi siber suç iletişim bilgileri veya şikayet taslağı oluştur → almak için ülkenizi seçin.