Skip to content

URGENT: Multiple Crypto Phishing & Wallet Drainer Domains Targeting dYdX Users #686

Description

@mrp300

I am submitting an urgent abuse notification regarding a cluster of malicious Web3 cryptocurrency phishing domains:

Targeted Domains:

dyodx.net (www.dyodx.net)

v2-dydx.at (www.v2-dydx.at)

app.v1-dyxd.net (v1-dyxd.net)

Impersonated Brand: dYdX Protocol / DEX (Official: https://dydx.exchange)

Description of Abuse:
These domains employ deliberate typosquatting ("dyodx", "dyxd") and brand impersonation to target dYdX users. They host automated Web3 wallet-draining infrastructure designed to trick victims into signing fraudulent token approval transactions (Permit/Approve) and harvesting private keys/seed phrases.

Violations:

Financial Cybercrime & Theft: Unauthorized deployment of wallet-draining mechanisms and malicious smart contract interaction scripts.

Typosquatting & Brand Impersonation: Deceptive misrepresentation of dYdX's protected brand identity.

Acceptable Use Policy (AUP) Violation: Severe breach of network, registrar, and registry policies regarding financial fraud and phishing.

Requested Action:
Please immediately suspend hosting and DNS resolution for these domains and place them on clientHold / serverHold status to prevent further financial theft.

Date: August 2, 2026

Reporter: Web3 Threat Intelligence Team

Image Image Image Image Image Image

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions