Suspicious
Phishings targeting KuCoin
Suspicious and active websites
Phishings targeting Kucoin
Suspicious and active websites
Active
7
New (7d)
4
Trend (7d)
↑300%
Suspicious sites — confidence is not always 100%. Use for Threat Hunting or watchlists.
| Last check (UTC) | First seen (UTC) ▾ | URL | Screenshot | Flags | Details |
|---|---|---|---|---|---|
| 2026-09-22 01:02 | 2026-09-22 01:02 | ![]() |
OpenPhish | Details | |
| 2026-09-21 21:30 | 2026-09-21 13:04 | ![]() |
OpenPhish | Details | |
| 2026-09-21 21:30 | 2026-09-20 01:02 | ![]() |
OpenPhish | Details | |
| 2026-09-21 21:30 | 2026-09-15 01:01 | ![]() |
OpenPhish | Details | |
| 2026-09-21 21:30 | 2026-09-14 17:25 | ![]() |
GSB | Details | |
| 2026-09-21 21:30 | 2026-09-05 13:04 | ![]() |
OpenPhish | Details | |
| 2026-09-21 21:30 | 2026-09-04 01:02 | ![]() |
OpenPhish | Details |
Suspicious sites — confidence is not always 100%. Use for Threat Hunting or watchlists.
| URL | Screenshot | Details |
|---|---|---|
| https://kucoinlogin_us.godadd…
OpenPhish |
![]() |
Details |
| https://kucoinloginab.gitbook…
OpenPhish |
![]() |
Details |
| https://kucoinloginaa.gitbook…
OpenPhish |
![]() |
Details |
| http://kucoin-referral-code-p…
OpenPhish |
![]() |
Details |
| https://kucoin9.com
GSB |
![]() |
Details |
| https://kucoinv.com
OpenPhish |
![]() |
Details |
| https://kucoinloign.gitbook.io
OpenPhish |
![]() |
Details |
AIHow to verify a real KuCoin URL
- Legitimate KuCoin URLs always end in
kucoin.com(e.g.www.kucoin.com,account.kucoin.com). Anything else — including look-alike typosquats, hyphenated variations, or unfamiliar TLDs like.xyz/.top/.vip— is not KuCoin. - The padlock icon proves TLS is active, not that the site is safe. Free DV certificates are issued to attackers in minutes; every active site listed above has a valid TLS certificate.
- If you got the link from email, SMS, or social media, do not click it. Open
kucoin.comfrom your browser bookmark or type the domain manually. - Real KuCoin pages almost never ask for credentials immediately after clicking from a message — treat any such redirect as a phishing attempt until the domain is verified.






