Suspicious

Phishings targeting KuCoin

Suspicious and active websites


Phishings targeting Kucoin

Suspicious and active websites


About
AICrypto exchange phishing - same login / 2FA-bypass pattern as Binance and Coinbase, often paired with a fake 'suspicious login' or KYC-verification lure.
Countries
United StatesUnited States (5) · The NetherlandsThe Netherlands (3)
TLS certs
YE1 (2) · Google Trust Services (1)
Historical record. phishunt is not tracking any active KuCoin phishing site right now; the 8 entries below are from the 365-day archive (sites taken down, cleaned up, or otherwise inactive). Use them for retrospective analysis, not as a current threat-feed signal.
First seen URL IP Cert Detail
2026-08-30 https://kucoin_o_logi.godaddysites.com 76.223.105.230 - View →
2026-08-30 https://kucoin_u_logi.godaddysites.com 76.223.105.230 - View →
2026-08-22 http://eng-kucoin-us-help.framer.ai 31.43.160.6 YE1 View →
2026-08-22 http://help-kucoinn-eng.framer.ai 31.43.160.6 YE1 View →
2026-08-22 http://public-kucoin-en-us.onepage.website 136.144.226.23 - View →
2026-08-20 https://kucoinloggom.gitbook.io 172.64.147.209 - View →
2026-08-16 http://kucoine-learn-doce.typedream.app 188.114.97.3 - View →
2026-08-14 https://kucoin-compliance-bridge--kucoin-eu-compliance.europe-west4.h… 35.219.200.120 Google Trust Services View →

AIHow to verify a real KuCoin URL

  • Legitimate KuCoin URLs always end in kucoin.com (e.g. www.kucoin.com, account.kucoin.com). Anything else — including look-alike typosquats, hyphenated variations, or unfamiliar TLDs like .xyz / .top / .vip — is not KuCoin.
  • The padlock icon proves TLS is active, not that the site is safe. Free DV certificates are issued to attackers in minutes; every active site listed above has a valid TLS certificate.
  • If you got the link from email, SMS, or social media, do not click it. Open kucoin.com from your browser bookmark or type the domain manually.
  • Real KuCoin pages almost never ask for credentials immediately after clicking from a message — treat any such redirect as a phishing attempt until the domain is verified.