Phishing detection: metamask-docs-p13jojaa8-consensys-ddffed67.vercel.app

MetaMask
http://metamask-docs-p13jojaa8-consensys-ddffed67.vercel.app/metamask-connect Access site
Screenshot
Screenshot of metamask-docs-p13jojaa8-consensys-ddffed67.vercel.app
Investigate
Domain metamask-docs-p13jojaa8-consensys-ddffed67.vercel.app0 CT hosts on apex
URL http://metamask-docs-p13jojaa8-consensys-ddffed67.vercel.ap…
Phishunt analysis Beta
39 medium suspicion suspiciousheuristic risk score · not a probability
Why?
  • +5.3 Keyword match
  • +5.1 Site cluster
  • +5.1 urlscan.io
  • +4.5 Brand in title
  • +4.1 Brand in screenshot
  • +3.7 Brand in domain label
  • +3.4 Shared IP cluster
  • +3.0 OpenPhish
  • +1.1 ASN reputation
  • +1.1 No CSP header
  • +0.6 Long domain
  • +0.6 Suspicious TLD
  • +0.5 Young certificate
  • +0.4 Hyphens
  • +0.3 Free CA
  • +0.1 External scripts
  • +0.1 Deep subdomain
21 signals fired · detector v3.0.0
AI analysis AIBeta
Credential harvesting

Site impersonates MetaMask, the cryptocurrency wallet extension, on Vercel PaaS infrastructure. The wallet-connection path indicates it is designed to steal seed phrases or drain wallets from victims prompted to connect their accounts. Confirmed malicious by OpenPhish and urlscan.

Brand in domain labelKeyword matchOpenPhish
AI-generated from stored detector signals - the AI never visited the site. · 2026-07-23 · confidence 76%
Domain & Network
Whois
Registrar Tucows Domains Inc
Network
Country United StatesUnited States
ASN AS16509
TLS Cert WR1
External detection OpenPhish urlscan.io
CleanGoogle Safe Browsing · PhishTank · TweetFeed
Report this phishing
Network / ASN Amazon.com, Inc.
Registrar Tucows Domains Inc

Tracked from 2026-05-09 01:03 UTC  ·  Last refreshed 2026-08-23 13:30 UTC