Protocol-impersonator domain registered (typosquat)
BENQI's assessment for RD-F-161 — scored yellow on the v1.7.0 rubric. The evidence below is the curator's reasoning for this score.
Evidence summary #
Typosquat monitoring: `bnqi.fi` was registered 2026-03-11 — 66 days before assessment date 2026-05-16, which is within the 90-day window. PhishDestroy confirmed phishing classification (risk score 80/100): domain mimics Benqi and also impersonates the Across protocol. Listed on three public security blocklists: MetaMask, PhishDestroy, and SEAL. VirusTotal 1/1 vendor detection. Hosted on Cloudflare CDN (IP 104.21.19.12). Registrar: Immaterialism Ltd (UK). Domain is currently offline (HTTP 403 Forbidden) but within the active 90-day monitoring window. Additionally, b-enqi.fi appears in web search results as a BENQI-positioned site (returned HTTP 403 on direct fetch; registration date not confirmed in public data — insufficient to count separately without blocklist confirmation). The 90-day window is defined as a curator call per taxonomy; at 66 days bnqi.fi is within the window and carries three blocklist confirmations.
Sources #
- URLOfficial BENQI domain — benqi.fi (reference for typosquat comparison)https://benqi.fi/retrieved 2026-05-16
- PhishDestroy bnqi.fi report — registered 2026-03-11, phishing confirmed, 3 blocklists, 1/1 VirusTotal detectionhttps://phishdestroy.io/domain/bnqi.fi/retrieved 2026-05-16
Methodology #
Determine whether a typosquat of the official protocol domain has been registered in the last 90 days.
See the full factor methodology and distribution across all protocols →