Protocol-impersonator domain registered (typosquat)
Morpho V1 (Morpho Blue + MetaMorpho)'s assessment for RD-F-161 — scored yellow on the v1.7.0 rubric. The evidence below is the curator's reasoning for this score.
Evidence summary #
morpho-app.org registered December 5, 2025 (within 90-day lookback). Used Angel Drainer kit. DNS now suspended. Active impersonation infrastructure confirmed — threat actor class is live around Morpho brand.
Detail #
Threshold: typo-squat of official domain registered within last 90 days. morpho-app.org registered Dec 5, 2025; hosted at 104.21.1.228; Angel Drainer phishing kit; DNS suspended by assessment date. This confirms a coordinated scam ecosystem. DNS suspension is positive but does not confirm the threat actor cannot register additional domains.
Sources #
- URLhttps://phishdestroy.io/domain/morpho-app.orgretrieved 2026-04-27
Methodology #
Determine whether a typosquat of the official protocol domain has been registered in the last 90 days.
See the full factor methodology and distribution across all protocols →