During an investigation on November 16, 2025, security researchers identified suspicious activity in CypherGoat's traffic logs originating from the domain cyhpergoat.com. This case was classified as a classic typosquatting attack, where the threat actor swapped the letters "ph" for "hp" in an attempt to deceive unsuspecting users.
A closer analysis revealed that the attacker had created a pixel-perfect visual clone of the legitimate CypherGoat service. The domain had been registered merely 24 hours prior to detection, indicating a premeditated phishing operation aimed at stealing user funds.
However, further investigation into the threat infrastructure uncovered a critical flaw in the attacker's setup. The cloned site completely lacked a backend and had no technical capability to execute crypto swaps. In reality, the malicious site was simply forwarding all incoming traffic directly to CypherGoat's legitimate servers. Consequently, despite the malicious intent, user funds and data were never at risk.
To mitigate the threat, the incident response team promptly contacted Cloudflare, which was providing DNS services for the malicious domain, as well as Nicenic, the domain registrar. Both parties were provided with documented evidence of the impersonation.
In parallel, CypherGoat's engineers implemented an elegant technical workaround to instantly neutralize the attack on their end. They modified their backend to intercept requests originating from the spoofed domain. As a result, all traffic routed through cyhpergoat.com was immediately blocked, and the attackers received a single message: Access denied. Nice try, counterfeit goat.
source
https://cyphergoat.com/blog/phishing-attempt
Trust Rating
related to the category