Goxcoins Scam Review 2026: FBI Seized This Fake Exchange
Goxcoins.com is a scam: DFPI-flagged as a fake crypto exchange, its domain now sits on FBI seizure servers. Full evidence inside. Read before you deposit.
1.0 / 5
The nameservers are ns1.fbi.seized.gov and ns2.fbi.seized.gov. In twenty years of fraud investigation, no case file has ever handed me a shorter verdict.
Goxcoins.com is a scam, and this Goxcoins scam review will not ask you to take our word for it. California's Department of Financial Protection and Innovation lists the site on its public Crypto Scam Tracker as a fraudulent trading platform, after a resident reported losing more than $57,000 to a rigged "futures" desk run through the domain. The complaint describes the full machinery: a WhatsApp investment group, two handlers calling themselves "Charles" and "Isabella," promised daily returns, and a withdrawal that froze the moment it was requested. Today the site answers visitors with a single line — "This Website Has Been Seized" — and the domain's own records show whose servers it now points to.
What follows is built from primary sources: the registry record, the DNS data, the regulator's published complaint, and the seizure notice itself. If you have money trapped on this platform, skip ahead to the victim section and act today. If you were about to deposit, the next few minutes will cost you nothing — and may save you everything you were about to wire away.
Domain dossier
Everything below was pulled by our desk on August 12, 2026, from live registry and DNS data.
| Item | What we found |
|---|---|
| Domain | goxcoins.com |
| Domain age | Registered May 13, 2017 — roughly 9 years old |
| Registrar | Gname.com Pte. Ltd. (Singapore) |
| Registry status | Locked: serverDelete, serverTransfer, serverUpdate prohibited |
| Nameservers | ns1.fbi.seized.gov / ns2.fbi.seized.gov |
| A records | 188.114.96.12 and 188.114.97.12 (Cloudflare) |
| MX records | None |
| SSL certificate | Let's Encrypt (free, domain-validated), issued June 21, 2026 |
| Site status | Online, displaying a federal seizure banner |
Our trust score: 3/100 — see why.
What is Goxcoins?
On paper, Goxcoins presented itself as a crypto-trading platform where users could trade futures contracts with promised daily returns. In practice, according to the complaint published by California's DFPI, it was the cash register at the end of a WhatsApp funnel.
The mechanics ran like this. A man calling himself "Charles" posted stock recommendations and position sizes in an investing-focused WhatsApp group, with an assistant, "Isabella," reinforcing the act. Once the audience was warmed up, Charles steered members to GOXCOINS.com to trade crypto futures, and the two of them issued specific instructions on when and how to place each trade. Deposits went in as USDC — dollar-pegged stablecoins sent over the Ethereum network. Irreversible by design.
The company behind the site? There isn't one we could verify. The registrant is redacted for privacy. No corporate name, no physical address, no license number, and no registration with any financial regulator appears anywhere in the records we reviewed. For a business that asked strangers to wire it hundreds of thousands of dollars, Goxcoins kept a remarkable silence about who it was.
And the domain's biography gives the game away. Created in May 2017, goxcoins.com spent most of its life parked: Wayback Machine captures from 2018 and from July 11, 2025 show it redirecting to a for-sale listing on HugeDomains, a domain marketplace. An aged, credible-looking shell, waiting for a buyer. A cached WHOIS record shows the entry was updated on November 25, 2025 — consistent with the shell changing hands. Whatever "exchange" appeared on the domain afterward had no nine-year trading history. It had a nine-year-old costume.
The red flags we found
We count six, and every one is documented.
- The withdrawal that never arrives. When the victim tried to pull money out, the platform announced that withdrawals were "temporarily disabled" pending an "automatic security review." Charles then delivered the real terms: pay 50% of the withdrawal amount, upfront, before any funds could be released. That is advance-fee fraud wearing a support ticket's clothes. No legitimate exchange charges you to touch your own balance. They never do.
- "Daily returns" on crypto futures. Guaranteed daily profit on leveraged derivatives does not exist in any regulated market on this planet. A promise like that is not a marketing flourish. It is the confession.
- The WhatsApp handlers. Strangers who add you to an "investment group," post winning trades, and then walk you onto one specific platform are not advisers — they are the platform's acquisition arm. This is the operating core of the pig-butchering playbook, and Goxcoins followed it line for line, right down to the "high-net-worth" room that demanded a $400,000 minimum buy-in. Greed is the hook. Belonging is the net.
- A recycled nine-year-old domain. ScamAdviser's algorithm looked at goxcoins.com and concluded it was "very likely not a scam but legit and reliable," citing its age and valid SSL. That rating was stale — the scan was over a year old when we checked — but the failure runs deeper than one website: automated checkers reward domain age, and scammers now buy age off the shelf.
- No one home. Redacted ownership, an offshore registrar, no mail server, no corporate entity, and no regulatory registration we could locate anywhere. When the money disappears, there is no one to call, no one to sue, no jurisdiction to complain to. That is not an oversight by the operators. It is the design.
- The seizure. As of this writing, the domain answers on FBI seizure nameservers and serves a banner stating the website has been seized. Whatever the eventual court record shows, domains do not land on fbi.seized.gov through clerical error.
The technical picture
Run the raw data and the story tells itself in five lines.
The registry record shows a domain created on May 13, 2017, last changed on April 23, 2026, and locked at the registry level — server delete, transfer, and update all prohibited, which is how a domain looks when someone other than its owner controls it. The nameservers belong to the FBI's seizure infrastructure. The A records point at Cloudflare, which is simply where the seizure banner is hosted. The SSL certificate is a free 90-day Let's Encrypt cert issued on June 21, 2026, and it proves exactly one thing: that whoever requested it controlled the domain on that date. It says nothing — nothing — about honesty.
One more detail worth your attention. There is no MX record, meaning the "exchange" could not even receive email at its own domain. Customer support lived where the scam lived: inside the WhatsApp chat.
Compare that with what the automated tools said. ScamAdviser's cached page for goxcoins.com awards it an "average to good" trust score on the strength of its age and its certificate, and its stale WHOIS snapshot — last updated November 25, 2025 — preserves the moment the shell was being fitted out as an exchange. Age is a fact. Trustworthiness is a judgment. Confusing the two is how learning to check whether a website is legit became a survival skill rather than a hobby.
What victims are saying
The most detailed public account comes from the DFPI complaint itself. A California resident joined a WhatsApp investing group, followed Charles and Isabella onto the platform, and watched the account balance grow — numbers on a screen, controlled by the same people asking for more deposits. When the pair began pushing a new "high-net-worth" group requiring a minimum investment of $400,000, the victim finally tried to withdraw. The platform disabled the withdrawal. Charles demanded a 50% upfront payment to release it. The resident refused, reported the operation, and is out more than $57,000. Per the DFPI entry, the money traveled over Ethereum to a single wallet address, which the regulator published: 0x571d7fc3749212ed7e463e592d846b398491dc5b.
You will not find a Goxcoins review page on Trustpilot — we looked, and we could not locate one as of this writing. Platforms built this way do not accumulate reputations. They burn through domains, and each burned domain takes a fresh set of victims with it.
The Goxcoins scam is one entry among 604 complaints in the archived copy of the DFPI tracker we reviewed, 555 of them tagged "fraudulent trading platform." The script barely varies. The FBI's Internet Crime Complaint Center counted $7.2 billion in reported cryptocurrency-investment-fraud losses for 2025 — the costliest crime category it tracks. Behind every one of those dollars is a version of the same conversation that started in a chat group.
How to protect yourself
- Treat the group chat as the crime scene. Any WhatsApp or Telegram "adviser" who posts wins and routes you to one platform is showing you the first stage of the fraud, not an opportunity. Our guide to how to spot a crypto scam walks through the full script.
- Search the official trackers before any deposit. The DFPI Crypto Scam Tracker is free, public, and searchable by domain. Sixty seconds there beats any rating site.
- Check a domain's history, not its age. A nine-year-old domain that spent eight of those years parked for sale is not a nine-year-old company. The Wayback Machine shows you what a site used to be.
- Never pay to withdraw. Any platform that demands a fee, a tax, or a deposit before releasing your balance has told you what it is. Believe it the first time.
- If you already sent money, stop now and document everything. Screenshots, chat logs, transaction hashes, wallet addresses. File reports with the FBI at ic3.gov and the FTC at reportfraud.ftc.gov, then follow our first 48 hours protocol. Expect "recovery agents" to appear in your inbox afterward — they are the second fraud, not the solution to the first. And if this platform took your money, tell us. Your report may be the one that connects the next case.
Our verdict
Goxcoins.com displays every hallmark of a fraudulent crypto exchange, and our verdict is Scam. This assessment is based on publicly available data: a regulator's published complaint, registry and DNS records anyone can query, and a seizure banner anyone can load. The DFPI entry is a consumer complaint — an allegation the state judged credible enough to publish — and the criminal proceedings behind the domain seizure, if any have been announced, were not detailed in the sources we reviewed. We could not verify whether charges have been filed. We could verify that the platform promised daily returns, froze a withdrawal, demanded a 50% ransom on it, and now answers to federal nameservers.
If the operators of this platform believe we have gotten something wrong, our corrections policy explains how to reach us.
We'll wait.
Frequently asked questions
Is Goxcoins.com a legitimate crypto exchange?
No. The California DFPI flags it as a fraudulent trading platform, the domain now resolves to FBI seizure servers, and we could not verify any license, corporate entity, or registration behind it. Nothing in the public record supports treating it as a real exchange.
I already deposited money with Goxcoins — what now?
Stop sending money today, and do not pay any "fee" or "tax" to unlock a withdrawal — that demand is the second act of the same fraud. Preserve everything: screenshots, chat logs, transaction hashes, the wallet addresses you sent to. File a report with the FBI at ic3.gov and with the FTC at reportfraud.ftc.gov, then work through our first 48 hours guide step by step.
Why does Goxcoins.com show an FBI seizure notice?
Because the domain's nameservers now point to ns1.fbi.seized.gov and ns2.fbi.seized.gov — infrastructure the FBI uses when it takes control of a domain. A banner like this, served from those nameservers, means federal authorities hold the domain. The underlying case has not been detailed in the public sources we reviewed as of August 12, 2026.
Can I get my money back from Goxcoins?
Honestly: recovery is hard, because crypto transfers cannot be reversed. It is not hopeless. Seizures and prosecutions sometimes lead to victim remission programs, and the reports you file with IC3 and the FTC are how investigators find and count victims — so file them, and keep your evidence organized. Ignore anyone who contacts you promising to recover the funds for an upfront fee. That is a recovery scam, and it targets the same people twice.
The domain is nine years old with valid SSL — how can it be a scam?
Because age and encryption say nothing about who is behind a site. This domain spent years parked and was still redirecting to a for-sale listing in July 2025; the "exchange" came later. The certificate is a free 90-day Let's Encrypt cert that any domain owner can obtain in minutes. ScamAdviser's algorithm called the site "legit and reliable" on exactly those two signals. Wrong, as it turned out: the Goxcoins scam ran on a nine-year-old domain with a valid certificate the whole time.
Who are "Charles" and "Isabella"?
Those are the names used by the WhatsApp handlers in the DFPI complaint — the pair who posted trade calls and directed members onto the platform. They are almost certainly personas, possibly operated by one person or a whole team; we could not verify any real identities behind them. Treat any "adviser" who finds you through a messaging app the same way you would treat these two.
Frequently asked questions
Is Goxcoins.com a legitimate crypto exchange?
No. The California DFPI flags it as a fraudulent trading platform, the domain now resolves to FBI seizure servers, and we could not verify any license, corporate entity, or registration behind it. Nothing in the public record supports treating it as a real exchange.
I already deposited money with Goxcoins — what now?
Stop sending money today, and do not pay any "fee" or "tax" to unlock a withdrawal — that demand is the second act of the same fraud. Preserve everything: screenshots, chat logs, transaction hashes, the wallet addresses you sent to. File a report with the FBI at ic3.gov and with the FTC at reportfraud.ftc.gov, then work through our first-48-hours guide at /reviews/what-to-do-if-scammed-first-48-hours step by step.
Why does Goxcoins.com show an FBI seizure notice?
Because the domain's nameservers now point to ns1.fbi.seized.gov and ns2.fbi.seized.gov — infrastructure the FBI uses when it takes control of a domain. A banner like this, served from those nameservers, means federal authorities hold the domain. The underlying case has not been detailed in the public sources we reviewed as of August 12, 2026.
Can I get my money back from Goxcoins?
Honestly: recovery is hard, because crypto transfers cannot be reversed. It is not hopeless. Seizures and prosecutions sometimes lead to victim remission programs, and the reports you file with IC3 and the FTC are how investigators find and count victims — so file them, and keep your evidence organized. Ignore anyone who contacts you promising to recover the funds for an upfront fee. That is a recovery scam, and it targets the same people twice.
The domain is nine years old with valid SSL — how can it be a scam?
Because age and encryption say nothing about who is behind a site. This domain spent years parked and was still redirecting to a for-sale listing in July 2025; the "exchange" came later. The certificate is a free 90-day Let's Encrypt cert that any domain owner can obtain in minutes. ScamAdviser's algorithm called the site "legit and reliable" on exactly those two signals. Wrong, as it turned out: the Goxcoins scam ran on a nine-year-old domain with a valid certificate the whole time.
Who are "Charles" and "Isabella"?
Those are the names used by the WhatsApp handlers in the DFPI complaint — the pair who posted trade calls and directed members onto the platform. They are almost certainly personas, possibly operated by one person or a whole team; we could not verify any real identities behind them. Treat any "adviser" who finds you through a messaging app the same way you would treat these two.
About the investigator
Marcus Hale
Fraud investigator · 20 years · former bank compliance
Marcus Hale spent two decades inside bank compliance departments, chasing suspicious transaction reports through correspondent accounts until the trail went cold at some offshore shell. He left to investigate the same money from the outside.
All investigations by Marcus →