atomic-wallet[.]to
“Home Page”
ملخص الأدلة
PhishDestroy identifies atomic-wallet.to as a brand impersonation threat specifically targeting users of Atomic Wallet, a legitimate cryptocurrency wallet. This domain is designed to trick visitors into believing they are on the official Atomic Wallet website, with the ultimate goal of stealing sensitive information such as login credentials, private keys, or seed phrases. The threat type is a crypto drainer, meaning that once a user enters their wallet details, the attackers can remotely access and drain funds from the victim's cryptocurrency wallet. The domain's title, "Home Page," is deliberately generic to avoid raising suspicion, but its sole purpose is to facilitate credential theft and asset theft.
Technical evidence strongly supports the malicious nature of this domain. VirusTotal reports that 14 out of 95 security vendors flag atomic-wallet.to as malicious, a significant detection rate that underscores the widespread recognition of its threat. The domain was registered on May 6, 2025, through the Government of Kingdom of Tonga, a registrar often associated with low scrutiny and abuse. It appears on at least one security blocklist and has been identified in three threat intelligence pulses on AlienVault OTX. The site lacks an SSL certificate, meaning any data transmitted is unencrypted and easily intercepted. The domain resolves to IP address 2606:4700:3031::6815:4918, which is associated with Cloudflare, a service that can obscure the true hosting location. As of the latest check, the domain has been taken offline, but similar sites may reappear under different domains.
If a user has visited atomic-wallet.to or entered any information, they should immediately consider their wallet compromised. The first step is to transfer all funds from the affected wallet to a new, secure wallet that has never been used on any suspicious site. Users should also change passwords for any associated accounts and enable two-factor authentication wherever possible. Running a full antivirus scan on the device is recommended, as the site may have attempted to deliver malware. Finally, users should report the domain to relevant authorities and monitor their accounts for any unauthorized activity. PhishDestroy advises always verifying URLs before entering sensitive information and using official channels to access cryptocurrency services.
Data Coverage
مسار الاستجابة للتهديدات Pipeline
تغطية قوائم الحظر
١٠ مصادر خارجية مراقبة · لقطة محفوظة 11/08/2026
المخطط الزمني للاكتشاف
-
Cloudflare Radar
تم حفظ فحص Cloudflare Radar · فتح الفحص
تحليل VirusTotal
هل تأثرت بهذا الموقع؟
إذا أدخلت بيانات اعتماد الحساب أو المعلومات الشخصية أو معلومات الدفع أو قمت بتنزيل ملف من هذا النطاق، فاتخذ إجراءً فوريًا. فيما يلي موارد لمساعدتك في الإبلاغ عن الحادث وحماية نفسك.
أبلغ السلطات المحلية
حدد بلدك للحصول على الاتصالات الرسمية المتعلقة بالجرائم الإلكترونية أو إنشاء مسودة شكوى →.
تحقق من أي نطاق
تحليل التهديدات باستخدام قائمة الحظر المخزنة، وWHOIS، وDNS، وأدلة الفحص العامة
امسح الآنالإبلاغ عن محاولة تصيد احتيالي
أرسل النطاقات المشبوهة إلى قاعدة بيانات التهديدات الخاصة بنا — ساهم في حماية المجتمع
إبلاغتحديثات فورية حول التهديدات
تقارير التصيد الاحتيالي الأخيرة وتغييرات التوفر الملحوظة
مراقبةابقَ على اطلاع، وابقَ آمنًا
راقب التهديدات في الوقت الفعلي أو اعترض على هذا الإدراج إذا كنت تعتقد أنه إنذار كاذب