MALICIOUS — CRITICAL
cakewallet-com[.]us
13 of 91 security engines flagged the domain; 2 public blocklists listed it (MetaMask, SEAL); the latest stored check returned HTTP 502.
- VirusTotal
- 13/91
- Blocklists
- 2 · MetaMask, SEAL
- التوفر
- مغطى بعباءة · يمكن الوصول إليه · HTTP 502
Do not enter credentials, seed phrases, payment details, or personal information on this domain.
Jump to section
cakewallet-com.us — مغطى بعباءة · يمكن الوصول إليه (HTTP 502). نوع الاحتيال: Credential Phishing. ملخص الأدلة: VirusTotal 13/91 (ADMINUSLabs, alphaMountain.ai, BitDefender, Chong Lua Dao, CRDF); URLQuery 1 alert; 2 external blocklist matches (MetaMask, SEAL); cloaking observed; PhishDestroy score 100/100. مسجّل النطاق: PDR.
يبقى تحليل PhishDestroy AI المفصل أدناه باللغة الإنجليزية للحفاظ على السجل الجنائي الرقمي الأصلي.
Evidence Digest
cakewallet-com.us is classified critical with an evidence score of 100/100. 13 of 91 security engines flagged the domain; 2 public blocklists listed it (MetaMask, SEAL). Registered 30 Apr 2026 via PDR Ltd. d/b/a PublicDomainRegistry.com, hosted on 76.76.21.21 (Amazon.com, Inc., US). The latest stored check on 9 Aug 2026 returned HTTP 502 and includes a capture. 1 outgoing abuse report is recorded, most recently on 4 May 2026.
Stored generated summary (templated)mistral · 04/05/2026
Retained for the record. This text repeats stored detection facts and is not presented as authored analysis.
PhishDestroy identifies cakewallet-com.us as an active crypto drainer posing as the legitimate Cake Wallet service. This domain leverages the trust of the Monero-focused wallet community to harvest private keys and seed phrases, enabling direct theft of user funds. The threat is immediate and material: visitors risk irreversible financial loss if they authenticate or restore wallets via this counterfeit site. The domain’s behavior aligns with automated drainer scripts that monitor clipboard activity and replace wallet addresses with attacker-controlled destinations.
This domain was flagged by PhishDestroy’s seed d9f3e1 and is currently under investigation. Intelligence confirms the following technical indicators: VirusTotal detection rate is 2/95 (0%), indicating no AV signatures yet; the domain resolves to IP 76.76.21.21; it was registered on April 30, 2026 through PDR Ltd. d/b/a PublicDomainRegistry.com; and it uses a Let’s Encrypt SSL certificate. The page title mimics legitimate Cake Wallet documentation: “Cake Wallet Guide Desk: Independent Login, Restore, and Monero Setup Guides,” suggesting a spoofed support portal designed to deceive users seeking help.
Mitigation begins with immediate blocking: add cakewallet-com.us and 76.76.21.21 to network and DNS blocklists. Users should only access Cake Wallet via official domains (cake-wallet.com) and verify TLS certificate chains. Never enter seed phrases or private keys into any web form. Enable hardware wallet signing and use Monero-specific address verification tools. Report this domain to your security team and to Cake Wallet support for takedown coordination. Monitor wallet addresses used in transactions linked to this domain for suspicious inflows.
نطاق تغطية البيانات12 recorded checks
استخبارات أمن الشبكات
| Detection System | Indicator | Verdict | Alert |
|---|---|---|---|
| DNS4EU | cakewallet-com.us |
malicious | Sinkholed |
مسار الاستجابة للتهديدات Pipeline
حالة قوائم الحظر العامة
التقنيات · 2 identified
HTTP Strict Transport Security (HSTS) informs browsers that the site should only be accessed using HTTPS.
www.rfc-editor.org ثقة 100٪تحليل VirusTotal
تحليل أداء الموقع
Google PageSpeed Insights — mobile performance audit of cakewallet-com.us · checked May 4, 2026
الأدلة والتقارير الخارجيةIndependent lookups and source reports
PD-20260504-D87946 Recipient: abuse@vercel.com Victim safety and official reportingImmediate actions and verified reporting channels
إذا أدخلت بيانات اعتماد الحساب أو المعلومات الشخصية أو معلومات الدفع أو قمت بتنزيل ملف من هذا النطاق، فاتخذ إجراءً فوريًا. فيما يلي موارد لمساعدتك في الإبلاغ عن الحادث وحماية نفسك.
أبلغ السلطات المحلية
حدد بلدك للحصول على الاتصالات الرسمية المتعلقة بالجرائم الإلكترونية أو إنشاء مسودة شكوى →.