Analysis as of July 30 2026 identifies trustwallet-co.com as an active crypto drainer infrastructure. The domain was registered on July 28 2026 through Squarespace Domains II LLC and is served by the nameservers nsc1.squarespacedns.com, nsc2.squarespacedns.com, nsc3.squarespacedns.com, nsc4.squ. DNS resolution points to the IPv4 address 198.49.23.144, which is the sole listed host for this indicator.
The domain is currently listed on three public security blocklists and has been explicitly blocked by the PhishDestroy, MetaMask, and SEAL detection suites. VirusTotal scans report that four of ninety‑one AV engines flagged the domain as malicious, reinforcing its classification as high‑risk. No additional metadata such as SSL certificate details, HTTP response codes, or page title information is available in the source data, so the precise content served by the site remains unconfirmed.
The observed attributes—recent registration, single‑IP hosting, association with reputable anti‑phishing products, and multi‑vendor detection—support the conclusion that trustwallet-co.com is being used to lure cryptocurrency owners into disclosing private keys or authorizing unauthorized transfers. Defenders should immediately add the domain to local and network‑level blocklists, monitor DNS queries for the associated IP, and issue user advisories warning that any Trust Wallet‑related prompts originating from this hostname are fraudulent. Continuous re‑evaluation is advised, as further host‑level activity or payload delivery details may emerge as the campaign evolves.