On July 31, 2026, the domain trezor-wallet-e.webflow.io is identified as an active high-risk crypto drainer threat. The domain currently resolves to IP address 172.64.151.8 and remains accessible as of the reporting date. Security intelligence indicates that it has been flagged by 9 out of 91 vendors on VirusTotal, demonstrating detection across multiple engines. Additionally, trezor-wallet-e.webflow.io has been included in at least one security blocklist and is explicitly blocked by PhishDestroy, which reflects an established consensus among some threat intelligence sources regarding its malicious use.
The domain is registered through Webflow, Inc. Nameservers are recorded as NS_NOT_FOUND, which may indicate non-standard or misconfigured DNS infrastructure, a pattern sometimes observed in domains established for illicit purposes. The site’s specific content and functionality have not been directly analyzed for this report; however, the domain is classified as a crypto drainer based on threat intelligence, meaning it is likely involved in operations designed to illicitly access and withdraw victims' cryptocurrency assets. The sustained activity and positive detections confirm the ongoing threat posed by this infrastructure.
Defenders should ensure this domain is proactively blocked within their environments and monitor for user access attempts. Incidents involving this domain should be treated as high-risk, with rapid investigation and remediation procedures. Continued tracking is recommended, as the domain remains actively engaged in malicious operations and is not yet neutralized according to current blocklist and detection data.