Domain Security Reports
Search our database of flagged domains. Check if a website is a scam, phishing, or legitimate.
How This Attack Works
Solana Ecosystem scams are on the rise, targeting unsuspecting users with sophisticated phishing tactics. Here's how these scams typically unfold.
STEP 1
Domain Registration
Attackers register domains with misleading names such as solana-drop.app to mimic legitimate Solana services.
STEP 2
Phishing Campaign
Scammers launch phishing campaigns using emails or social media to lure victims to the fake websites.
STEP 3
Data Harvesting
Once on the fake site, victims are prompted to enter sensitive information, such as private keys or seed phrases.
STEP 4
Asset Theft
The collected data is used to access victims' wallets, leading to unauthorized transactions and asset theft.
Technical Analysis
Solana Ecosystem scams often utilize a variety of technical methods to deceive users. Attackers typically use typosquatting to register domains that closely resemble legitimate Solana services. Common tactics include deploying phishing kits that clone the appearance of genuine websites to trick users into inputting sensitive information. Many of these sites are hosted on platforms like Cloudflare for additional anonymity and protection against takedowns. Attackers may also employ smart contract functions to execute automated asset transfers once they gain access to a victim's wallet. This infrastructure enables rapid and often irreversible transactions, making recovery difficult.
Real Cases
Solana Wallet Phishing Scheme (2024)
$4.5 million stolen
A phishing campaign targeting Solana users resulted in the theft of $4.5 million worth of SOL and other tokens.
Fake Solana Staking Site (2023)
$2 million stolen
Scammers created a fake staking site that led to $2 million in stolen funds from users attempting to earn staking rewards.
Deceptive Token Airdrop (2024)
$1.2 million stolen
An airdrop scam promising free tokens tricked users into revealing private keys, resulting in $1.2 million in losses.
How to Detect
Unusual domain names mimicking Solana-related services
Unexpected emails or messages prompting action
Websites requesting private keys or seed phrases
Lack of HTTPS on websites claiming to be secure
Promises of unrealistic returns or free token offers
How to Protect Yourself
1
Verify the authenticity of websites before entering sensitive information
2
Enable two-factor authentication on your wallets
3
Regularly update your security software
4
Be cautious of unsolicited messages or offers
5
Use a hardware wallet for added security
Frequently Asked Questions
Data sourced from PhishDestroy threat intelligence database — 2,421 domains tracked for this threat type