Domain Security Reports

Search our database of flagged domains. Check if a website is a scam, phishing, or legitimate.

0
Total Tracked
0
Detected
0
Content Alive
0
Content Dead
0
VT Pending
Solana Drainer
CRITICAL THREAT

Understanding and Combating Solana Drainer Threats

Solana Drainer threats pose a critical risk with 1,323 domains tracked and 184 currently active. PhishDestroy insights reveal top TLDs and registrars involved.

2,090
Domains Detected
CRITICAL
Threat Level

How This Attack Works

Solana Drainer threats exploit vulnerabilities in Solana's crypto ecosystem to steal funds. Understanding their operation is crucial for prevention.

STEP 1
Target Identification
Attackers identify potential victims through phishing emails and fake websites.
STEP 2
Phishing Execution
Victims are lured to malicious sites mimicking legitimate platforms, like phantomairdrop.com.
STEP 3
Credential Harvesting
Once on the fake site, victims input sensitive information, believing it to be secure.
STEP 4
Fund Drainage
Attackers utilize harvested credentials to access wallets and drain funds via illicit transactions.

Technical Analysis

Solana Drainer attacks leverage phishing techniques to exploit the Solana blockchain. Attackers often create copycat websites using top TLDs such as .com, .xyz, and .cc, with domains hosted by registrars like Cloudflare, Inc. and PDR Ltd. These sites employ deceptive JavaScript and HTML code to mimic legitimate interfaces, tricking users into entering their private keys or seed phrases. Once credentials are obtained, attackers interact with the Solana blockchain via RPC calls to execute unauthorized transactions. The usage of smart contract functions like `transfer` and `approve` allows attackers to swiftly move funds out of victims' accounts. The infrastructure often involves a network of proxy servers to obfuscate the origin of the attack and make tracing back to the perpetrators difficult.

Real Cases

Phantom Wallet Breach (2023)
$2 million stolen
Attackers created a fraudulent Phantom wallet site to harvest user credentials, resulting in a $2 million theft.
SolUnion Scam (2024)
$1.5 million stolen
Using the domain phantom.solunion.cc, scammers executed a sophisticated phishing attack, stealing $1.5 million in SOL.
VaultBenefits Exploit (2024)
$3 million stolen
A fake airdrop campaign via vaultbenefits.net led to credential compromise and a subsequent $3 million drain.

How to Detect

Unsolicited emails or messages offering free SOL or airdrops
Websites with slight misspellings of legitimate names
Requests for private keys or seed phrases
Suspicious URL structures or unfamiliar TLDs like .xyz or .cc
Lack of HTTPS security on sites claiming to be secure

How to Protect Yourself

1 Verify URLs carefully before interacting
2 Enable multi-factor authentication on your wallet
3 Never share your private key or seed phrase
4 Regularly check transaction histories for unauthorized activity
5 Use official wallet apps and browser extensions

Frequently Asked Questions

What is Solana Drainer?
Solana Drainer refers to phishing attacks targeting Solana wallet users to steal funds by tricking them into revealing sensitive credentials.
How much money has been stolen through Solana Drainer?
Millions have been lost, with notable cases like the Phantom Wallet Breach resulting in a $2 million loss.
How do I protect myself from Solana Drainer?
Stay vigilant by verifying URLs, using multi-factor authentication, and never sharing your private keys.
What should I do if I'm a victim of Solana Drainer?
Report the incident to authorities and your wallet provider immediately, and attempt to trace unauthorized transactions.
Data sourced from PhishDestroy threat intelligence database — 2,090 domains tracked for this threat type
Solana Drainer — Threat Intelligence Smart Contract High Threat
solana.com (official)
2,090
Domains
732
Alive
1,301
Taken Down
5.2
Avg VT
35%
Alive Rate
95.3%
Detected
Since Mar 2024 842 domains with VT ≥ 5
Solana Drainer 2,090 domains
jitocore.com
10 VTLiveacross
jitoplus.com
10 VTLiveacross
jup-portfolio.com
10 VTLivediscord
jup-promotion.net
10 VTTaken Downjupiter
jup-verse.io
10 VTTaken Downjupiter
jup-wallet.web.app
10 VTTaken DownSolana
jupdappchain.click
10 VTLiveJupiter
jupiter-solana.network
10 VTLiveJupiter
kamino-layer.com
10 VTLivehashflow
meme-event.fun
10 VTTaken Downrevolut
metaaichain.xyz
10 VTLiveSolana
phanstart.live
10 VTLivephantom
phantom-rewards.xyz
10 VTLivePhantom
phantom-voted.com
10 VTTaken DownPhantom Wallet
phantom.ad
10 VTTaken DownPhantom
phantomvote.org
10 VTTaken DownPhantom Wallet
phantomwallets.blogspot.kr
10 VTTaken DownPhantom
phantomwalletx.blogspot.sn
10 VTTaken DownPhantom
portal-rayduim.live
10 VTLiveceler
protocol-ray.xyz
10 VTTaken Downceler
punchtoken.net
10 VTTaken DownOKX
raydiumclaims.live
10 VTLiveRaydium
sniper.solhq.cc
10 VTTaken DownSolana
sol-award.buzz
10 VTLivebitget
sol-space.pro
10 VTTaken DownSolana
sol-wheel.cc
10 VTLivesolana
solana-nft-creator.com
10 VTTaken DownSolana
solana.com-miner.club
10 VTSolana
solanamax-airdrop.pages.dev
10 VTLiveAirdrop Scam
solanaquiz.fun
10 VTLiveSolana
solminatorai.xyz
10 VTTaken Down
solsolana.solhost.cc
10 VTTaken DownSolana
sospin.icu
10 VTLivesolana
spin.defibase.live
10 VTLivesolana
stream-pump.fun
10 VTTaken DownPump.fun
sulf.live
10 VTTaken Down
swiftsolchain.live
10 VTTaken Downjupiter
trades-hyperliquid.xyz
10 VTLivefoundation
trumpair.today
10 VTLiveacross
trumpwallet.trade
10 VTLivesolana
umbra.events
10 VTTaken Down
unlock.wrldlibertyficoin.world
10 VTTaken Downrevolut
uscr.distribution.finance
10 VTLiverevolut
usdcwheel.com
10 VTLivesolana
user57085.live
10 VTLiveacross
usor.click
10 VTTaken DownLedger
usor.lat
10 VTTaken DownLedger
verifiedkeyring-beta.icu
10 VTTaken DownSolana
votetrending.com
10 VTTaken DownSolana
weeddrop.fun
10 VTLiveSolana
weedrop.fun
10 VTTaken Downrevolut
wet.solhost.cc
10 VTTaken DownSolana
whalegurusol.fun
10 VTLiverevolut
wlfi.xsol.pro
10 VTLiverevolut
wlficoin.life
10 VTLiverevolut
zrealdrop.top
10 VTLiveacross
57429.my
9 VTTaken DownSolana
air.solcore.cc
9 VTTaken Downsolana
airclaim.presidentxi.live
9 VTLivesolana
auth-phantom-en.created.app
9 VTTaken DownPhantom
backpacks.live
9 VTTaken Down
bit.solcore.cc
9 VTTaken DownSolana
calabi.network
9 VTTaken DownSolana
chainsol.live
9 VTLiveJupiter
claim.moonad.top
9 VTLivemonad
claim.switchboards.world
9 VTLiveacross
djcoin.onsol.pro
9 VTTaken Downrevolut
early-pudgypenguins.com
9 VTLivesolana
event-safemoon.fun
9 VTTaken Downtwitter
event-smithers.fun
9 VTLiveSolana
fomo.solcore.cc
9 VTTaken Downdiscord
gethachiko.top
9 VTTaken Downacross
ghostwareos.org
9 VTTaken Downsolana
jailer.solplanet.cc
9 VTTaken DownSolana
jitob.com
9 VTTaken DownSolana
jup-ai-web.live
9 VTTaken DownJupiter
jupuaryevent.live
9 VTLivejupiter
lobstarwilde-solana.com
9 VTTaken DownSolana
maindapp.top
9 VTLiveJupiter
mainsolchains.com
9 VTLiveJupiter
meteora.cloud
9 VTTaken DownSolana
meteora.xvault.live
9 VTLiverevolut
moonshot.sol-galaxy.cc
9 VTTaken DownMoonshot
mountain.xsolana.cc
9 VTTaken DownSolana
nietzscheanpenguin.top
9 VTLiveceler
pamcad.com
9 VTTaken DownSolana
penguxdrop.fun
9 VTLivesolana
phantom-wallets.com.westnationalplc.ru
9 VTTaken DownPhantom
phantomwalletx.blogspot.sg
9 VTTaken DownPhantom
pudgypenguins.top
9 VTTaken DownSolana
qsmqw.town
9 VTTaken DownSolana
raydium.io-i.pro
9 VTTaken DownRaydium
register-elonair.fun
9 VTLiverevolut
smartdappresolvers.live
9 VTTaken DownSolana
smartresolverapp.pages.dev
9 VTTaken DownSolana
sol-good.pro
9 VTsolana
sol-hyperliquid.app
9 VTTaken DownSolana
sol-incinerator.icu
9 VTLivesolana
sol.solshelter.cc
9 VTTaken DownJupiter
solana-incinerator.app
9 VTTaken DownSolana
« Prev 1 2 3 4 5 6 7 Next » Page 4 of 21