# airdrop-pretzel.build — MALICIOUS > The domain airdrop-pretzel.build was linked to crypto draining scams. Avoid interaction and ensure your crypto assets are secure. ## Summary PhishDestroy identifies airdrop-pretzel.build as a medium-risk crypto drainer domain targeting cryptocurrency users. It was designed to trick victims into revealing private keys or wallet credentials. The domain was registered on February 21, 2026, and is currently flagged on multiple security blocklists. VirusTotal analysis shows detection by several security vendors. It was registered through a dead domain registrar, indicating potential malicious intent. Currently taken offline, the domain poses no active threat. Users are advised to remain vigilant, avoid suspicious airdrop offers, and secure their wallets with trusted tools. ## Threat Details - Verdict: MALICIOUS - Site status: alive (HTTP 530) - Scam type: Airdrop Scam - Target brand: Berachain - Page title: $PRET — Built on Berachain ## Domain Intelligence - Registered: 2026-02-21 07:01:08 - IP: 172.67.168.54 - SSL Issuer: WE1 ## Detection Status - VirusTotal: 6 vendors flagged Vendors: ["alphaMountain.ai", "CyRadar", "Ermes", "Fortinet", "Gridinsoft", "SOCRadar"] - Google Safe Browsing: clean - Blocklists: 5 hits Lists: ["PhishDestroy", "ScamSniffer", "Polkadot", "Enkrypt", "Codeesura"] ## Evidence - Screenshot: https://urlscan.io/screenshots/019bb7d2-2035-74f9-b986-aeaeb19df100.png - PhishDestroy: https://phishdestroy.io/domain/airdrop-pretzel.build/ - LLM endpoint: https://phishdestroy.io/domain/airdrop-pretzel.build/llm.txt ## If You Visited This Site 1. Change any passwords you may have entered 2. Enable 2FA on all related accounts 3. Monitor your accounts for unauthorized activity 4. Report to: FBI IC3, Europol, local authorities --- Report by PhishDestroy | https://phishdestroy.io/domain/airdrop-pretzel.build/ Last updated: 2026-03-19