# airdrop.t3rn.lol — SUSPICIOUS > Warning: airdrop.t3rn.lol is an active crypto drainer domain. Avoid interacting to protect your crypto assets from unauthorized access. ## Summary PhishDestroy identifies airdrop.t3rn.lol as a crypto drainer domain used to illicitly extract cryptocurrency from victims. The page titled "BRN to TRN Claim" suggests a fraudulent token swap or claim mechanism. The domain, created on February 21, 2026, resolves to IP 172.67.137.122 and is listed on two security blocklists. VirusTotal currently flags it by 2 out of 95 security vendors, indicating low but notable risk. This threat remains active. Users and systems should block or avoid this domain to prevent crypto wallet compromise. Continued monitoring and blocking are recommended. ## Threat Details - Verdict: SUSPICIOUS - Site status: alive (HTTP 530) - Scam type: Airdrop Scam - Page title: BRN to TRN Claim ## Domain Intelligence - Registered: 2026-02-21 07:01:08 - IP: 172.67.137.122 - SSL Issuer: WE1 ## Detection Status - VirusTotal: 2 vendors flagged Vendors: ["Fortinet", "Gridinsoft"] - Google Safe Browsing: clean - Blocklists: 2 hits Lists: ["PhishDestroy", "ScamSniffer"] ## Evidence - Screenshot: https://urlscan.io/screenshots/019986cb-c8f2-729c-b4db-5cb631f4b5df.png - PhishDestroy: https://phishdestroy.io/domain/airdrop.t3rn.lol/ - LLM endpoint: https://phishdestroy.io/domain/airdrop.t3rn.lol/llm.txt ## If You Visited This Site 1. Change any passwords you may have entered 2. Enable 2FA on all related accounts 3. Monitor your accounts for unauthorized activity 4. Report to: FBI IC3, Europol, local authorities --- Report by PhishDestroy | https://phishdestroy.io/domain/airdrop.t3rn.lol/ Last updated: 2026-03-19