# btcbullera.pages.dev — SUSPICIOUS > URGENT: btcbullera.pages.dev hosts a crypto drainer posing as 'BTC Bullera.' Only 1/95 scanners detected it. Verify immediately on PhishDestroy. ## Summary PhishDestroy identifies btcbullera.pages.dev as a live crypto drainer domain actively impersonating the legitimate 'BTC Bullera' platform, designed to steal cryptocurrency from unsuspecting users. This malicious domain leverages deceptive branding to lure victims into connecting their wallets or entering seed phrases, enabling immediate fund exfiltration. The campaign is hosted on a Cloudflare Pages domain (188.114.97.3) with a Google Trust Services SSL certificate, creating a veneer of legitimacy while operating in full stealth mode against most detection engines. This domain was flagged by PhishDestroy following its discovery in a recent sweep of phishing infrastructure targeting crypto enthusiasts. Intelligence shows VirusTotal coverage remains critically low at just 1 out of 95 security vendors detecting the threat, while the domain continues to resolve actively. Registered through Cloudflare, Inc., this page utilizes Google’s trusted infrastructure to evade basic network filtering. The low detection rate combined with the domain’s recent instantiation makes it particularly dangerous to users relying on traditional security measures. Users who visited btcbullera.pages.dev should immediately assume their credentials or wallet connections may have been compromised. Disconnect any active wallet connections, revoke any approvals granted to unknown contracts, and transfer remaining assets to a clean wallet. Report the incident to your wallet provider and consider freezing affected tokens if supported. For a comprehensive threat assessment, verify the domain’s status on PhishDestroy’s live threat intelligence feed before interacting with any crypto-related platforms. ## Threat Details - Verdict: SUSPICIOUS - Site status: alive (HTTP ?) ## Domain Intelligence - Registrar: Cloudflare, Inc. - IP: 188.114.97.3 ## Detection Status - VirusTotal: 1 vendors flagged - Google Safe Browsing: clean - Blocklists: 0 hits ## Evidence - Cloudflare Radar: https://radar.cloudflare.com/scan/d4f01c80-37b2-476b-8911-394a347ec2db - PhishDestroy: https://phishdestroy.io/domain/btcbullera.pages.dev/ - LLM endpoint: https://phishdestroy.io/domain/btcbullera.pages.dev/llm.txt ## If You Visited This Site 1. Change any passwords you may have entered 2. Enable 2FA on all related accounts 3. Monitor your accounts for unauthorized activity 4. Report to: FBI IC3, Europol, local authorities --- Report by PhishDestroy | https://phishdestroy.io/domain/btcbullera.pages.dev/ Last updated: 2026-03-25