# card-phantom.com — MALICIOUS — Crypto Drainer (Solana Drainer) > Warning: card-phantom.com is a CRYPTO DRAINER impersonating Phantom. Protect your wallet! 6/95 vendors flag it on VirusTotal. Verify on PhishDestroy now. ## Summary PhishDestroy has identified card-phantom.com as a critical threat: a crypto drainer. This website is designed to steal cryptocurrency from unsuspecting users by tricking them into connecting their wallets and signing malicious transactions. It specifically targets users of the Phantom wallet, attempting to deceive them into believing it is a legitimate Phantom service. Our analysis revealed that card-phantom.com is an active threat, resolving to the IP address 37.140.192.11. As of this analysis, VirusTotal reports that 6 out of 95 security vendors have flagged this domain as malicious. The domain was registered through Registrar of Domain Names REG.RU LLC, a detail sometimes associated with fraudulent activities. The drainer kit used is a Solana Drainer, confirming its focus on Solana-based assets. If you have visited card-phantom.com and connected your wallet, immediately disconnect your wallet and move your assets to a new, secure wallet. Revoke any permissions granted to the site. Monitor your wallet for any unauthorized transactions. If you entered your seed phrase or private key, your wallet is compromised, and you must move your assets immediately. Report the site to the Phantom wallet support team and relevant cybersecurity authorities. Regularly verify domain safety using PhishDestroy before interacting with crypto platforms. ## Threat Details - Verdict: MALICIOUS — Crypto Drainer (Solana Drainer) - Site status: alive (HTTP ?) - Drainer type: Solana Drainer - Target brand: Phantom ## Domain Intelligence - Registrar: Registrar of Domain Names REG.RU LLC - IP: 37.140.192.11 ## Detection Status - VirusTotal: 6 vendors flagged - Google Safe Browsing: clean - Blocklists: 0 hits ## Evidence - PhishDestroy: https://phishdestroy.io/domain/card-phantom.com/ - LLM endpoint: https://phishdestroy.io/domain/card-phantom.com/llm.txt ## If You Visited This Site 1. Revoke all token approvals immediately (revoke.cash / unrekt.net) 2. Move remaining funds to a new wallet 3. Do not interact with any transactions from this site 4. Report to: FBI IC3, Europol, local authorities --- Report by PhishDestroy | https://phishdestroy.io/domain/card-phantom.com/ Last updated: 2026-03-26