claim[.]lombardyield[.]finance
“Nur einen Moment…”
The domain claim.lombardyield.finance was identified as a crypto drainer phishing site, designed to steal cryptocurrency by tricking users into connecting their wallets. This type of scam does not impersonate a specific brand but instead relies on deceptive promises of rewards or airdrops to lure victims. As of the latest verification, claim.lombardyield.finance has been taken offline, though it previously posed a direct threat to users' digital assets by draining funds once wallet access was granted.
Technical analysis of claim.lombardyield.finance revealed limited detection at the time of investigation. The domain was flagged by 1 of 1 security blocklists (PhishDestroy) but showed 0 of 95 detections on VirusTotal, indicating low initial awareness among security vendors. It was registered through Cloudflare, Inc., and resolved to the IP address 104.21.81.3, hosted by Cloudflare in the US (AS13335). No SSL certificate was observed, and the page title displayed 'Nur einen Moment…' during access attempts. The creation date of the domain remains unavailable.
Users who interacted with claim.lombardyield.finance should immediately revoke any token approvals granted to the site via wallet management tools like Etherscan or revoke.cash. It is also recommended to transfer remaining funds to a new, secure wallet to prevent further unauthorized access. Reporting the domain to platforms such as PhishTank, Google Safe Browsing, or local cybercrime units can help prevent additional victims. Victims should monitor their wallets for suspicious transactions and enable transaction alerts where possible.
Threat Response Pipeline
Public Blocklist Status
Stored Capture
Domain Intelligence
Technical detailsDNS, SSL SANs, timestamps
ICANN OVERSIGHT
Registration: lombardyield.finance
Accreditation and RAA context
Accreditation and RAA context
Registrar accreditation and DNS abuse obligations
For the registrable domain lombardyield.finance behind this subdomain, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Forensic Intelligence
VirusTotal Analysis
Evidence & External Reports
Were You Affected by This Site?
If credentials, payment data, or files were exposed, report the incident immediately. Change affected passwords, revoke active sessions, and scan the device.
Report to Your Local Authorities
Select your country to get official cybercrime contacts, or create a complaint draft →.
Check Any Domain
Threat analysis using stored blocklist, WHOIS, DNS, and public scan evidence
Scan NowReport Phishing
Submit suspicious domains to our threat database — protect the community
ReportLive Threat Feed
Recent phishing reports and observed availability changes
MonitorStay Informed, Stay Safe
Monitor live threats or contest this listing if you believe it's a false positive