# claimsoltokens.pages.dev — SUSPICIOUS > Domain claimsoltokens.pages.dev is a confirmed OKX brand impersonation crypto drainer with 2/95 VirusTotal detections. ## Summary PhishDestroy identifies an active brand impersonation campaign using the domain claimsoltokens.pages.dev to deceive users by mimicking the legitimate OKX cryptocurrency exchange. This domain is part of a crypto drainer operation, designed to trick visitors into connecting their crypto wallets and approve malicious transactions that drain funds. The fraudulent site leverages Cloudflare Pages to host its content, making it appear legitimate at a glance, but its sole purpose is to steal digital assets under the guise of an OKX-related service. This domain was flagged by PhishDestroy after analysis confirmed it resolves to IP 188.114.96.3 and is registered through Cloudflare, Inc. Security vendor detection remains low at 2 out of 95 on VirusTotal, indicating this campaign is likely in early stages of deployment or leveraging evasion techniques to avoid immediate detection. While the exact creation date is not publicly available, the domain’s infrastructure and targeting suggest a recent, coordinated effort to exploit user trust in the OKX brand. If you visited claimsoltokens.pages.dev or interacted with it, immediately disconnect your wallet from any dApps or websites and revoke any unauthorized permissions using tools like revoke.cash or your wallet’s built-in security features. Do not enter any credentials, connect your wallet, or approve transactions on this site. Report the domain to OKX’s official fraud reporting channels and consider scanning your device for malware. Always verify URLs and use bookmarked links for official platforms to avoid similar scams. ## Threat Details - Verdict: SUSPICIOUS - Site status: unknown (HTTP ?) - Target brand: OKX ## Domain Intelligence - Registrar: Cloudflare, Inc. - IP: 188.114.96.3 ## Detection Status - VirusTotal: 2 vendors flagged - Google Safe Browsing: clean - Blocklists: 0 hits ## Evidence - PhishDestroy: https://phishdestroy.io/domain/claimsoltokens.pages.dev/ - LLM endpoint: https://phishdestroy.io/domain/claimsoltokens.pages.dev/llm.txt ## If You Visited This Site 1. Change any passwords you may have entered 2. Enable 2FA on all related accounts 3. Monitor your accounts for unauthorized activity 4. Report to: FBI IC3, Europol, local authorities --- Report by PhishDestroy | https://phishdestroy.io/domain/claimsoltokens.pages.dev/ Last updated: 2026-03-26