distribution-ethena[.]fi
“Ethena”
Evidence Summary
The site distribution-ethena.fi displays the page title "distribution-ethena.fi | 522: Connection timed out" and is classified as a Crypto Scam. This domain impersonates the Ethena brand, likely attempting to deceive users into interacting with a fraudulent cryptocurrency distribution scheme. The primary threat is financial loss, as victims may provide credentials or send funds to the site under the false pretense of a legitimate token distribution.
Technical analysis shows that distribution-ethena.fi was created on 2026-02-21. It is hosted on IP address 2a06:98c1:3120::3, associated with AS13335 Cloudflare, Inc., and located in the United States. The domain uses nameservers junade.ns.cloudflare.com and maya.ns.cloudflare.com. Its SSL certificate is issued by Google Trust Services / WE1. VirusTotal reports 4 out of 95 security vendors flagging the site as malicious, with detections from CRDF, Ermes, Gridinsoft, and Kaspersky. It appears on 1 blocklist.
The site is currently DOWN/OFFLINE and has a domain risk score of 56, indicating a moderate to high threat level. Due to its offline status, immediate active risk is reduced, but the domain remains a potential vector for future attacks if reactivated.
Data Coverage
Network Security Intelligence
| Detection System | Indicator | Verdict | Alert |
|---|---|---|---|
| DNS0 Zero | distribution-ethena.fi |
malicious | Sinkholed |
Threat Response Pipeline
Blocklist coverage
10 monitored external feeds · stored snapshot Aug 12, 2026
10 monitored external feeds No match
Detection timeline
-
Cloudflare Radar
Cloudflare Radar scan stored · Open scan
Financial Infrastructure
Addresses extracted from the phishing page.
Wallet addresses
Telegram
Technologies
2 high-confidence technologies identified
VirusTotal Analysis
Were You Affected by This Site?
If a wallet, seed phrase, or account was exposed, report the incident immediately. Revoke approvals and move remaining assets to a new wallet created on a trusted device.
Report to Your Local Authorities
Select your country to get official cybercrime contacts, or create a complaint draft →.
Check Any Domain
Threat analysis using stored blocklist, WHOIS, DNS, and public scan evidence
Scan NowReport Phishing
Submit suspicious domains to our threat database — protect the community
ReportLive Threat Feed
Recent phishing reports and observed availability changes
MonitorStay Informed, Stay Safe
Monitor live threats or contest this listing if you believe it's a false positive
Recommendations & Advice for Victims
An estimated $51 billion flowed to illicit crypto wallets in 2024 (source). If you interacted with distribution-ethena.fi — act now.
What should I do immediately?
Urgent
- Revoke token approvals — use revoke.cash to remove access granted to malicious smart contracts
- Move remaining funds to a brand-new wallet. The compromised wallet is no longer safe
- Change all passwords — email, exchange accounts, anything that shares the same password
- Enable 2FA using an authenticator app (not SMS). Disable SMS-based recovery
- Freeze cards if you entered banking details on the phishing site
What information should I collect for my report?
FBI guidelines
According to the FBI, the most important details are transaction data:
- Cryptocurrency addresses — scammer's wallet (e.g.,
0x5856...35985) - Amount & crypto type — exact amount (e.g., 1.02345 ETH, 0.5 BTC, 500 USDT)
- Transaction ID (hash) — the unique blockchain transaction identifier
- Exact dates & times — of each transaction and first contact with scammer
- Screenshots — scam website, chat messages, emails, wallet transactions, social media
- All URLs & domains used by the scammer (including
distribution-ethena.fi) - Communications — emails, texts, phone numbers, usernames the scammer used
Even if you don't have all details — file a report anyway. Partial information still helps investigations.
Where should I report the scam?
- FBI IC3 — Internet Crime Complaint Center (US federal reporting)
- Europol — European cybercrime reporting (EU)
- Chainabuse — flag scam wallets across exchanges & platforms
- Your crypto exchange — notify its fraud team immediately; it may be able to preserve records or restrict funds held on its platform
- Local police — creates an official record, even if they can't act immediately
A report is not a guarantee of recovery or investigation, but prompt, accurate transaction data can help authorities and service providers trace the incident.
How do crypto scams typically work?
- Fake websites — pixel-perfect clones of legitimate sites with slightly altered domains
- Malicious approvals — "connect wallet" prompts that grant unlimited token spending to attackers
- Pig butchering — trust built over weeks via Telegram/WhatsApp/dating apps, then money stolen
- Recovery scams — fraudsters pose as recovery agents and demand upfront fees. Never share a seed phrase or pay before independently verifying the provider
- Fake ads & airdrops — Google/social media ads and "free token" offers leading to wallet drainers
- AI-powered scams — deepfakes, automated phishing, and AI-generated sites making fraud harder to detect
How can I protect myself in the future?
- Use a hardware wallet (Ledger, Trezor). Never store large amounts in browser wallets
- Bookmark official sites — never click links from emails, DMs, or ads
- Read every approval — verify permissions before signing. Reject unlimited approvals
- Verify domains — check on PhishDestroy before interacting. Check HTTPS, spelling, domain age
- "Too good to be true" = scam — guaranteed returns, celebrity endorsements, urgent deadlines