# eigenplayer.xyz — SUSPICIOUS > eigenplayer.xyz is a brand impersonation site impersonating EigenLayer. PhishDestroy identifies this domain as a potential crypto drainer with 0/95 VirusTotal. ## Summary PhishDestroy identifies eigenplayer.xyz as a malicious domain actively impersonating EigenLayer, a prominent liquid staking protocol in the Ethereum ecosystem. This domain has been flagged for brand impersonation, a common tactic used by threat actors to deceive users into connecting wallets or entering sensitive credentials under the guise of legitimacy. Initial analysis suggests this site may function as a crypto drainer, designed to siphon digital assets from unwitting victims who interact with fake interfaces or sign malicious transactions. Users should exercise extreme caution and avoid visiting this domain entirely, as even passive exposure could result in financial loss. This domain exhibits multiple red flags consistent with malicious infrastructure. Registered through NICENIC INTERNATIONAL GROUP CO., LIMITED on January 11, 2024, it currently resolves to IP address 172.67.192.191 and has already been blocked by two security services, ScamSniffer and Enkrypt. Notably, it has yet to be flagged by VirusTotal, with a clean detection score of 0 out of 95 scans at the time of analysis. The domain utilizes a Let's Encrypt SSL certificate, which does not guarantee legitimacy but is commonly abused by threat actors to lend an air of authenticity to their operations. The combination of recent registration, low detection rates, and active blocklisting highlights the evolving nature of this threat and the need for heightened vigilance among users. If you have already visited eigenplayer.xyz, immediately disconnect your wallet from any suspicious dApps, revoke any recently approved permissions, and transfer remaining funds to a clean wallet. Do not interact with any prompts or transactions on this domain. Report the domain to PhishDestroy for further analysis and consider running a malware scan on your system. Always verify URLs against official sources and use hardware wallets for high-value transactions to mitigate the risk of asset loss. Stay informed by monitoring updates from EigenLayer and reputable security researchers to avoid falling victim to similar impersonation campaigns. ## Threat Details - Verdict: SUSPICIOUS - Site status: unknown (HTTP ?) - Target brand: EigenLayer ## Domain Intelligence - Registered: 2024-01-11 20:13:12 - Registrar: NICENIC INTERNATIONAL GROUP CO., LIMITED - IP: 172.67.192.191 ## Detection Status - VirusTotal: 0 vendors flagged - Google Safe Browsing: clean - Blocklists: 2 hits Lists: ["ScamSniffer", "Enkrypt"] ## Evidence - Cloudflare Radar: https://radar.cloudflare.com/scan/c52ab1b6-2589-4e15-b7c4-3efee4a14eed - PhishDestroy: https://phishdestroy.io/domain/eigenplayer.xyz/ - LLM endpoint: https://phishdestroy.io/domain/eigenplayer.xyz/llm.txt ## If You Visited This Site 1. Change any passwords you may have entered 2. Enable 2FA on all related accounts 3. Monitor your accounts for unauthorized activity 4. Report to: FBI IC3, Europol, local authorities --- Report by PhishDestroy | https://phishdestroy.io/domain/eigenplayer.xyz/ Last updated: 2026-03-28