# en-smartchainresolver.pages.dev — MALICIOUS > en-smartchainresolver.pages.dev is a live crypto wallet phishing site hosted on Cloudflare, with 11/95 VirusTotal detections. ## Summary PhishDestroy identifies a live cryptocurrency wallet phishing campaign targeting users tricked into connecting their wallets via a fraudulent domain masquerading as a legitimate blockchain interface. The domain en-smartchainresolver.pages.dev is actively resolving to IP address 188.114.96.3 through Cloudflare's Pages service, leveraging Cloudflare's infrastructure to evade traditional network-based blocking. At the time of analysis, this domain exhibited elevated risk behavior with 11 out of 95 independent security vendors on VirusTotal flagging it as malicious or suspicious. The use of Cloudflare's legitimate certificate authority (Google Trust Services) further enhances the appearance of legitimacy, increasing the likelihood of successful deception. This threat vector specifically targets cryptocurrency users by presenting a spoofed blockchain resolver interface designed to harvest wallet seed phrases, private keys, or grant malicious wallet permissions. The domain was registered through Cloudflare’s platform, which obscures the true registrant identity and allows for rapid deployment and iteration of phishing pages. While the exact domain creation date is not provided in current data feeds, the campaign's active status and deployment through Cloudflare Pages indicates recent establishment and ongoing operation. The low but meaningful detection rate on VirusTotal (11/95) underscores the sophistication of the threat, as many automated security tools may initially miss the deception due to Cloudflare’s legitimate traffic routing and SSL certificate. Such campaigns typically lead to immediate financial loss upon successful compromise, with stolen credentials or session tokens enabling attackers to drain connected wallets or execute unauthorized transactions. Users who visited en-smartchainresolver.pages.dev are strongly advised to immediately disconnect from the site and inspect any connected wallet applications or browser extensions for unauthorized permissions or transactions. Revoke any permissions granted to unfamiliar or suspicious domains using tools such as WalletConnect or MetaMask’s connection management. Conduct a full scan of the device using updated antivirus and anti-malware software to detect potential infostealers or keyloggers that may have been installed. Enable transaction notifications and set spending limits on wallets to mitigate future losses. Report the domain to your wallet provider and relevant cybersecurity authorities to aid in blocking and takedown efforts. Exercise heightened caution when accessing crypto interfaces: verify URLs through official channels, use hardware wallets for large holdings, and treat unexpected wallet connection prompts as highly suspicious. ## Threat Details - Verdict: MALICIOUS - Site status: unknown (HTTP ?) ## Domain Intelligence - Registrar: Cloudflare, Inc. - IP: 188.114.96.3 ## Detection Status - VirusTotal: 11 vendors flagged - Google Safe Browsing: clean - Blocklists: 0 hits ## Evidence - Cloudflare Radar: https://radar.cloudflare.com/scan/cedfa072-3cf3-4255-a692-cf8962509ff8 - PhishDestroy: https://phishdestroy.io/domain/en-smartchainresolver.pages.dev/ - LLM endpoint: https://phishdestroy.io/domain/en-smartchainresolver.pages.dev/llm.txt ## If You Visited This Site 1. Change any passwords you may have entered 2. Enable 2FA on all related accounts 3. Monitor your accounts for unauthorized activity 4. Report to: FBI IC3, Europol, local authorities --- Report by PhishDestroy | https://phishdestroy.io/domain/en-smartchainresolver.pages.dev/ Last updated: 2026-03-22