eth[.]defiusdt[.]top
“ETH”
The domain eth.defiusdt.top was a crypto drainer phishing site designed to steal cryptocurrency by draining funds from connected wallets. It did not impersonate a known brand or use a publicly identified drainer kit. The site is currently taken offline, but it previously posed an elevated risk to users who interacted with it.
Eth.defiusdt.top was detected by 1 of 95 security vendors on VirusTotal, including Gridinsoft, and appeared on 1 security blocklist (PhishDestroy). Google Safe Browsing did not flag the domain. The domain was created on February 21, 2026, and resolved to the IP address 8.209.205.6, hosted on Alibaba's infrastructure in Japan (AS45102). The SSL certificate was issued by R10. Trust scores from Gridinsoft and Scamadviser were 0/100 and 1/100, respectively, further indicating malicious intent.
Users who connected a wallet to eth.defiusdt.top should immediately revoke all token approvals using a tool like Etherscan's token approval checker or Revoke.cash. Funds should be transferred to a new, secure wallet. Report the domain to platforms such as Google Safe Browsing, PhishTank, or local cybercrime authorities to prevent further abuse.
Threat Response Pipeline
Public Blocklist Status
Forensic Intelligence
VirusTotal Analysis
Evidence & External Reports
“@AceStorage”
Were You Affected by This Site?
If credentials, payment data, or files were exposed, report the incident immediately. Change affected passwords, revoke active sessions, and scan the device.
Report to Your Local Authorities
Select your country to get official cybercrime contacts, or create a complaint draft →.
Check Any Domain
Threat analysis using stored blocklist, WHOIS, DNS, and public scan evidence
Scan NowReport Phishing
Submit suspicious domains to our threat database — protect the community
ReportLive Threat Feed
Recent phishing reports and observed availability changes
MonitorStay Informed, Stay Safe
Monitor live threats or contest this listing if you believe it's a false positive