exodus[.]walletv3[.]com
“Exodus”
Evidence Summary
This domain, exodus.walletv3.com, poses a direct threat to cryptocurrency users by impersonating the legitimate Exodus wallet interface. Analysis indicates the site functions as a crypto drainer, designed to automatically siphon funds from connected wallets without user consent. Victims who interact with the site risk losing control of their digital assets, as the malicious scripts execute unauthorized transactions once wallet access is granted. Infrastructure analysis reveals multiple indicators of malicious activity. The domain was registered on February 21, 2026, an unusually future-dated creation that suggests registry manipulation or fraudulent practices. It resolves to the IP address 193.108.113.211, hosted on AS48347 (JSC Mediasoft ekspert) in Russia. Security vendors on VirusTotal flagged the domain at a rate of 20/95, while three independent blocklists, including PhishDestroy and MetaMask, have already blacklisted it. The SSL certificate, issued by R13, provides no meaningful assurance of legitimacy, as such certificates are frequently abused in phishing operations. Users who visited exodus.walletv3.com should immediately revoke any wallet permissions granted to the site. Disconnect all connected wallets and transfer remaining funds to a new, secure wallet address. Scan the device used to access the site for malware, as crypto drainers often deploy additional payloads. Monitor transaction histories for unauthorized activity and report the incident to the legitimate Exodus support team for further assistance. If financial loss occurred, file a report with local cybercrime authorities and provide them with the domain, IP address, and any transaction hashes related to the incident.
Data Coverage
Threat Response Pipeline
Blocklist coverage
10 monitored external feeds · stored snapshot Aug 13, 2026
10 monitored external feeds No match
VirusTotal Analysis
Were You Affected by This Site?
If credentials, payment data, or files were exposed, report the incident immediately. Change affected passwords, revoke active sessions, and scan the device.
Report to Your Local Authorities
Select your country to get official cybercrime contacts, or create a complaint draft →.
Check Any Domain
Threat analysis using stored blocklist, WHOIS, DNS, and public scan evidence
Scan NowReport Phishing
Submit suspicious domains to our threat database — protect the community
ReportLive Threat Feed
Recent phishing reports and observed availability changes
MonitorStay Informed, Stay Safe
Monitor live threats or contest this listing if you believe it's a false positive